One Hat Cyber Team
Your IP :
216.73.216.240
Server IP :
162.240.106.28
Server :
Linux server.ganesand.com 3.10.0-1160.80.1.el7.x86_64 #1 SMP Tue Nov 8 15:48:59 UTC 2022 x86_64
Server Software :
Apache
PHP Version :
7.1.33
Buat File
|
Buat Folder
Eksekusi
Dir :
~
/
home
/
thoa
/
www
/
admin
/
View File Name :
mg_content.php
<?php include('config.php'); ?> <?php /* $con = mysql_connect('localhost', 'root', ''); mysql_select_db("ecomm", $con); */ error_reporting(0); ?> <?php $CON_ID = $_GET['CON_ID']; $view = mysql_query("select * from content where CON_ID = '".$CON_ID."'"); // for editing $data = mysql_fetch_array($view); if($_GET['SAI']){ $STS = $_GET['FEA_STS']; if($STS == 0){ $upd_sts = mysql_query("UPDATE content SET FEA_STS ='0' WHERE CON_ID ='".$_GET['SAI']."'"); //for changing status } else{ $upd_sts = mysql_query("UPDATE content SET FEA_STS ='1' WHERE CON_ID ='".$_GET['SAI']."'"); } } if($_GET['SAI1']){ $STS = $_GET['NEW_STS']; if($STS == 0){ $upd_sts = mysql_query("UPDATE content SET NEW_STS ='0' WHERE CON_ID ='".$_GET['SAI1']."'"); //for changing status } else{ $upd_sts = mysql_query("UPDATE content SET NEW_STS ='1' WHERE CON_ID ='".$_GET['SAI1']."'"); } } if($_GET['SAI2']){ $STS = $_GET['TOP_STS']; if($STS == 0){ $upd_sts = mysql_query("UPDATE content SET TOP_STS ='0' WHERE CON_ID ='".$_GET['SAI2']."'"); //for changing status } else{ $upd_sts = mysql_query("UPDATE content SET TOP_STS ='1' WHERE CON_ID ='".$_GET['SAI2']."'"); } } if($_GET['del_id']){ ?> <?php $del = mysql_query("delete from content where CON_ID='".$_GET['del_id']."'"); //for deleting status if($del){?> <script> alert("Category deleted sucessfully"); window.location= "mg_content.php"; </script> <?php } if(!$del){?> <script> alert("Not able deleted sucessfully"); window.location= "mg_content.php"; </script> <?php } } if($_POST['submit']){ $brand = mysql_real_escape_string($_POST['brand']); $cname = mysql_real_escape_string($_POST['category']); $subcatname = mysql_real_escape_string($_POST['subcatname']); $name = mysql_real_escape_string($_POST['name']); $pri = mysql_real_escape_string($_POST['pri']); $pri1 = mysql_real_escape_string($_POST['pri1']); $des = mysql_real_escape_string($_POST['des']); $code = mysql_real_escape_string($_POST['code']); $stock = mysql_real_escape_string($_POST['stock']); $pdimage = ($_FILES['pd1image']['name']); $tmp_img1 = $_FILES['pd1image']['tmp_name']; move_uploaded_file($tmp_img1,"images/".$pdimage); $view1 = mysql_query("select * from category where CAT_NAME = '".$cname."'"); // for cid $data1 = mysql_fetch_array($view1); $cid=$data1['CAT_ID']; $view2 = mysql_query("select * from subcategory where SC_NAME = '".$subcatname."'"); // for cid $data2 = mysql_fetch_array($view2); $sid=$data2['SC_ID']; if($_GET['CON_ID']==""){ $ins = mysql_query("insert into content (CAT_NAME,SC_ID,SCAT_NAME,CON_NAME,CON_IMG,CON_PRI,CON_PRI1,CAT_ID,CON_CODE,CON_DES,STOCK) values('$cname','$sid','$subcatname','$name','$pdimage','$pri','$pri1','$cid','$code','$des','$stock')"); ?><script>alert("Inserted sucessfully"); </script><? } if($_GET['CON_ID']!="" && $_FILES['pd1image']['tmp_name']!="") { $upd = mysql_query("update content set CAT_NAME='$cname',SC_ID='$sid',SCAT_NAME='$subcatname',CON_NAME='$name',CON_IMG='$pdimage',CON_PRI='$pri',CON_PRI1='$pri1',CAT_ID='$cid',CON_CODE='$code',CON_DES='$des',STOCK='$stock' where CON_ID='".$CON_ID."'"); //header('Location:mg_slide.php'); } else if($_GET['CON_ID']!="") { $upd = mysql_query("update content set CAT_NAME='$cname',SC_ID='$sid',SCAT_NAME='$subcatname',CON_NAME='$name',CON_PRI='$pri',CON_PRI1='$pri1',CAT_ID='$cid',CON_CODE='$code',CON_DES='$des',STOCK='$stock' where CON_ID='".