AnonSec Shell
Server IP : 104.21.37.246  /  Your IP : 104.23.243.32   [ Reverse IP ]
Web Server : Apache
System : Linux cpanel01wh.bkk1.cloud.z.com 2.6.32-954.3.5.lve1.4.59.el6.x86_64 #1 SMP Thu Dec 6 05:11:00 EST 2018 x86_64
User : cp648411 ( 1354)
PHP Version : 7.2.34
Disable Function : NONE
Domains : 0 Domains
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home2/cp648411/public_html/ilawasia.onnud20.com/Attachment/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : /home2/cp648411/public_html/ilawasia.onnud20.com/Attachment/Create.php
<?php
$ck='not';
include("../include/checkLogin.php");
include("../include/class.php");
include("../include/table_name.php");
$date_year = date("Y");
$date_month = date("m");
require_once("../class/coreClass.php");
$core_db = new coreClass;
/*
echo "<pre>";
print_r($_POST);
echo "</pre>";
echo "<pre>";
print_r($_FILES);
echo "</pre>";
exit();
$data = $_POST;
echo json_encode($data, JSON_UNESCAPED_UNICODE);

exit();
*/


if(@$_POST['CaseNumber']!=''){
  $sql_case = array('table'=>$name_table2,'where'=>"CaseNumber = '".@$_POST["CaseNumber"]."'");
  $view_sql_case = $view_db->view($sql_case);
  $request_case = $view_db->q_ro($view_sql_case);
  $num_case = $view_db->q_nr($request_case);
  $row_case = $view_db->q($view_sql_case);
  if(@$num_case==0){
    $_SESSION['Error'] = 'Case is not found';
  }
}
elseif(@$_POST['CustomerCode']!=''){
  $sql_customer = array('table'=>$name_table51,'where'=>"NamesCode = '".@$_POST["CustomerCode"]."'");
  $view_sql_customer = $view_db->view($sql_customer);
  $request_customer = $view_db->q_ro($view_sql_customer);
  $num_customer = $view_db->q_nr($request_customer);
  $row_customer = $view_db->q($view_sql_customer);
  if(@$num_customer==0){
    $_SESSION['Error'] = 'Customer is not found';
  }
}

$caseId='';
$customerId='';

if(@$_POST['CaseNumber']!='')
{
  $sql_case = array('table'=>$name_table2,'where'=>"CaseNumber = '".@$_POST["CaseNumber"]."'");
  $view_sql_case = $view_db->view($sql_case);
  $row_case = $view_db->q($view_sql_case);
  $caseId = $row_case['CaseId'];
  $customerId = $row_case['CustomerId'];
}
elseif(@$_POST['CustomerCode']!='')
{
  $sql_customer = array('table'=>$name_table51,'where'=>"NamesCode = '".@$_POST["CustomerCode"]."'");
  $view_sql_customer = $view_db->view($sql_customer);
  $row_customer = $view_db->q($view_sql_customer);
  $customerId = $row_customer['NamesId'];
}

$attachNo = "";
if(@$_POST["ParentId"]!='')
{

  $sql_parent = array('table'=>$name_table51,'where'=>"AttachmentId = '".@$_POST["ParentId"]."'");
  $view_sql_parent = $view_db->view($sql_parent);
  $row_parent = $view_db->q($view_sql_parent);
  $attachNo = $row_parent['AttachmentNumber'];

  $sql_parent2 = array('table'=>$name_table,'where'=>"ParentId = '".@$_POST["ParentId"]."'");
  $view_sql_parent2 = $view_db->view($sql_parent2);
  $row_parent2 = $view_db->q($view_sql_parent2);
  $Seq = $row_parent2['Seq'];

