403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.15
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/cooperative/sell/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/cooperative/sell/orderdetail.php
<?
ob_start();
session_start();
if($_SESSION["adminlogin"]=="")
{
header('location:index.php');
exit();
}
//============ Start Session และทำการเรียก Function ติดต่อฐานข้อมูล 
require_once('../connect/connect.php');
require_once('../connect/function.php');

if($_GET["Action"]=="UpdateStatus")
{
$sql="update cusorder set status='$_POST[rdoStatus]' where OrderNo='$_GET[OrderNo]'";
$query=mysql_query($sql);
header("location:$_SERVER[PHP_SELF]?OrderNo=$_GET[OrderNo]");
}

?>
<html>
<title>..:: ระบบจัดการฐานข้อมูล ::</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<link rel="stylesheet" href="../css/styles.css" type="text/css">
<script language="JavaScript" src="editor.js"></script>
<div align="center"><br>
<?
//=========== อ่านใบสั่งซื้อ
$result=select("cusorder","where 1=1 and OrderNo='".$_GET["OrderNo"]."'");
if(!$result)
{
header("location:cusorder.php");
}
$status=$result["status"];

$resultMember=select("member","where 1=1 and MemberID='".$result["MemberID"]."'");



?>
  <table cellspacing=1 cellpadding=4 width="68%" bgcolor=#CCCCCC border=0 align="center" height="10">
    <tbody>
      <tr bgcolor=#e5e5e5> 
        <td width="100%" bgcolor="#FFFFFF"> <div align="center"></div>
          <table cellspacing=1 cellpadding=4 width="100%" border=0 align="center" height="10">
            <tbody>
              <tr bgcolor=#e5e5e5> 
                <td width="35%" bgcolor="#FFFFFF"> <div align="left"><b><img src="../image/allrowto.gif" width="11" height="11" align="absbottom"> 
                    รายละเอียดสั่งซื้อ </b></div></td>
                <td width="22%" align=middle bgcolor="#FFFFFF"> <div align="left"> 
                  </div></td>
                <td width="43%" bgcolor="#FFFFFF"> <div align="right"><a href="cusorder.php">กลับไป</a></div></td>
              </tr>
            </tbody>
          </table></td>
      </tr>
    </tbody>
  </table>
  <br>
</div>