$CON_ID."'"); } if($upd){?> <script>alert("updated sucessfully"); window.location ="mg_content.php" </script> <?php } if(!$upd){?> <?php } } ?> <script> function del(id){ var del = confirm("Are you sure Want to delete"); if(del){ window.location.href = "mg_content.php?del_id="+id+"&del=1"; } else{ window.location.href = "mg_content.php"; } } </script> <script> function showUser1(str) { $.ajax({ type: "GET", url: "getsub1.php?q="+str, success: function(result){ $("#subcat1").html(result); } }); } </script> <script> function calculatePercentage (oldval, newval) { percentsavings =oldval-((oldval * newval) / 100); document.getElementById("pdfin").value = percentsavings ; } </script> <script> function nval(n) { document.getElementById("n1").value = n ; } </script> <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <title>Admin Panel</title> <link href="css/bootstrap.min.css" rel="stylesheet"> <link href="css/datepicker3.css" rel="stylesheet"> <link href="css/styles.css" rel="stylesheet"> <!--[if lt IE 9]> <script src="js/html5shiv.js"></script> <script src="js/respond.min.js"></script> <![endif]--> </head> <script type="text/javascript" src="js/tinymce/tinymce.min.js"></script> <script type="text/javascript"> tinymce.init({ selector: "textarea", themes: "modern", forced_root_block : 'p' plugins: [ "advlist autolink lists link image charmap print preview anchor", "searchreplace visualblocks code fullscreen", "insertdatetime media table contextmenu paste" ], toolbar: "insertfile undo redo | styleselect | bold italic | alignleft aligncenter alignright alignjustify | bullist numlist outdent indent | link image" }); </script> <body> <nav class="navbar navbar-inverse navbar-fixed-top" role="navigation"> <div class="container-fluid"> <div class="navbar-header"> <a href="#"><button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#sidebar-collapse"> <span class="sr-only">Toggle navigation</span> <span class="icon-bar"></span> <span class="icon-bar"></span> <span class="icon-bar"></span> </button> </a> <a class="navbar-brand" href="#"><b>Fine Home Delivery Menu</b></a> <ul class="user-menu"> <li class="dropdown pull-right"> <a href="#" class="dropdown-toggle" data-toggle="dropdown"><img src="own.png" style="border-radius:40%;width:35px;height:35px;"> MR. Ramachandran<span class="caret"></span></a> <ul class="dropdown-menu" role="menu"> <li><a href="logou.php" style="color:red;"><span class="glyphicon glyphicon-off"></span> Logout</a></li> </ul> </li> </ul> </div> </div><!-- /.container-fluid --> </nav> <div id="sidebar-collapse" class="col-sm-3 col-lg-2 sidebar"> <form role="search"> <div class="form-group"> <input type="text" class="form-control" placeholder="Search"> </div> </form> <? include('header.php');?> </div><!--/.sidebar--> <div class="col-sm-9 col-sm-offset-3 col-lg-10 col-lg-offset-2 main"> <div class="row"> <ol class="breadcrumb"> <li><a href="#"><span class="glyphicon glyphicon-home"></span></a></li> <li class="active">Manage Content</li> </ol> </div><!--/.row--> <div class="row"> <div class="col-lg-12"> <h2 class="page-header">Add Product</h2> </div> </div><!--/.row--> <section class="content"> <div class="row"> <!-- left column --> <div class="col-xs-12"> <!-- general form elements --> <div class="box box-primary"> <!-- form start --> <div class="container"> <form role="form" method="post" action="" enctype="multipart/form-data"> <div class="box-body"> <!-- <div class="form-group col-sm-11"> <label for="exampleInputFile">Brand</label> <? // if($CON_ID) {?