[ Th3_Err0r Bypassed ]




Upload:

Command:

liwaavux@216.73.217.165: ~ $
<?php 
ob_start();
session_start();
?>
<?php
$fb = '';
$ft = '';
if(isset($_GET['fb'])){
    $res = filter_var($_GET['fb'], FILTER_SANITIZE_STRING);
    $fb = 'WHERE code ='  .  "'$res'" ;
}
if(isset($_GET['ft'])){
    $res = filter_var($_GET['ft'], FILTER_SANITIZE_NUMBER_INT);
    $fb = 'WHERE type ='  .  "'$res'" ;
}
?>
<?php
if(isset($_SESSION['user_liwwan_admin_2023930']) AND ($_SESSION['type'] == "manager_session_alliwan") ){
    $pageTitle  = 'alliwan / Projects ';
    include 'init.php';

$stmt = $conn->prepare("SELECT * FROM projects $fb $ft ORDER BY pid DESC ");
// Excute the ststment
$stmt->execute();
//Assign To varriable
$rows = $stmt->FetchAll();
/*if($rows['adminid'] != 1)  {
    header('Location:logout.php');
    exit;
}*/
?>
<?php if( (isset($_GET['okshow'])) || (isset($_GET['pendshow'])) || (isset($_GET['delpr'])) || (isset($_GET['added'])) || (isset($_GET['shhead'])) || (isset($_GET['xshhead'])) || (isset($_GET['edpr'])) ) { ?>
    <section class="myalertsec">
        <div class="container">
        <div class="alert alert-dismissible fade show  alert-emp" role="alert">
         <?php if(isset($_GET['okshow'])) {?>
         <?php echo "تم تمكين عرض المشروع في الرئيسية بنجاح";
          }elseif(isset($_GET['pendshow'])) {?>
           <?php echo "تم إلغاء عرض المشروع في الرئيسية بنجاح";
            }elseif(isset($_GET['delpr'])) {?> 
          <?php echo "لقد تم حذف المشروع بنجاح" ;
          }elseif(isset($_GET['added'])) {?> 
          <?php echo "لقد تم إضافة المشروع بنجاح" ;
          }elseif(isset($_GET['shhead'])) {?> 
            <?php echo "تم تمكين عرض المشروع في صفحة الحاسبة بنجاح" ;
            }elseif(isset($_GET['xshhead'])) {?> 
                <?php echo "تم إلغاء عرض المشروع في صفحة الحاسبة بنجاح" ;
                }elseif(isset($_GET['edpr'])) {?> 
                    <?php echo "تم تعديل صورة مشروع" ;
                    }?>
        <button type="button" class="btn-close bg-white rounded m-3 p-1" data-bs-dismiss="alert" aria-label="Close"></button>
        </div>
        </div>
    </section>
    <?php }?>

    <section class="con-benfs">
        <div class="container">
        <div class="row ">
            <div class="col-12 w-25 m-auto">
            <p  class="text-center bg-dark text-white fw-bold rounded" data-bs-toggle="collapse" data-bs-target="#serchcollapse" aria-expanded="false" aria-controls="serchcollapse">
                <span> فلترة المشاريع </span><span><i class="fa-solid fa-sort-down fs-4 text-light text-center px-1"></i></span>
            </p>
            </div>
            <div class="collapse mt-2" id="serchcollapse">
            <div class="card card-body">
                
