403Webshell
Server IP : 27.254.152.13  /  Your IP : 216.73.217.38
Web Server : Apache/2
System : Linux ns1-252017.dragonhispeed.com 5.2.0 #1 SMP Fri Mar 29 22:50:14 MSK 2024 x86_64
User : coloflew ( 1072)
PHP Version : 5.6.40
Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/coloflew/domains/tessabalpatiu.go.th/public_html/administrator/modules/setting/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/coloflew/domains/tessabalpatiu.go.th/public_html/administrator/modules/setting/user.php
<?php 


$res = 0;
$linkurl = "index.php?name=setting&file=user";
$tableName = "userlogin";

if(@$_GET['act']=="add"){

	$arrData = array();
		
	$arrData['Username']		= $_POST['usernames'];
	$arrData['Password']		= $_POST['passwords'];
	$arrData['Name']			= str_replace("'", "\'", @$_REQUEST['Name']);
	$arrData['Surname']			= str_replace("'", "\'", @$_REQUEST['Surname']);
	$arrData['Email']			= $_POST['Email'];
	
	$arrData['CreateDate']		= @$objMaster->getdateformat(date("d M Y",time()));
	
	$db->insertData($tableName,$arrData); 
	//echo "<pre>"; print_r($arrData); 
	//exit();
	

	//exit;		
	$msg = $lang_set['txtSaveComplete']; 
	$res = 1;
}elseif(@$_GET['act']=="editdata"){


	$arrData = array();
	
	$arrData['Username']		= $_POST['usernames'];
	$arrData['Password']		= ($_POST['old_pass'] != $_POST['passwords'] && $_POST['passwords'] ? $_POST['passwords'] : $_POST['old_pass']);
	$arrData['Name']			= str_replace("'", "\'", @$_REQUEST['Name']);
	$arrData['Surname']			= str_replace("'", "\'", @$_REQUEST['Surname']);
	$arrData['Email']			= $_POST['Email'];
	
	
	
	//echo "<pre>"; print_r($arrData); exit();

	$db->updateData($tableName,$arrData,"EmpID='".$_POST['EmpID']."'");
	
	//exit;
	$msg = $lang_set['txtEditComplete'];
	$res = 1;

}elseif(@$_GET['act']=="edit"){
	
	$arrRes = $db->getOne($tableName,"*","EmpID='".@$_GET['EmpID']."' ");
	//echo "<pre>"; print_r($arrRes);
	
}elseif(@$_GET['act']=="deletedata"){


	$getchkp = $db->getOne($tableName,"*","EmpID='".$_GET['EmpID']."'");
	$db->deleteData($tableName,"EmpID='".$getchkp['EmpID']."'");
	
	$msg = $lang_set['txtDeleteComplete'];
	$res = 1;
}elseif(@$_GET['act']=="deleteAll"){
	//echo "<pre>"; print_r($_POST);
	
		if(count(@$_POST['pagedel']) > 0){
			foreach(@$_POST['pagedel'] as $key => $val){
				$getchkp = $db->getOne($tableName,"*","EmpID='".$val['EmpID']."'");
				$db->deleteData($tableName,"EmpID='".$getchkp['EmpID']."'");
			}
		}
	
	$msg = "Update Data complete.";
	$res = 1;
}

$where_f = "";
$where_f2 = "";
if(@$_REQUEST['keyword']){
	@$_REQUEST['keyword'] = str_replace("'", "\'", @$_REQUEST['keyword']); 
	if($where_f){
	
		$where_f .= " and (Name like '%".@$_REQUEST['keyword']."%' or Email like '%".@$_REQUEST['keyword']."%')";
		$where_f2 .= " and (Name like '%".@$_REQUEST['keyword']."%' or Email like '%".@$_REQUEST['keyword']."%')";
	}else{
		$where_f = " (Name like '%".@$_REQUEST['keyword']."%' or Email like '%".@$_REQUEST['keyword']."%')";
		$where_f2 .= " (Name like '%".@$_REQUEST['keyword']."%' or Email like '%".@$_REQUEST['keyword']."%')";
	}	
	
	$linkurl .= "&keyword=".$_REQUEST['keyword'];
}

$page = @$_GET['page'] ? @$_GET['page'] : 1;