> <select name="brand" class="form-control" onchange="showUser(this.value)"> <?php // $query1=mysql_query("select * from content where CON_ID = '".$CON_ID."'"); // while($row1=mysql_fetch_array($query1)) {?> <option value="<?php //echo $row1['BR_NAME'];?>"><?php //echo $row1['BR_NAME'];?></option> <?php //}?> <?php // $query1=mysql_query("select * from brand "); // while($row1=mysql_fetch_array($query1)) {?> <option value="<?php //echo $row1['BR_NAME'];?>"><?php //echo $row1['BR_NAME'];?></option> <?php// }?> </select> <?//}else{?> <select name="brand" class="form-control" onchange="showUser(this.value)"> <?php // $query1=mysql_query("select * from brand "); // while($row1=mysql_fetch_array($query1)) {?> <option value="<?php //echo $row1['BR_NAME'];?>"><?php// echo $row1['BR_NAME'];?></option> <?php// }?> </select> <?//}?> </div> --> <div class="form-group col-sm-11"> <label for="exampleInputFile">Category</label> <? if($CON_ID) {?> <select name="category" class="form-control"> <?php $query1=mysql_query("select * from content where CON_ID = '".$CON_ID."'"); while($row1=mysql_fetch_array($query1)) {?> <option value="<?php echo $row1['CAT_NAME'];?>"><?php echo $row1['CAT_NAME'];?></option> <?php }?> <?php $query1=mysql_query("select * from category "); while($row1=mysql_fetch_array($query1)) {?> <option value="<?php echo $row1['CAT_NAME'];?>"><?php echo $row1['CAT_NAME'];?></option> <?php }?> </select> <?}else{?> <select name="category" class="form-control"> <option value="">Select</option> <?php $query1=mysql_query("select * from category "); while($row1=mysql_fetch_array($query1)) {?> <option value="<?php echo $row1['CAT_NAME'];?>"><?php echo $row1['CAT_NAME'];?></option> <?php }?> </select> <?}?> </div> <div class="form-group col-sm-11"> <label for="exampleInputEmail1">Name of Product:</label> <input type="text" class="form-control" id="name" name="name" value="<?php echo $data['CON_NAME']; ?>"> </div> <div class="form-group col-sm-11"> <label for="exampleInputEmail1">Product Code:</label> <input type="text" class="form-control" id="code" name="code" value="<?php echo $data['CON_CODE']; ?>"> </div> <div class="form-group col-sm-3"> <label for="exampleInputFile">Choose Image</label> <div> <input type="file" name="pd1image" id="exampleInputFile"><br> <?php if($CON_ID){ ?> <img src = "images/<?php echo $data['CON_IMG'];?>" height="100" width="100"> <?php } ?> </div> </div> <div class="form-group col-sm-11"> <label for="exampleInputEmail1">Product Information:</label> <textarea class="form-control" rows="2" id="des" name="des"><?php echo $data['CON_DES']; ?></textarea> </div> <div class="form-group col-sm-11"> <label for="exampleInputEmail1">Original Price:</label> <input type="text" class="form-control" id="pri" name="pri" value="<?php echo $data['CON_PRI']; ?>"> </div> <div class="form-group col-sm-11"> <label for="exampleInputEmail1">Offer Rate:</label> <input type="text" class="form-control" id="pri1" name="pri1" value="<?php echo $data['CON_PRI1']; ?>"> </div> <div class="form-group col-sm-11"> <label for="exampleInputEmail1">Stock Available:</label> <? if($data['CON_NAME']) {?> <select name="stock" class="form-control"> <option value="<?php echo $data['STOCK']; ?>"><?php echo $data['STOCK']; ?></option> <option value="YES">YES</option> <option value="NO">NO</option> </select> <?}else{?> <select name="stock" class="form-control"> <option value="YES">YES</option> <option value="NO">NO</option> </select> <? } ?> </div> <div class="box-footer col-sm-11"> <button type="submit" name="submit" value="submit" class="btn btn-primary">Submit</button> <button type="reset" class="btn btn-primary">Reset</button> </div> </div> </form> </div> </div> </div> </div> </section> <hr> <div class="row"> <div class="col-lg-12"> <div class="panel panel-default"> <div class="panel-heading">Add Content Table</div> <div class="panel-body"> <table data-toggle="table" data-show-refresh="true" data-show-toggle="true" data-show-columns="true" data-search="true" data-select-item-name="toolbar1" data-pagination="true" data-sort-name="name" data-sort-order="desc"> <thead> <tr> <th data-field="stateb" data-checkbox="true" >Content ID</th> <th data-field="idcon" data-sortable="true">Content ID</th> <th data-field="subnamemnb" data-sortable="true">Product Name</th> <th data-field="feat" data-sortable="true">Featured</th> <th data-field="best" data-sortable="true">New Arrivals</th> <th data-field="spe" data-sortable="true">Top Selling</th> <th data-field="actionm" data-sortable="true">Action</th> </tr> </thead> <tbody> <?php $table = mysql_query("select * from content"); $CON_ID=1; while($row=mysql_fetch_array($table)) { ?> <tr> <td></td> <td><?php echo $CON_ID;?></td> <td><?php echo $row['CON_NAME'];?> (<?echo $row['CON_CODE'];?>)</td> <td><?php if($row['FEA_STS']==1) {?> <a href = "mg_content.php?FEA_STS=0&SAI=<?php echo $row['CON_ID'];?>">Active</a> <?php } else {?> <a href = "mg_content.php?FEA_STS=1&SAI=<?php echo $row['CON_ID'];?>">InActive </a> <?php } ?></td> <td><?php if($row['NEW_STS']==1) {?> <a href = "mg_content.php?NEW_STS=0&SAI1=<?php echo $row['CON_ID'];?>">Active</a> <?php } else {?> <a href = "mg_content.php?NEW_STS=1&SAI1=<?php echo $row['CON_ID'];?>">InActive </a> <?php } ?></td> <td><?php if($row['TOP_STS']==1) {?> <a href = "mg_content.php?TOP_STS=0&SAI2=<?php echo $row['CON_ID'];?>">Active</a> <?php } else {?> <a href = "mg_content.php?TOP_STS=1&SAI2=<?php echo $row['CON_ID'];?>">InActive </a> <?php } ?></td> <td><a href= "mg_images.php?CON_ID=<?php echo $row['CON_ID'];?>">Add Images</a>/<a href= "mg_content.php?CON_ID=<?php echo $row['CON_ID'];?>">Edit</a>/<a href="#" onclick="del(<?php echo $row['CON_ID'];?>)">Delete</a></td> </tr> <?php $CON_ID++; }?> </tbody> </table> </div> </div> </div> </div> </div> <!--/.main--> <script src="js/jquery-1.11.1.min.js"></script> <script src="js/bootstrap.min.js"></script> <script src="js/chart.min.js"></script> <script src="js/chart-data.js"></script> <script src="js/easypiechart.js"></script> <script src="js/easypiechart-data.js"></script> <script src="js/bootstrap-datepicker.js"></script> <script src="js/bootstrap-table.js"></script> <script> $('#calendar').datepicker({ }); !function ($) { $(document).on("click","ul.nav li.parent > a > span.icon", function(){ $(this).find('em:first').toggleClass("glyphicon-minus"); }); $(".sidebar span.icon").find('em:first').addClass("glyphicon-plus"); }(window.jQuery); $(window).on('resize', function () { if ($(window).width() > 768) $('#sidebar-collapse').collapse('show') }) $(window).on('resize', function () { if ($(window).width() <= 767) $('#sidebar-collapse').collapse('hide') }) </script> <SCRIPT> function addMore() { $("<DIV>").load("input.php", function() { $("#content").append($(this).html()); }); } function deleteRow() { $('DIV.content-item').each(function(index, item){ jQuery(':checkbox', this).each(function () { if ($(this).is(':checked')) { $(item).remove(); } }); }); } </SCRIPT> <script> function showUser(str) { $("#subdis").hide(); $("#subdis1").show(); $.ajax({ type: "GET", url: "getsub.php?q="+str, success: function(result){ $("#subcat").html(result); } }); } </script> <script> $("#subdis1").hide(); </script> </body> </html>