            <div class="search container text-center p-3 rounded">
                <div class="input-group row mt-2 mb-2">
                    <div class="col-md-6 col-sm-12">
                    <div class="autocomplete-wrap">
                        <form action="" method="GET">
                        <div class="row">
                        <div class="col-lg-8 col-sm-12">
                        <select class="text-center text-dark bg-white border-0 rounded w-75 m-auto py-2" type="text" name="ft">
                            <option disabled value="" class="bg-dark text-white px-3 fw-bold" selected>إختر نوع المشروع</option>
                            <option value="1"> ديكور داخلي </option>
                            <option value="2"> تصميم خارجي </option>
                            <option value="3"> مكاتب شركات </option>
                            <option value="4"> تنسيق حدائق </option>
                            <option value="5"> تصميم فيلا </option>
                            <option value="6"> تصميم & تنفيذ </option>
                        </select>
                        </div>
                        <div class="col-lg-4 col-sm-12">
                            <button type="submit" class="btn py-2 px-3 fw-bold rounded"> ok</button>
                        </div>
                        </div>
                        </form>
                    </div>
                    </div>
                    <div class="col-md-6 col-sm-12">
                      <div class="autocomplete-wrap">
                     <form action="" method="GET">
                        <div class="row">
                        <div class="col-md-8 col-sm-12">
                            <input  type="text" name="fb" id="search-textbox" class="py-2 rounded fw-bold px-3 text-center" autocomplete="off"
                            area-lable="search-bycontractcusid" placeholder="أدخل معرف المشروع "
                            area-describedby="search-button"/> 
                        </div>
                        <div class="col-md-4 col-sm-12">
                            <button type="submit" class="btn py-2 px-3 fw-bold rounded"> ok</button>
                        </div>
                        </div>
                     </form>
                    </div>
                    </div>
                </div>
            </div>
            </div>
            </div>
        </div>
    </div>
</section>
<div class="noresult m-0 p-0">
    <?php
    if ((isset($_GET['ft'])) AND (empty($rows))) 
    {echo "<p class='container text-center fw-bold text-dark mb-2 w-50 rounded-pill h5 p-4  bg-warning mt-5'>" .  "لايوجد نتائج مطابقة للبحث" . "</p>" . "<br>";
    echo "<a href='projects.php'>" . "<p class='container text-center fw-bold text-white mb-5 w-25 rounded-pill fs-6 p-3  bg-primary mt-2'>" .  "عودة لصفحة المشاريع" . "</p>" . "</a>";
    }if((isset($_GET['fb'])) AND (empty($rows))) {
        echo "<p class='container text-center fw-bold text-dark mb-2 w-50 rounded-pill h5 p-4  bg-warning mt-5'>" .  "لايوجد نتائج مطابقة للبحث" . "</p>" . "<br>";
    echo "<a href='projects.php'>" . "<p class='container text-center fw-bold text-white mb-5 w-25 rounded-pill fs-6 p-3  bg-primary mt-2'>" .  "عودة لصفحة المشاريع" . "</p>" . "</a>";
    }?>
</div>
<section class="admins_sess">
    <h1 class="member-h1"> Projects </h1>
    <div class="container-fluid">
        <a href ="add_project.php" class="btn-add fw-bold">+ New Project</a><br>
        <div class="table-responsive my-4">
            <table class="main-table table  table-dark table-striped text-center mb-5 p-3  table-hover table-bordered border-muted" style="width:100%;overflow-x:scroll!important;">
                <tr>
                    <td >#ID</td>
                    <td>tittle</td>
                    <td>code</td>
                    <td>img</td>
                    <td>compname</td>
                    <td>type</td>
                    <td>description</td>
                    <td>country</td>
                    <td>done date</td>
                    <td class="w-25">controll</td>
                </tr>
                         <?php
                        foreach ($rows as $row ) {?>
                        <tr>
                            <td><?php echo $row ['pid']; ?></td>
                            <td><?php echo $row ['ar_tittle']; ?></td>
                            <td><?php echo $row ['code']; ?></td>
                            <td><img src="images/uploads/projects/<?php echo $row ['img1']; ?>" class="img-fluid pr_img" alt=""></td>
                            <td><?php echo $row ['ar_compname']; ?></td>
                            <td>
                            <?php
								if ($row['type'] == 1) {
									echo 'ديكور داخلي';
								}elseif ($row['type'] == 2) {
									echo 'تصميم خارجي';
								}elseif ($row['type'] == 3) {
									echo 'مكاتب شركات';
								}elseif ($row['type'] == 4) {
									echo 'تنسيق حدائق';
								}elseif ($row['type'] == 5) {
									echo 'تصميم فيلا';
								}elseif ($row['type'] == 6) {
									echo 'تصميم & تنفيذ';
								}
								 ?>
                            </td>
                            <td><?php echo $row ['ar_description']; ?></td>
                            <td><?php echo $row ['ar_country']; ?></td>
                            <td><?php echo $row ['donedate']; ?></td>
                            <td>
                            <div class="row">
                                <div class="col-lg-3 col-sm-12 mt-1">
                                    <form action="ac_projects.php" method="POST">
                                    <input type="hidden" name="pr_id" value="<?php echo $row ['pid'];?>">
                                        <button href="ac_projects.php" type="submit" name="delproject" onclick="return confirm('متأكد من حذف المشروع');" class="w-100 btn btn-danger fw-bold bg-none border-0">D</button>
                                    </form>
                                </div>
                                <div class="col-lg-3 col-sm-12 mt-1">
                                    <form action="imgs.php" method="POST">
                                        <input type="hidden" name="pr_id" value="<?php echo $row ['pid'];?>">
                                        <button href="imgs.php" type="submit" name="edit_imgs" class="w-100 btn btn-dark fw-bold bg-none border-0">img</button>
                                    </form>
                                </div>
                                <div class="col-lg-3 col-sm-12 mt-1">
                                    <form action="ac_edit_pr.php" method="POST">
                                        <input type="hidden" name="pr_id" value="<?php echo $row ['pid'];?>">
                                        <button href="ac_edit_pr.php" type="submit" name="edit_pr" class="w-100 btn btn-info fw-bold bg-none border-0">ED</button>
                                    </form>
                                </div>
                                <div class="col-lg-3 col-sm-12 mt-1">
                                    <form action="show.php" method="POST">
                                    <input type="hidden" name="id" value="<?php echo $row ['pid'];?>">
                                        <button href="show.php" type="submit" name="showpr" class="w-100 btn btn-primary fw-bold bg-none border-0">SH</button>
                                    </form>
                                </div>
                                <?php
								if ($row['showinmain'] == 1) {?>
                                <div class="col-12 mt-3">
                                    <form action="ac_projects.php" method="POST">
                                    <input type="hidden" name="pr_id" value="<?php echo $row ['pid'];?>">
                                        <button href="ac_projects.php" type="submit" name="stopinhome" onclick="return confirm('متأكد من منع العرض في الرئيسية');" class="w-100 btn btn-warning fw-bold bg-none border-0">منع العرض في الرئيسية</button>
                                    </form>
                                </div>
                                <?php }elseif ($row['showinmain'] == 0) {?>
                                <div class="col-12 mt-3">
                                    <form action="ac_projects.php" method="POST">
                                        <input type="hidden" name="pr_id" value="<?php echo $row ['pid'];?>">
                                        <button href="ac_projects.php" type="submit" name="showinhome" onclick="return confirm('متأكد من تفعيل العرض في الرئيسية');" class="w-100 btn btn-success fw-bold bg-none border-0">تفعيل العرض في الرئيسية</button>
                                    </form>
                                </div>
                                <?php }?>
                                <?php
								if ($row['showinhead'] == 1) {?>
                                <div class="col-12 mt-3">
                                    <form action="ac_projects.php" method="POST">
                                    <input type="hidden" name="pr_id" value="<?php echo $row ['pid'];?>">
                                        <button href="ac_projects.php" type="submit" name="stopinhead" onclick="return confirm('متأكد من منع العرض في صفحة الحاسبة');" class="w-100 btn btn-warning fw-bold bg-none border-0">منع العرض في صفحة الحاسبة</button>
                                    </form>
                                </div>
                                <?php }elseif ($row['showinhead'] == 0) {?>
                                <div class="col-12 mt-3">
                                    <form action="ac_projects.php" method="POST">
                                        <input type="hidden" name="pr_id" value="<?php echo $row ['pid'];?>">
                                        <button href="ac_projects.php" type="submit" name="showinhead" onclick="return confirm('متأكد من تفعيل العرض في صفحة الحاسبة');" class="w-100 btn btn-success fw-bold bg-none border-0">تفعيل العرض في صفحة الحاسبة</button>
                                    </form>
                                </div>
                                <?php }?>
                            </div>
                        </td>
                        </tr>
                        <?php } ?>
            </table>
        </div>