$arrpageP = $db->getAll( $tableName, "*",$where_f,"" );
$arrPage = $objMaster->viewPages($page, $arrpageP, "15");
$getPage = $db->getAll($tableName,"*","","order by name asc",@$arrPage["offset"]);


?>
<!--colorbox popup-->

<div class="content-box"><!-- Start Content Box -->
	<div class="content-box-header">
        <h3><?php echo $lang_set['usertitle']; ?></h3>
        <ul class="content-box-tabs">
            <li><a href="#tab1" <?php echo ($_GET['act']=="" ? 'class="default-tab"' : "" );?>><?php echo $lang_set['list_page']; ?></a></li>
          <li><a href="#tab2" <?php echo ($_GET['act']=="edit" ? 'class="default-tab"' : "" );?>><?php echo $lang_set['add_page']; ?></a></li>
      </ul>
        <div class="clear"></div>
	</div> <!-- End .content-box-header -->
        <div class="content-box-content">
            <div class="tab-content <?php echo ($_GET['act']!="edit" ? "default-tab" : "" );?>" id="tab1"> <!-- This is the target div. id must match the href of this div's tab -->
            <?php if($res==1){?>
                <div class="notification success png_bg">
					<a href="#" class="close"><img src="images/icons/cross_grey_small.png" title="Close this notification" alt="close" /></a>
					<div>
					<?php echo $msg;?>
					</div>
				</div>
                <meta http-equiv="refresh" content="1;URL=<?php echo $linkurl;?>">
            <?php }?>
        <form action="<?php echo $linkurl;?>" method="post" name="jumb1">
        <table>
        	<tr>
            	<td>
        		<input type="text" class="text-input small-input" name="keyword" value="<?php echo $_POST['keyword'];?>" /> &nbsp;
        		<input type="submit" class="button" value="<?php echo $lang_set['search']; ?>" />            
                </td>
            </tr>
        </table>
        </form>
        <form action="<?php echo $linkurl;?>&act=deleteAll" method="post">
        <table>
        	<thead>
            <tr>
               <th style="width:10px;"><input class="check-all" type="checkbox" /></th>
               <th><?php echo $lang_set['txtCreateDate'];?></th>
               <th><?php echo $lang_set['txtUsername'];?></th>
               <th><?php echo $lang_set['txtEmail']; ?></th>
               <th><?php echo $lang_set['txtLastlogin']; ?></th>
               <th>&nbsp;</th>
            </tr>
            </thead>
            <tfoot>
            <tr>
                <td colspan="8"> 
                <div class="bulk-actions align-left">
                  <select name="actdel">
                    <option value="del"><?php echo $lang_set['delete']; ?></option>
                  </select>
                  <input type="submit" class="button" value="<?php echo $lang_set['submit']; ?>" />
                </div>
                <div class="pagination">
                <?php if( $arrPage["startPage"]!="" && $arrPage["endPage"] !="" ){?>
                    <a href="<?php echo $linkurl;?>&page=<?php echo $arrPage["startPage"];?>" title="First Page">&laquo; <?php echo $lang_set['txtFirst']?></a><a href="<?php echo $linkurl;?>&page=<?php echo ($page-1);?>" title="Previous Page">&laquo; <?php echo $lang_set['txtPrevious']?></a>
                    <?php 
					for($i = $arrPage["startPage"]; $i <= $arrPage["endPage"]; ++$i) {
						echo'<a href="'.$linkurl.'&page='.$i.'" class="number '.($page == $i ? 'current' : '').'">'.($i).'</a>';
					}?>
                    <a href="<?php echo $linkurl;?>&page=<?php echo ($page+1);?>" title="Next Page"><?php echo $lang_set['txtNext']?> &raquo;</a><a href="<?php echo $linkurl;?>&page=<?php echo $arrPage["endPage"];?>" title="Last Page"><?php echo $lang_set['txtLast']?> &raquo;</a>
                <?php }?>
                </div> <!-- End .pagination -->
                <div class="clear"></div>
                </td>
            </tr>
            </tfoot>
            <tbody>
            <?php 
            if($getPage){
                foreach($getPage as $key => $val){
				$dates = explode(" ",@$val['CreateDate']);
            ?>
            <tr>
            	 <td style="vertical-align:middle;"><?php if($_SESSION['userid']!=$val['EmpID'] and $val['adminType'] != '1'){?><input type="checkbox" name="pagedel[]" value="<?php echo $val['EmpID'];?>"/><?php }?></td>
            	 <td><?php echo @$objMaster->getdbdateformat($dates[0]);?></td>
            	 <td><?php echo $val['Username'];?></td>
                 <td><?php echo $val['Email'];?></td>
                