  <table cellspacing=1 cellpadding=3 width="68%" bgcolor=#CCCCCC border=0 align="center" height="10">
    <tbody>
      <tr bgcolor=#e5e5e5> 
        <td width="100%" bgcolor="#FFFFFF">
          <table width="100%" border="0" cellspacing="2" cellpadding="2">
          <tr> 
            <td width="12%">&nbsp;</td>
            <td width="26%">&nbsp;</td>
            <td width="62%">&nbsp;</td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td valign="top">รหัสสั่งซื้อ</td>
            <td> 
              <?=$_GET["OrderNo"];?>
            </td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td valign="top">อีเมล์</td>
            <td> 
              <?=$resultMember["Email"];?>
            </td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td valign="top">ชื่อ</td>
            <td> 
              <?=$resultMember["Name"];?>
              <?=$resultMember["LastName"];?>
            </td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td valign="top">ที่อยู่</td>
            <td> 
              <?=nl2br($resultMember["Address"]);?>
            </td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td valign="top">จังหวัด</td>
            <td> 
              <?=nl2br($resultMember["Province"]);?>
            </td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td valign="top">รหัสไปรษณีย์</td>
            <td> 
              <?=nl2br($resultMember["ZipCode"]);?>
            </td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td valign="top">หมายเลขโทรศัพท์</td>
            <td> 
              <?=$resultMember["Tel"];?>
            </td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td valign="top">หมายเลขโทรสาร</td>
            <td> 
              <?=$resultMember["Fax"];?>
            </td>
          </tr>
          <tr> 
            <td valign="top">&nbsp;</td>
            <td width="26%" bgcolor="#FFFFFF"> <div align="left"></div></td>
            <td>&nbsp;</td>
          </tr>
        </table>
        <table width="456" border="0" align="center">
          <tr> 
            <td><strong><b><img src="../image/allrowto.gif" width="11" height="11" align="absbottom"></b> 
              รายละเอียด</strong></td>
          </tr>
          <tr> 
            <td>&nbsp;</td>
          </tr>
          <tr> 
            <td><table width="98%" height="21" border="0" align="center" cellpadding="2" cellspacing="1" bgcolor="#666666">
                <tr bgcolor="#FFFFEF"> 
                  <td><div align="center">ลำดับ</div></td>
                  <td>ชื่อสินค้า</td>
                  <td><div align="center">ราคา</div></td>
                  <td><div align="center">ค่าจัดส่ง</div></td>
                  <td><div align="center">จำนวน</div></td>
                  <td><div align="center">รวม</div></td>
                </tr>
                <?
				//=========== อ่านว่ามีรายการสั่งซื้ออะไรบ้าง
$strNum=0;
$strTotal=0;
$sqlOrder="select * from order_detail where 1=1 and OrderNo='".$result["OrderNo"]."' ";
$queryOrder=mysql_query($sqlOrder);
while($resutOrder=mysql_fetch_array($queryOrder))
{
$result=select("product","where 1=1 and ProductID='".$resutOrder["ProductID"]."' ");
if($result)
{
$strNum++;
?>
                <tr bgcolor="#FFFFEF"> 
                  <td width="9%"> <div align="center"> 
                      <?=$strNum;?>
                    </div></td>
                  <td width="48%"> 
                    <?=$result["ProductName"];?>
                  </td>
                  <td width="14%"> <div align="right"> 
                      <?="".number_format($result["Price"], 2,'.',',');?>
                    </div></td>
                  <td width="13%"> 
                    <div align="right">
                      <?="".number_format($result["PriceSend"], 2,'.',',');?>
                    </div></td>
                  <td width="13%"><div align="center"> 
                      <?=$resutOrder["Quanlity"];?>
                    </div></td>
                  <td width="16%"> <div align="right"> 
                      <?="".number_format(($result["Price"]+$result["PriceSend"])*$resutOrder["Quanlity"], 2,'.',',');?>
                    </div></td>
                </tr>
                <?
								  $strTotal=$strTotal+(($result["Price"]+$result["PriceSend"])*$resutOrder["Quanlity"]);
}
}
?>
              </table>
              <br> <table width="98%" height="21" border="0" align="center" cellpadding="2" cellspacing="1" bgcolor="#666666">
                <tr bgcolor="#FFFFEF"> 
                  <td><div align="right">จำนวน (รายการ)</div></td>
                  <td> <div align="right"> 
                      <?=$strNum;?>
                    </div></td>
                </tr>
                <tr bgcolor="#FFFFEF"> 
                  <td> <div align="right">ราคารวม (บาท)</div></td>
                  <td width="16%"> <div align="right"> 
                      <?="".number_format($strTotal, 2,'.',',');?>
                    </div></td>
                </tr>
              </table></td>
          </tr>
          <tr> 
            <td width="378"><div align="center"> 
                <form action="?Action=UpdateStatus&OrderNo=<?=$_GET["OrderNo"];?>" method="post" name="frmUpdate" id="frmUpdate">
                  <div align="left"> 
                    <table width="100%" border="0" cellspacing="0" cellpadding="0">
                      <tr>
                        <td width="77%">&nbsp;</td>
                        <td width="23%">&nbsp;</td>
                      </tr>
                      <tr> 
                        <td><strong>สถานะ </strong> <input name="rdoStatus" type="radio" value="1" <? if($status=="1"){?>checked<?}?>>
                          รอการชำระเงิน 
                          <input name="rdoStatus" type="radio" value="2" <? if($status=="2"){?>checked<?}?>>
                          ชำระเงิน/จัดส่งสินค้าไปแล้ว </td>
                        <td><input name="Submit" type="submit" class="button" value="Submit"></td>
                      </tr>
                    </table>
                  </div>
                </form>
                <br>
                <br>
              </div></td>
          </tr>
        </table></td>
      </tr>

    </tbody>
  </table>
</form>


Youez - 2016 - github.com/yon3zu
LinuXploit