        <a href ="add_project.php" class="btn-add fw-bold">+ New Project</a>

    </div>
</section>
<?php
include 'assets/includes/template/footer.php';
?>
<?php
}else{
header('Location:logout.php');
exit;
}
?>

<?php
ob_end_flush();

Filemanager

Name Type Size Permission Actions
assets Folder 0755
images Folder 0755
ac_citycalc.php File 15.27 KB 0644
ac_edit_admin.php File 2.67 KB 0644
ac_edit_admininfo.php File 4.36 KB 0644
ac_edit_imgs.php File 34.27 KB 0644
ac_edit_pr.php File 10.72 KB 0644
ac_projects.php File 5.24 KB 0644
ac_workshops.php File 18.62 KB 0644
add_admin.php File 4.32 KB 0644
add_customer_template.php File 11.1 KB 0644
add_project.php File 17.22 KB 0644
add_workshop.php File 5.15 KB 0644
admins.php File 4.81 KB 0644
citycalc.php File 5.01 KB 0644
cons_orders.php File 4.51 KB 0644
custommer_templates.php File 4.59 KB 0644
dashboard.php File 4.11 KB 0644
edit_cus_template.php File 11.74 KB 0644
editadminpassword.php File 5.17 KB 0644
error_log File 309.84 KB 0644
imgs.php File 18.17 KB 0644
index.php File 3.19 KB 0644
init.php File 183 B 0644
logout.php File 186 B 0644
newsletter.php File 3.13 KB 0644
projects.php File 13.89 KB 0644
projects_card.php File 13.29 KB 0644
show.php File 8.81 KB 0644
workshop_details.php File 12.08 KB 0644
workshops.php File 4.63 KB 0644