                 <td><?php echo @$objMaster->getdbdateformat(@$val['LastLogin']);?></td>
                <td class="delete" style="vertical-align:middle; width:60px;"><div align="center">
                <a href="<?php echo $linkurl;?>&act=edit&EmpID=<?php echo $val['EmpID']?>" title="Edit Detail"><img src="images/icons/pencil.png" alt="Edit Detail" /></a>&nbsp;
                <?php if($_SESSION['userid']!=$val['EmpID'] and $val['adminType'] != '1'){?>
                <a href="javascript:void();" onclick="chkConfirm('<?php echo $linkurl;?>&act=deletedata&EmpID=<?php echo $val['EmpID']?>','Are you sure delete?');"  title="Delete"><img src="images/icons/cross.png" alt="Delete" /></a><?php }?></div></td>
            </tr>
                 
            <?php
                }
            }else{
            ?>
            <tr>
                <td colspan="8" style="text-align:center"><?php echo $lang_set['status']; ?><?php echo $lang_set['page_not_have']; ?>.</td>
            </tr>
            <?php 
            }
            ?>
            </tbody>
        </table>
      </form>
    </div> <!-- End #tab1 -->

    <div class="tab-content <?php echo ($_GET['act']=="edit" ? "default-tab" : "" );?>" id="tab2">
    <!--<form action="index.php?name=gallery&act=<?php echo (@$_GET['act']=="edit" ? "editdata" : "add");?>" method="post" enctype="multipart/form-data" id="formID">-->
    <form action="<?php echo $linkurl;?>&act=<?php echo (@$_GET['act']=="edit" ? "editdata" : "add");?>" method="post" enctype="multipart/form-data" id="formID" onsubmit="return CheckFromUser();">
    <input type="hidden" name="EmpID" value="<?php echo $arrRes['EmpID']; ?>" />
        
    	<p>
			<label><?php echo $lang_set['txtName']; ?> :</label>
			<input type="text" class="validate[required] text-input medium-input" name="Name" id="Name" value="<?php echo @$arrRes['Name'];?>" /> 
		</p>
        <p>
           <label><?php echo $lang_set['txtEmail'];?> : </label>
           <input value="<?php echo $arrRes['Email'];?>" class="validate[required,custom[email]<?php echo ($_GET['act']=="edit" ? "" : ",ajax[ajaxUserCall]" );?>] text-input medium-input" type="text" name="Email" id="Email" />
        </p> 
        <p>
           <label><?php echo $lang_set['txtUsername'];?> : </label>
           <input value="<?php echo $arrRes['Username'];?>" class="validate[required,custom[onlyLetterSp]<?php echo ($_GET['act']=="edit" ? "" : ",ajax[ajaxNameCallPhp]" );?>] text-input medium-input" type="text" name="usernames" id="username" />
        </p> 
        <p>
           <label><?php echo $lang_set['txtPassword'];?> : </label>
           <input value="<?php echo $arrRes['Password'];?>"  class="<?php echo ($_GET['act']=="edit" ? "" : "validate[required]");?> text-input" type="password" name="passwords" id="password" />
           <input type="hidden" name="old_pass" value="<?php echo $arrRes['Password'];?>" />
        </p> 
        <p>
           <label><?php echo $lang_set['txtRePassword'];?> : </label>
           <input value="" class="validate[<?php echo ($_GET['act']=="edit" ? "" : "validate[required],");?>equals[password]] text-input" type="password" name="password2" id="password2"/>
        </p>   	

		<hr />
		<p>
				<input type="submit" class="button" value="<?php echo $lang_set['submit']; ?>" />
		</p>
	</form>
    </div> <!-- End #tab2 -->        
</div> <!-- End .content-box-content -->
</div>

Youez - 2016 - github.com/yon3zu
LinuXploit