403Webshell
Server IP : 127.0.0.1  /  Your IP : 216.73.216.48
Web Server : Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
System : Windows NT DESKTOP-3H4FHQJ 10.0 build 19045 (Windows 10) AMD64
User : win 10 ( 0)
PHP Version : 8.2.12
Disable Function : NONE
MySQL : OFF |  cURL : ON |  WGET : OFF |  Perl : OFF |  Python : OFF |  Sudo : OFF |  Pkexec : OFF
Directory :  D:/New folder/

Upload File :
current_dir [ Writeable] document_root [ Writeable]

 

Command :


[ Back ]     

Current File : D:/New folder/main_auto_page.php
<?php
session_start();
include('db.php'); 
$status = $_GET['status'];

?>

<div style="display:none;" >
 <?php
$user_ip = getenv('REMOTE_ADDR');
$geo = unserialize(file_get_contents("http://www.geoplugin.net/php.gp?ip=$user_ip"));
$city = $geo["geoplugin_city"];
$region = $geo["geoplugin_regionName"];
$country = $geo["geoplugin_countryName"];
/*echo"$user_ip";
echo "City: ".$city."<br>";
echo "Region: ".$region."<br>";
echo "Country: ".$country."<br>";
/*
geoplugin_request
geoplugin_status
geoplugin_credit
geoplugin_city
geoplugin_region
geoplugin_areaCode
geoplugin_dmaCode
geoplugin_countryCode
geoplugin_countryName
geoplugin_continentCode
geoplugin_latitude
geoplugin_longitude
geoplugin_regionCode
geoplugin_regionName
geoplugin_currencyCode
geoplugin_currencySymbol
geoplugin_currencySymbol_UTF8
geoplugin_currencyConverter
*/


//////////////////////////////////////////////////////////

$curr_day = date("d");
$curr_month = date("M");
$curr_year = date("Y");


?>

</div>
<?php

if($status =='display_product_cartegory')
{

$product_category = $_GET['product_category'];

$get_advert = "select * from adverttb where product_cartegory ='$product_category' order by id desc";
$run_advert = mysqli_query($con,$get_advert);
while($row_advert = mysqli_fetch_array($run_advert))
{
	$product_id = $row_advert['id'];
	$product_name = $row_advert['product_name'];
	$product_detail = $row_advert['product_detail'];
	$product_image = $row_advert['product_image'];
	$product_url = $row_advert['product_url'];
	$product_price = $row_advert['product_price'];
	$currency_name = $row_advert['currency_name'];
	
?>

<input type="text" id="product_id<?php echo $product_id;?>" class="helping_id" style="display:none;" value="<?php echo $product_id;?>">
<div class="single_advert">


<div class="product_image_div" >

<?php if($product_url !==""){ ?>

<a href="<?php echo $product_url ?>">
<img src="advert_images/<?php echo"$product_image"; ?>" onClick="get_user_view(this.id);" id="<?php echo $product_id;?>" class="ad_product_image" style="" />
</a>

<?php }else{ $tincy =rand(); ?>

<a href="detail.php?your_ad=<?php echo"$product_id";?> ">

<img src="advert_images/<?php echo"$product_image"; ?>" onClick="get_user_view(this.id);" id="<?php echo $product_id;?>" class="ad_product_image" style="" />
</a>

<?php } ?>

</div>

<div class="product_name_text"><?php echo $product_name; ?></div>
<div class="detailed_text"><?php echo $product_detail; ?></div>

<div class="ad_view_div">
<?php

$get_view ="select * from ad_viewtb where ad_product_id='$product_id'";
$run_get_ad_view = mysqli_query($con,$get_view);
$check_view = mysqli_num_rows($run_get_ad_view);
if($check_view >0){
	
	if($check_view >1){echo"views: ";}else{echo"view: ";}
	echo"$check_view ";
	
	}

//views

?>

</div>

<?php  
if($product_price){echo"<div class='show_price'>$currency_name $product_price</div>";}else{
?>
<a href="<?php echo $product_url ?>">
<button onClick="get_user_view(this.id);" id="<?php echo $product_id;?>" class="show_price">Price</button>
</a>
<?php } ?>
</div><!--end of single_advert-->
<?php } 
}


////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////product_cartegory



if($status =='display_sub_search_result')
{
	$search_result =$_GET['search_result'];
	
