403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.15
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/cooperative/sell/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/cooperative/sell/sumtotal.php.bak
<?
ob_start();
session_start();
if($_SESSION["adminlogin"]=="")
{
header('location:index.php');
exit();
}
//============ Start Session และทำการเรียก Function ติดต่อฐานข้อมูล 
require_once('../connect/connectdb.php');
$user=$_SESSION["user"];
?>
<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=tis-620">

<title>มาเดอะมอมินิมาร์ท</title>

</head>
<body>
<?
//*** Update Condition ***//
if($_GET["Action"] == "Save")
{
	for($i=1;$i<=$_POST["hdnLine"];$i++)
	{
		$strSQL = "UPDATE stocin SET ";
		$strSQL .="status= '".$_POST["r1$i"]."' ";
		$strSQL .="WHERE idstocin = '".$_POST["hdnid$i"]."' ";
		$objQuery = mysql_query($strSQL);
	}
	//header("location:$_SERVER[PHP_SELF]");
	//exit();
}
$strSQL = "SELECT * FROM stocin join product on product.ProductID=stocin.idcodin where status<1 order by timein desc";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
$i = 1;

?>
<table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                
              </table>
<form name="frmMain" method="post" action="sumtotal.php?Action=Save">
<table  width="100%" border="0" bgcolor="#999999">
 <center><font size='3' color='red'>สร้างรหัส CODE</font></center>
  
  <tr bgcolor="#FFFFFF">
    <th width="10"> <div align="center"></div></th>
	 <th width="10"> <div align="center">#</div></th>
    <th width="100"> <div align="center">ID</div></th>
	<th width="100"> <div align="center">bacode</div></th>
	<th width="100"> <div align="center">วันที่นำเข้า</div></th>
	<th width="100"> <div align="center">จำนวน</div></th>
	<th width="100"> <div align="center">ขาย</div></th>
	<th width="100"> <div align="center">คงเหลือ</div></th>
	<th width="100"> <div align="center">ตัด stoc</div></th>


  </tr>
<?
$i =0;

while($objResult = mysql_fetch_array($objQuery))

{
if($bg == "#EEEEEE") { //ส่วนของการ สลับสี 
$bg = "#FFFFFF";
} else {
$bg = "#EEEEEE";
}

	$i = $i + 1;
	$code1 =$objResult["idcodin"];
	$timein =$objResult["timein"];
	$signup = date("j/n/").(date("Y")+543) ;
	$bacode =$objResult["bacode"];
	$namestoc =$objResult["ProductName"];
	
	

?>
  <tr bgcolor="<?=$bg?>">
    <td><div align="center">
	<input type="hidden" name="hdnid<?=$i;?>" size="5" value="<?=$objResult["idstocin"];?>">
	 <td><?=$i?></td>

	<td><div align="right"><? echo "$namestoc"; ?>
	</div></td>
	



				<?$crsql="SELECT sum( unitin ) FROM `stocin`
					WHERE bacode = '$bacode'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$unittatal=$dcrd[0];	
					?>
						
								
								<?$crsql="SELECT sum( unitsell ) FROM `sell`
					WHERE bacodesell = '$bacode'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$unittatalsell=$dcrd[0];	
					
					
				$unitt=$unittatal-$unittatalsell;	
					?>
								
								
								
								
	
	<td><? echo "$bacode"; ?></td>
	<td><? echo "$timein"; ?></td>
	<td><? echo "$unittatal"; ?></td>
	<td><? echo "$unittatalsell"; ?></td>
	<td><? echo "$unitt"; ?></td>
	<td><input type="text" name="r1<?=$i;?>" size="3" maxlength="2" readonly="readonly" value="

<? if($unitt < 1)
 {
   echo "1";
 }
 else if($unitt >1)
 {
   echo "";
 }
?>
" >
</td>






  </tr>
<?
	  $i = $i;
  }
  ?>
</table>
  <input type="submit" name="submit" value="submit">
  <input type="hidden" name="hdnLine" value="<?=$i;?>">
</form>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit