403Webshell
Server IP : 51.89.169.208  /  Your IP : 216.73.216.9
Web Server : Apache
System : Linux ns3209505.ip-198-244-202.eu 4.18.0-553.27.1.el8_10.x86_64 #1 SMP Tue Nov 5 04:50:16 EST 2024 x86_64
User : yellowleaf ( 1019)
PHP Version : 7.4.33
Disable Function : exec,passthru,shell_exec,system
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /home/yellowleaf/public_html/members/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/yellowleaf/public_html/members//NEW_editbusiness3.html
<?php
$path  = $_SERVER['DOCUMENT_ROOT'];
include_once $path.'/connect_db.php';
include 'accesscontrol.php';
$adid=$_GET['adid'];
$min_limit = 10;
$max_limit = 50;
// css for menu
if(isset($_POST['submit'])){


	$monday=addslashes($_POST['monday']);
	$tuesday=addslashes($_POST['tuesday']);
	$wednesday=addslashes($_POST['wednesday']);
	$thursday=addslashes($_POST['thursday']);
	$friday=addslashes($_POST['friday']);
	$saturday=addslashes($_POST['saturday']);
	$sunday=addslashes($_POST['sunday']);
	$serv1 = array_filter(array_map('trim',($_POST['serv'])));

	foreach($serv1 as $key => $value){
		$serv .= trim($value);
		if($key != (count($serv1) - 1)){
			$serv .= " || ";
		}
	}
	
	
	$promotion=addslashes($_POST['promotion']);
	$urlPattern='#^http[s]?://+#i';
	$facebook=preg_replace($urlPattern,"",addslashes($_POST['facebook']));
	$twitter=preg_replace($urlPattern,"",addslashes($_POST['twitter']));
	$google=preg_replace($urlPattern,"",addslashes($_POST['google']));
	$youtube=preg_replace($urlPattern,"",addslashes($_POST['youtube']));
	$linkedin=preg_replace($urlPattern,"",addslashes($_POST['linkedin']));
	
	
	if($promotion==""){$promotion=0;}else{$promotion=1;} // if promo set it as 1 if not 0
	
	/// operning hours table
	$q3 = "UPDATE `opening_hours` SET 
		 `monday` = '$monday',
		 `tuesday` = '$tuesday',
		 `wednesday` = '$wednesday',
		 `thursday` = '$thursday',
		 `friday` = '$friday',
		 `saturday` = '$saturday',
		 `sunday` = '$sunday'
		 WHERE `opadid` = '$adid'";
	$r3 =  $connect->query($q3) or die($connect->error);
	
	/// ads table
	$promo = "UPDATE `ads` SET `services_offered`= '$serv',`promotion` = '$promotion',`completed` = '1' WHERE `adid` = '$adid' and `memberid` = '$memberid'";
	$promo_row =  $connect->query($promo) or die($connect->error);
	
	/// promotions table
	$prom_title=addslashes($_POST['prom_title']);
	$prom_desc=addslashes($_POST['prom_desc']);
	$prom_date=time();
	$expiry_day=addslashes($_POST['expiry_day']);
	$expiry_month=addslashes($_POST['expiry_month']);
	$expiry_year=addslashes($_POST['expiry_year']);
	$valid_day=addslashes($_POST['valid_day']);
	$valid_month=addslashes($_POST['valid_month']);
	$valid_year=addslashes($_POST['valid_year']);
	
	// converting valid
	$val=$valid_month.'/'.$valid_day.'/'.$valid_year;
	$prom_valid=strtotime($val);
	
	// converting expiry
	$expiry_dmy=$expiry_month.'/'.$expiry_day.'/'.$expiry_year;
	$prom_expiry=strtotime($expiry_dmy);
	
	if($promotion==1){
	$q5 = "UPDATE promotions SET
			member_id = '$memberid',
			ad_id = '$adid',
			prom_title = '$prom_title',
			prom_desc = '$prom_desc',
			prom_date = '$prom_date',
			prom_valid = '$prom_valid',
			prom_expiry = '$prom_expiry'
			WHERE `ad_id` = '$adid' AND `ad_id` = '$adid'";

	$r5 = $connect->query($q5) or die($connect->error);
	}
	if($_POST['facebook']!=""||$_POST['twitter']!=""||$_POST['google']!=""||$_POST['youtube']!=""||$_POST['linkedin']!=""){
	$q6 = "UPDATE social_links SET
			facebook = '$facebook',
			googleplus = '$google',
			twitter = '$twitter',
			youtube = '$youtube',
			linkedin = '$linkedin'
			WHERE `so_member_id` = '$memberid' AND
			`so_ad_id` = '$adid'";

	$r6 = $connect->query($q6) or die($connect->error);
	}

	?><script>location.href='editbusiness4.html?adid=<?=$adid?>'</script><?
}

// for opening times
$add_que_sql = $connect->query("SELECT * FROM opening_hours WHERE opadid ='{$adid}'");
$add_row = $add_que_sql->fetch_assoc();


// for promotion
$promo_que_sql = $connect->query("SELECT * FROM ads WHERE `adid` = '$adid' and `memberid` = '$memberid'");
$promo_row = $promo_que_sql->fetch_assoc();
$services = array_filter(explode("||",$promo_row['services_offered']));

//print_r($services);
//die();


// for social
$social_que_sql = $connect->query("SELECT * FROM social_links WHERE `so_ad_id` = '$adid' and `so_member_id` = '$memberid'");
$social_row = $social_que_sql->fetch_assoc();
?>
<!DOCTYPE html>
<html lang="en">
   <head>
	  <title>YellowLeaf - Homepage</title>
      <meta charset="UTF-8">
      <meta http-equiv="X-UA-Compatible" content="IE=edge">
      <meta name="viewport" content="width=device-width, initial-scale=1.0">
      <link rel="stylesheet" href="/header-footer/global.css">
	  <link rel="stylesheet" href="submit-advert.css">
      <script src="https://code.jquery.com/jquery-3.6.0.min.js" integrity="sha256-/xUj+3OJU5yExlq6GSYGSHk7tPXikynS7ogEvDej/m4=" crossorigin="anonymous"></script>
	  <style>
		.error { color: #ff0000f7;}
	  </style>
</head>
<?php
include_once $path.'/header-footer/header.html';
?>
<script type="text/javascript">


function promCheck(){
var promCheckBox = document.getElementById('promo_check');
var addPromo = document.getElementById('add_promo');
	if(promCheckBox.checked==false){
		addPromo.style.display='none';
		promCheckBox.value='0';
	}else{
		addPromo.style.display='';
		promCheckBox.value='1';
	}
}
</script>
<section>
        <div class="container">
            <div class="advert-wrapper">
                <div class="advert-menu">
                    <div class="advert-menu-wrapper">
                        <a href="#">Manage Advert</a>
                        <a href="postbusiness1.html" class="active">Submit Advert</a>
                        <a href="#">My Account</a>
                        <a href="/support">Help & Support</a>
                        <a href="#">Logout</a>
                    </div>
                </div>
                <div class="advert-main">
                    <div class="advert-main-title">Submit Advert</div>
                    <div class="submit-advert-tab">
                        <span >1</span>
                        <span>2</span>
                        <span class="active">3</span>
                        <span>4</span>
                        <span>5</span>
                        <span>6</span>
                    </div>
                    <form class="submit-advert-form"  action="" method="POST" enctype="multipart/form-data">
						<?=$postbusiness_error?>
                        <div class="submit-advert-form-group">
                            <label for="name">Products, Services or Facilities:</label>
                            <p class="submit-advert-label-description <?=$errorcompanyname?>">Please enter products, services or facilities that your business offers.</p>

							<?php for($i=0;$i<4;$i++) { ?>
								<input   type="text" name="serv[]" placeholder="Products, services or facilities <?=$i+1?>" class="form-control" value="<?= $services[$i]; ?>"><br>
							<?php } ?>
							
							
                        </div>
						
						<div class="submit-advert-form-group">
                            <label for="name">Opening Times:</label>
                            <p class="submit-advert-label-description <?=$errorcompanyname?>">Please enter products, services or facilities that your business offers.</p>
							<?php
							$days = [
							 'monday','tuesday','wednesday','thursday','friday','staruday','sunday'
							];

							foreach($add_row as $key => $day) { 
								if($key != "opid" && $key != "opadid" && $key != "done"){
							?>
                            <input placeholder="<?=ucfirst($key)?>"  type="text" name="<?=$key?>" value="<?=$day?>" class="form-control">
							<br>
							<?php } } ?>
							
                        </div>
                        
						
						
                       
                        <div class="submit-advert-form-group">
                            <label for="facebook">Promotional Deals & Offers (optional):</label>
                            <p class="submit-advert-label-description ">Please state any promotional deals or offers that your business is currently offering</p>
                            <input  name="promotion" onclick="promCheck()" value="0" type="checkbox" id="promo_check" class="">
							<label>I wish to add a promotion</label>
							
                        </div>
						
                        <div id="add_promo" style="display:none;margin-top:20px;background-color:#f6f6f6;color:#444;">
							<div class="submit-advert-form-group">
								<label for="name">Promotion Title:</label>
								<p class="submit-advert-label-description <?=$errorprom_title?>">Please enter the title of your business promotion.</p>
								<input value="<?=$prom_title?>"  type="text" name="prom_title"  id="prom_title" class="form-control">
								
							</div>
							<div class="submit-advert-form-group">
								<label for="prom_desc">Business Address:</label>
								<p class="submit-advert-label-description <?=$errorprom_desc?>">Please enter the address of your business.</p>
								<textarea id="prom_desc" name="prom_desc" cols="30" rows="5" class="form-control"><?=$prom_desc?></textarea>
							</div>
							<div class="submit-advert-form-group">
								<label for="type">Promotion Valid From:</label>
								<p class="submit-advert-label-description <?=$errorbtype?>">Please enter the date that your promotion is valid from.</p>
								
								<select class="form-control" name="valid_day">
									<option value="" selected="">Day</option>
									<?php for($i=1;$i<31;$i++) { ?>
									<option value="<?=$i?>" ><?=$i?></option>
									<? } ?>
								</select>
								<br>
								<select class="form-control" name="valid_month">
									<option value="" selected="">Month</option>
									<?php for($i=1;$i<=12;$i++) { ?>
									<option value="<?=$i?>" ><?=$i?></option>
									<? } ?>
								</select>
								<br>
								<select class="form-control" name="valid_year">
									<option value="" selected="">Year</option>
									<?php
										$year = date('Y');
										$lyear = $year+50;
									?>
									<?php for($i=$year;$i<$lyear;$i++) { ?>
									<option value="<?=$i?>" ><?=$i?></option>
									<? } ?>
								</select>
						
							</div>
							
							<div class="submit-advert-form-group">
								<label for="type">Promotion Expiry:</label>
								<p class="submit-advert-label-description <?=$errorbtype?>">Please enter the expiry date of your promotion.</p>
								
								<select class="form-control" name="valid_day">
									<option value="" selected="">Day</option>
									<?php for($i=1;$i<31;$i++) { ?>
									<option value="<?=$i?>" ><?=$i?></option>
									<? } ?>
								</select>
								<br>
								<select class="form-control" name="valid_month">
									<option value="" selected="">Month</option>
									<?php for($i=1;$i<=12;$i++) { ?>
									<option value="<?=$i?>" ><?=$i?></option>
									<? } ?>
								</select>
								<br>
								<select class="form-control" name="valid_year">
									<option value="" selected="">Year</option>
									<?php
										$year = date('Y');
										$lyear = $year+50;
									?>
									<?php for($i=$year;$i<$lyear;$i++) { ?>
									<option value="<?=$i?>" ><?=$i?></option>
									<? } ?>
								</select>
						
							</div>
						
                        </div>
						
						<div class="submit-advert-form-group">
                            <label for="facebook">Your Social Links (optional):</label>
                            <p class="submit-advert-label-description <?=$errorpostcode?>">Please provide the links to your social pages</p>


							<? if($social_row['facebook']==''){$social_fb='http://';}else{$social_fb=$social_row['facebook'];}?>
							<input placeholder="facebook"  type="text" name="facebook" value="<?=$social_fb?>"  class="form-control">
							<br>

							<? if($social_row['twitter']==''){$social_twit='http://';}else{$social_twit=$social_row['twitter'];}?>
							<input placeholder="twitter"  type="text" name="twitter" value="<?=$social_twit?>"  class="form-control">
							<br>

							<? if($social_row['googleplus']==''){$social_ggl='http://';}else{$social_ggl=$social_row['googleplus'];}?>
							<input placeholder="google plus"  type="text" name="google" value="<?=$social_ggl?>"  class="form-control">
							<br>

							<? if($social_row['youtube']==''){$social_utube='http://';}else{$social_utube=$social_row['youtube'];}?>
							<input placeholder="youtube"  type="text" name="youtube" value="<?=$social_utube?>"  class="form-control">
							<br>

							<? if($social_row['linkedin']==''){$social_lnkdin='http://';}else{$social_lnkdin=$social_row['linkedin'];}?>
							<input placeholder="linkedin"  type="text" name="linkedin" value="<?=$social_lnkdin?>"  class="form-control">
							<br>
							
                        </div>
						
                        <button type="submit" name="submit" class="btn btn-yellow">Next</button>
                    </form>
                </div>
            </div>
        </div>
    </section>
<?php
   include_once $path.'/header-footer/footer.html';
?>
<script>
var  country = '<?=$countys?>';
var  town = '<?=$town?>';
get_town_drop(country,town);
function get_town_drop(value,town){
	
	var xmlhttp = false;
	var xmlhttp = (window.XMLHttpRequest) ? xmlhttp=new XMLHttpRequest() : xmlhttp=new ActiveXObject("Microsoft.XMLHTTP");
	xmlhttp.onreadystatechange=function() {
		if (xmlhttp.readyState==4 && xmlhttp.status==200){
			document.getElementById("town").innerHTML = xmlhttp.responseText;
			return true;
		}
	}
	xmlhttp.open("GET","ajax/get_town.ajax.php?value="+value+'&town='+town,true);
	xmlhttp.send();
}


</script>

Youez - 2016 - github.com/yon3zu
LinuXploit