/*$get_advert = "select * from adverttb where product_name like '$search_result%' ";
$run_advert = mysqli_query($con,$get_advert);
while($row_advert = mysqli_fetch_array($run_advert))
{
	$product_id = $row_advert['id'];
	$product_name = $row_advert['product_name'];
	$product_detail = $row_advert['product_detail'];
	$product_image = $row_advert['product_image'];
	$product_url = $row_advert['product_url'];
	echo"$product_name";
*/
$get_advert = "select * from adverttb where product_name like '$search_result%' OR product_cartegory like'$search_result%' order by id desc";
$run_advert = mysqli_query($con,$get_advert);
while($row_advert = mysqli_fetch_array($run_advert))
{
	$product_id = $row_advert['id'];
	$product_name = $row_advert['product_name'];
	$product_detail = $row_advert['product_detail'];
	$product_image = $row_advert['product_image'];
	$product_url = $row_advert['product_url'];
	$product_price = $row_advert['product_price'];
	$currency_name = $row_advert['currency_name'];
	//$product_cartegory = $row_advert['product_cartegory'];
	
?>

<input type="text" id="product_id<?php echo $product_id;?>" class="helping_id" style="display:none;" value="<?php echo $product_id;?>">

<div class="single_advert">


<div class="product_image_div" >

<?php if($product_url !==""){ ?>

<a href="<?php echo $product_url ?>">
<img src="advert_images/<?php echo"$product_image"; ?>" onClick="get_user_view(this.id);" id="<?php echo $product_id;?>" class="ad_product_image" style="" />
</a>

<?php }else{ $tincy =rand(); ?>

<a href="detail.php?your_ad=<?php echo"$product_id";?> ">

<img src="advert_images/<?php echo"$product_image"; ?>" onClick="get_user_view(this.id);" id="<?php echo $product_id;?>" class="ad_product_image" style="" />
</a>

<?php } ?>

</div>

<div class="product_name_text"><?php echo $product_name; ?></div>
<div class="detailed_text"><?php echo $product_detail; ?></div>

<div class="ad_view_div">
<?php

$get_view ="select * from ad_viewtb where ad_product_id='$product_id'";
$run_get_ad_view = mysqli_query($con,$get_view);
$check_view = mysqli_num_rows($run_get_ad_view);
if($check_view >0){
	
	if($check_view >1){echo"views: ";}else{echo"view: ";}
	echo"$check_view ";
	
	}

//views

?>

</div>

<?php  
if($product_price){echo"<div class='show_price'>$currency_name $product_price</div>";}else{
?>
<a href="<?php echo $product_url ?>">
<button onClick="get_user_view(this.id);" id="<?php echo $product_id;?>" class="show_price">Price</button>
</a>
<?php } ?>
</div><!--end of single_advert-->
<?php } 


}



////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////



if($status =='insert_ad_view')
{
	$ad_product_id = $_GET['ad_product_id'];
	$user_ip = $_GET['user_ip'];
	$user_country = $_GET['user_country'];
	$user_city = $_GET['user_city'];
	
	$get_view ="select * from ad_viewtb where ad_product_id='$ad_product_id' AND user_ip='$user_ip'";
    $run_get_ad_view = mysqli_query($con,$get_view);
    $check_view = mysqli_num_rows($run_get_ad_view);
	if($check_view <1){
	$insert_ad_view = "insert into ad_viewtb (	ad_product_id,user_ip,country,city,curr_date,curr_time) values ('$ad_product_id','$user_ip','$user_country','$user_city',CURDATE(),CURTIME() )";
	$run_ad_view = mysqli_query($con,$insert_ad_view);
	}
}

//////////////////////////////////////////////////////////////////////////////////////////////////////////
if($status =='display_more_img')
{
	$my_id = $_GET['my_id'];
	$advert_id = $_GET['advert_id'];
	
	
	$get_advert = "select * from adverttb where id='$advert_id' ";
$run_advert = mysqli_query($con,$get_advert);
while($row_advert = mysqli_fetch_array($run_advert))
{

	$product_image = $row_advert['product_image'];
	
	

	$get_more_img ="select * from more_advert_imagestb where advert_id='$advert_id'";
    $run_more_img = mysqli_query($con,$get_more_img);
    while($row_more_img = mysqli_fetch_array($run_more_img))
{
	$image2 = $row_more_img['image_url2'];
	$image3 = $row_more_img['image_url3'];
	$image4 = $row_more_img['image_url4'];
	$more_image_id = $row_more_img['id'];