}
else
{
  $GenDoc=2;
  $AttachmentNumber = $core_db->GenDocumentNumberOnlyYear($GenDoc,$isUpdate = "true");
  $attachNo = $AttachmentNumber['gdn3'];
}





  if($_FILES["File"]["error"] == 0)
  {
    $path = "../Upload/";
    $subPath = "Attachment/".@$AttachmentNumber['gdn3']."/";
    $Directory = $path . $subPath;
    if (!file_exists($Directory)) {mkdir($Directory, 0777, true);}
    $name_file = $image_class->file_up($_FILES["File"],$Directory,$subPath);
  }
  $list = array(
    'table'=>$name_table,
    'AttachmentNumber'=>"'".$attachNo."'",
    'Seq'=>"'".(@$_POST["ParentId"]=='')?0:$Seq."'",
    'ParentId'=>"'".@$_POST["ParentId"]."'",
    'DocumentType'=>"'".@$_POST["DocumentType"]."'",
    'DocumentDate'=>"'".@$date."'",
    'DocumentName'=>"'".@$_POST["DocumentName"]."'",
    'AttachmentDate'=>"'".@$date."'",
    'FilePath'=>"'".@$name_file."'",
    'CaseId'=>"'".@$caseId."'",
    'CustomerId'=>"'".@$customerId."'",
    'CreateBy'=>"'".@$_SESSION["UserInfo"][0]['UserId']."'",
    'CreateDateTime'=>"'".@$date."'",
    'UpdateBy'=>"'".@$a."'",
    'CreateDateTime'=>"'".@$date."'"
  );
  $add = $actiondata_db->add_db($list);





 if($add['suc']==1){
   if(@$_POST['CaseNumber']!=''){
     if($_FILES["File"]["error"] == 0)
     {
       $path = "../Upload/";
       $subPath = "Case/".@$caseId."/";
       $Directory = $path . $subPath;
       if (!file_exists($Directory)) {mkdir($Directory, 0777, true);}
       $name_file = $image_class->file_up($_FILES["File"],$Directory,$subPath);
     }
     $list = array(
       'table'=>$name_table3,
       'CaseId'=>"'".$caseId."'",
       'DocumentType'=>"'".$_POST['DocumentType']."'",
       'DocumentDate'=>"'".@$_POST['DocumentDate']."'",
       'DocumentName'=>"'".@$_POST['DocumentName']."'",
       'FilePath'=>"'".@$name_file."'",
       'AttachmentDate'=>"'".@$_POST['AttachmentDate']."'",
       'CreateBy'=>"'".@$_SESSION["UserInfo"][0]['UserId']."'",
       'CreateDateTime'=>"'".@$_POST["Status"]."'",
     );
     $add = $actiondata_db->add_db($list);
     if($add['suc']==1){
       $sql = array('table'=>$name_table3,'count'=>'MAX(CaseAttachmentId) AS max_id','where'=>"");
       $view_sql = $view_db->view($sql);
       $row = $view_db->q($view_sql);
       $CaseAttachmentId = $row['max_id'];

       $sql = array('table'=>$name_table,'count'=>'MAX(AttachmentId) AS max_id','where'=>"");
       $view_sql = $view_db->view($sql);
       $row = $view_db->q($view_sql);
       $AttachmentId = $row['max_id'];

       $list = array(
         'table'=>$name_table,
         'AttachmentId'=>$AttachmentId,
         'CaseAttachmentId'=>$CaseAttachmentId
       );
       $data = $actiondata_db->edit_db($list);
     }
   }
   $data = array(
     'caseId' => $caseId,
     'customerId' => $customerId,
     'attachNo' => $attachNo,
     'AttachmentNumber' => $AttachmentNumber,
     'AttachmentId' => $AttachmentId,
     'sql' => $list,
     'post' => $_POST,
     'Message' => 'Create payment terms successful',
   );
}else{
  $data = array(
    'caseId' => $caseId,
    'customerId' => $customerId,
    'attachNo' => $attachNo,
    'AttachmentNumber' => $AttachmentNumber,
    'sql' => $list,
    'Message' => 'false',
  );
}



 echo json_encode($data, JSON_UNESCAPED_UNICODE);
?>

Anon7 - 2022
AnonSec Team