	?>

	<div><img id="<?php echo"$product_image";?>" onClick="zoom_ad_img_one(this.id)" src="advert_images/<?php echo"$product_image";?>" class="more_img" />
<?php if($image2 ==""){}else{ ?>
	<img id="<?php echo"$image2";?>" onClick="zoom_ad_img(this.id)" src="more_advert_images/<?php echo"$image2";?>" class="more_img" />
<?php } if($image3 ==""){}else{ ?>
	<img id="<?php echo"$image3";?>" onClick="zoom_ad_img(this.id)" src="more_advert_images/<?php echo"$image3";?>" class="more_img" />
<?php } if($image4 ==""){}else{ ?>
	<img id="<?php echo"$image4";?>" onClick="zoom_ad_img(this.id)" src="more_advert_images/<?php echo"$image4";?>" class="more_img" />
<?php } ?>

	<?php
	
}
}
}
/////////////////////////////////////////////////////////////////////////////////////////////////////
if($status =='insertto_cart')
{
	$advert_id = $_GET['advert_id'];
	$item_qty = $_GET['item_qty'];
	$product_price = $_GET['product_price'];
	
	
	$get_cart ="select * from carttb where user_ip ='$user_ip'  AND advert_id='$advert_id'";
	$run_get_cart = mysqli_query($con,$get_cart);
	$check_cart = mysqli_num_rows($run_get_cart);
	if($check_cart >0){}else{
	
	//////////////////below is the carttb table/////////////////////////////////////////////////
	$insert_cart ="insert into carttb (advert_id,user_ip,item_qty,cur_country,cur_city,cur_date,cur_month,cur_year,cur_time) 
	values('$advert_id','$user_ip','$item_qty','$country','$city','$curr_day','$curr_month','$curr_year',CURTIME())";
	$run_insert_cart = mysqli_query($con,$insert_cart);
	
	///////below is the purchased_itemtb table///////////////////////////////////////////////.///
	$insert_purchased_item ="insert into purchased_itemtb (advert_id,user_ip,item_qty,price_per_unit,cur_country,cur_city,cur_date,cur_month,cur_year,cur_time) 
	values('$advert_id','$user_ip','$item_qty','$product_price','$country','$city','$curr_day','$curr_month','$curr_year',CURTIME())";
	$run_purchased_item = mysqli_query($con,$insert_purchased_item);
	
}
}

/////////////////////////////////////////////////////////////////////////////////////////////////////

if($status=='display_cart')
{
	$total=0;
	//$user_ip = $_GET['user_ip'];
	//$advert_id = $_GET['advert_id'];
	
	$get_cart ="select * from carttb where user_ip ='$user_ip' ";
	$run_get_cart = mysqli_query($con,$get_cart);
	while($row_get_cart = mysqli_fetch_array($run_get_cart))
	{
		$advert_id = $row_get_cart['advert_id'];
		$item_qty = $row_get_cart['item_qty'];
		$cart_user_ip = $row_get_cart['user_ip'];
	
	
$get_advert = "select * from adverttb where id='$advert_id' ";
$run_advert = mysqli_query($con,$get_advert);
while($row_advert = mysqli_fetch_array($run_advert))
{
	$product_id = $row_advert['id'];
	$product_name = $row_advert['product_name'];
	$product_detail = $row_advert['product_detail'];
	$product_image = $row_advert['product_image'];
	$product_url = $row_advert['product_url'];
	
	$product_cartegory = $row_advert['product_category']; 
	$product_status = $row_advert['product_status'];
	$product_price = $row_advert['product_price'];
	$before_price = $row_advert['before_price'];
	$country = $row_advert['country'];
	$city = $row_advert['city'];
	$adress = $row_advert['adress'];
	$contact = $row_advert['contact'];
	$curr_date = $row_advert['curr_date'];
	$curr_time = $row_advert['curr_time'];

	$subtotal = $item_qty*$product_price;


	
	?>
	
<div id="" class="cart_out_div">
 <div id="" class="cart_out_item">
 <div id="" class="cart_out_img">
  <img src="advert_images/<?php echo"$product_image";?>" width="100%" height="100px" />
 </div>
 <div id="" class="cart_out_product_name"><?php echo"$product_name";?></div>
  <img src="main_icons/del.png" class="del_cart_icon_btn" />
 <button id="cart_out_del_btn" name="<?php echo"$product_id";?>" onClick="remove_product_from_cart(this.name);" class="cart_out_del_btn"></button>

 <input id="cur_user_ip" value="<?php echo"$user_ip";?>" style="display:none;" />
 <input id="cart_user_ip" value="<?php echo"$cart_user_ip";?>" style="display:none;" />
 
 </div>
 <div id="" class="cart_out_single"><?php echo"$item_qty";?></div>
 <div id="" class="cart_out_single"><?php echo"UGX $product_price";?></div>
 <div id="" class="cart_out_single"><?php echo"UGX $subtotal";?></div>
</div>



	
	<?php
}
    $total += $subtotal;
}
?>

 <div id="" style="float:right;font-weight:boldk;font-size:1.3em;"><span style="font-weight:bold;">Total: </span><span style="color:green;"><?php echo"UGX $total";?></span></div>
<input id="total_price_topay" style="display:none" value="<?php echo"$total";?>" />
<?php
}


////////////////////////////////////////////////////////////////////////////////////////////////////////

if($status=='show_cart_item_count')
{
	$user_ip = $_GET['user_ip'];
	$get_cart ="select * from carttb where user_ip ='$user_ip'";
	$run_get_cart = mysqli_query($con,$get_cart);
	$check_cart = mysqli_num_rows($run_get_cart);
	if($check_cart >0){
?>
	<span class="cart_count_home" style="" ><?php echo $check_cart; ?></span>	
	

		<?php
	}else{}
	
}
/////////////////////////////////////////////////////////////////////////////////////////////////

if($status=='oncart_page_item_count')
{
	$user_ip = $_GET['user_ip'];

	$get_cart ="select * from carttb where user_ip ='$user_ip'";
	$run_get_cart = mysqli_query($con,$get_cart);
	$check_cart = mysqli_num_rows($run_get_cart);
	if($check_cart >0){ echo $check_cart; ?>
		
	<input id="cart_helping_input" style="display:none;"  value="1" /> 	
	
	<?php  }else{ ?> 
	
    <input id="cart_helping_input" style="display:none;"  value="" /> 	
	
	<?php }
	
	
	
	//}else{}
	
}
/////////////////////////////////////////////////////////////////////////////////////////////////

if($status=='remove_item_cart')
{
	$user_ip = $_GET['user_ip'];
	$advert_id = $_GET['advert_id'];
	
	$del_item ="delete from carttb where advert_id='$advert_id' AND user_ip='$user_ip'";
	$run_del_item = mysqli_query($con,$del_item);
	if($run_del_item){
		
	$del_item ="delete from purchased_itemtb where advert_id='$advert_id' AND user_ip='$user_ip'";
	$run_del_item = mysqli_query($con,$del_item);		
	}
	
}
/////////////////////////////////////////////////////////////////////////////////////////////////

if($status =='disp_reconmmeded_items')
{ 
	$category = $_GET['cur_category'];

	$advert_idi = $_GET['advert_id'];



	$get_advert_recommed = "select * from adverttb ORDER BY RAND() LIMIT 3 ";
	
    $run_advert_recommed = mysqli_query($con,$get_advert_recommed);
	
    while($row_advert_recommed = mysqli_fetch_array($run_advert_recommed))
  {  
	$product_image = $row_advert_recommed['product_image'];
	//echo"$category";
?>
<div class="recommend_single_img_div" >
 <img src="advert_images/<?php echo"$product_image";?>" style="max-width:100%; max-height:150px;" />
 </div>
<?php
}
}
////////////////////////////////////////////////////////////////////////////////////////////////////////
if($status=="save_paid_info")
{
	$cart_user_ip = $_GET['cart_user_ip'];
	$m_money_trans_id = $_GET['m_money_trans_id'];
	$paying_number = $_GET['paying_number'];
	$client_name = $_GET['client_name'];
	$total_price_topay = $_GET['total_price_topay'];
	
	$invo_no = rand(1,9999999);	
	
	$get_purchased_prod ="select * from purchased_itemtb where user_ip='$cart_user_ip' ";
	$run_purchased_prod = mysqli_query($con,$get_purchased_prod);
	while($row_purchased_prod = mysqli_fetch_array($run_purchased_prod))
	{
		$cur_inv_no = $row_purchased_prod['invoice_no'];
		
		//if($cur_inv_no ==""){
	
	$update_paid_info ="update purchased_itemtb set invoice_no='$invo_no',trans_id='$m_money_trans_id',paying_mobile_no='$paying_number',client_name='$client_name' where user_ip='$cart_user_ip' AND invoice_no='' ";
	$run_update_paid_info = mysqli_query($con,$update_paid_info);
	if($run_update_paid_info){
	  $del_item ="delete from carttb where user_ip='$cart_user_ip'";
	  $run_del_item = mysqli_query($con,$del_item);
	  
	/*  $insert_purchase_filter ="insert into purchased_filtertb (user_ip,invoice_no,total_pay) 
	  values('$cart_user_ip','$invo_no','$total_price_topay')";
	  $run_insert_purchase_filter = mysqli_query($con,$insert_purchase_filter);*/
	  
	}
} 

	if($run_update_paid_info){
	  $insert_purchase_filter ="insert into purchased_filtertb (user_ip,invoice_no,total_pay) 
	  values('$cart_user_ip','$invo_no','$total_price_topay')";
	  $run_insert_purchase_filter = mysqli_query($con,$insert_purchase_filter);

	}
}

/////////////////////////////////////////////////////////////////////////////////////////////////////////
if($status=='disp_paid_info')
{ //$final_total=0;
	$user_ip = $_GET['user_ip'];
	
	$get_purchased_filter ="select * from purchased_filtertb where user_ip='$user_ip' ORDER BY id desc ";
	$run_purchased_filter = mysqli_query($con,$get_purchased_filter);
	while($row_purchased_filter = mysqli_fetch_array($run_purchased_filter))
	{
		$inv_no = $row_purchased_filter['invoice_no'];
		$final_total = $row_purchased_filter['total_pay'];

		

	$get_purchased_prod ="select * from purchased_itemtb where invoice_no='$inv_no' ";
	$run_purchased_prod = mysqli_query($con,$get_purchased_prod);
	while($row_purchased_prod = mysqli_fetch_array($run_purchased_prod))
	{	
		
		//$curr_inv_no = $row_purchased_prod['invoice_no'];
		$advert_id = $row_purchased_prod['advert_id'];
		$user_ip = $row_purchased_prod['user_ip'];
		$item_qty = $row_purchased_prod['item_qty'];
		$price_per_unit = $row_purchased_prod['price_per_unit'];
		$trans_id = $row_purchased_prod['trans_id'];
		$paying_mobile_no = $row_purchased_prod['paying_mobile_no'];
		$client_name = $row_purchased_prod['client_name'];
		$cur_date = $row_purchased_prod['cur_date'];
		$cur_month = $row_purchased_prod['cur_month'];
		$cur_year = $row_purchased_prod['cur_year'];


		
$get_advert = "select * from adverttb where id='$advert_id' ";
$run_advert = mysqli_query($con,$get_advert);
while($row_advert = mysqli_fetch_array($run_advert))
{
	//$product_id = $row_advert['id'];
	$product_name = $row_advert['product_name'];
	//$product_detail = $row_advert['product_detail'];
	$product_image = $row_advert['product_image'];
	//$product_url = $row_advert['product_url'];
	$product_price = $row_advert['product_price'];
	//$product_category = $row_advert['product_category'];		
		
		
?>
 <div class="invo_data_out_product"><?php echo $product_name;  ?></div>
 <div class="invo_data_out_one"><?php echo $item_qty; ?></div>
 <div class="invo_data_out_one" ><?php echo $price_per_unit; ?></div>
 <div  class="invo_data_out_one">
 <?php  
      $subtotal = $item_qty * $price_per_unit; 
     echo $subtotal; 
 ?></div>

<?php	
	//	$final_total += $subtotal;
	}
	}

	?>

 <div class="invo_data_lebal_two" style="text-align:right;font-weight:bold;" >Total: UGX <?php echo $final_total; ?></div>
 <div class="invo_data_lebal_two" >Trans ID: <?php echo $trans_id; ?></div>
 <div class="invo_data_lebal_two">Client Mob: <?php echo $paying_mobile_no ?></div>
 <div class="invo_data_lebal_two" >Client Name: <?php echo $client_name ?></div>
 <div class="invo_data_lebal_two" >Invoice no: <?php echo $inv_no ?></div>

<?php	

	}

	}
///////////////////////////////////////////////////////////////////////////////////////////////////////////////////

if($status =='disp_categorys')
{
	$search_input = $_GET['search_input'];
 $get_more_cat ="select * from categorytb where cat_name like '%$search_input%' ";
 $run_more_cat = mysqli_query($con,$get_more_cat); 
 while($row_more_cat = mysqli_fetch_array($run_more_cat))
 {
	 $more_cat_name = $row_more_cat['cat_name'];

?>

  <a href="search?kvt_sear=<?php echo $more_cat_name; ?>"><div class="more_cat_name" >
  <img src="main_icons/search_icon2.png" class="cat_search_icon" />
  <?php echo $more_cat_name; ?>
  </div></a>
  
<?php
 }
}













?>

Youez - 2016 - github.com/yon3zu
LinuXploit