LittleDemon WebShell


Linux premium274.web-hosting.com 4.18.0-553.45.1.lve.el8.x86_64 #1 SMP Wed Mar 26 12:08:09 UTC 2025 x86_64
Path : /home/whagcoha/mos.mwagalwaservices.com/
File Upload :
Command :
Current File : /home/whagcoha/mos.mwagalwaservices.com/edititem.php

<?php
if ((!isset($_SESSION['gen256']))  ) {
  echo "<script>
        window.open('login.php','_self');
    </script>";  
}

?>
<script src="js/formd.js"></script>

<?php 
if ($_SESSION['gen256']['role']=='0') {

    $output='';

    $output .= " <div class='alert alert-warning' role='alert'>
  Oopps!!<b>You are not allowed to access this page contact the System Admin</b> <a href='index.php?p=activity&page=1'>Click to view Activities</a>
</div>";
    // code...
    echo $output;
}else{

?>

<?php
$cid=$_GET['cid'];
 $query1="SELECT * FROM items WHERE(id='$cid')"; 
                $result = mysqli_query($conn,$query1);
                $count = 1;
                while($row = mysqli_fetch_assoc($result) ){
                    $description = $row['description'];
                    $unit = $row['units'];
                    $unitp = $row['unitprice'];
                    $code = $row['code'];
                    $itemid = $row['id'];
                    $activityid2 = $row['activityid'];
                  
                 
                    ?>


<div class="row">
  
    <div class="col-lg-12">
        <div class="panel panel-default">
            <div class="panel-heading">
                Edit Item
            </div>
            <div class="panel-body">
               
                <form method="post" enctype="multipart/form-data">
                <div class="row">
                    <div class="col-lg-6">

     <div class="form-group">
  <label>Description:</label>
  <input type="text" class="form-control" value="<?php echo $description;?>" name="description" required>
</div>

  <div class="form-group">
  <label>Units:</label>
  <input type="text" class="form-control" value="<?php echo $unit;?>" name="unit" required>
</div>






  
</div>


 <div class="col-lg-6">

    <div class="form-group">
    <label>Unit Price:</label>
    <input type="text" class="form-control" value="<?php echo $unitp;?>" name="unitprice">
</div>
<div class="form-group">
    <label>CodeP:</label>
    <input type="text" class="form-control" value="<?php echo $code;?>" name="code">
</div>


<div class="form-group">
    <label>Select Activity:</label>
    
    <select class="form-control" name="activity" required>
    <option value="<?php echo $activityid2;?>">Select To Change Activity</option>  
    <?php
                $query="SELECT * FROM activity ORDER BY id DESC";

                 
                $result = mysqli_query($conn,$query);
                $count = 1;
                while($row = mysqli_fetch_assoc($result) ){
                    $actiivityid = $row['id'];
                    $activity = $row['activity'];
                   
                
                    ?> 
    <option value="<?php echo $actiivityid; ?>"><?php echo $activity; ?></option>

    <?php
                    $count ++;
                }
            ?>  
    
   <!--  <option>Female</option>  -->
  </select>

</div>



<div class="form-group">
    <input type="submit" name="record" class="btn btn-sm btn-success" value="Update Item">
</div>
</div>


  


<!-- Test Code -->




  
</form>

</div>
<!-- </form> -->
</div>
</div>
</div>
</div>


<script src="js/formd.js"></script>



                     <?php
                    $count ++;
                }



            ?>  


<?php
include "dbconfig/db.php";
if(isset($_POST['record'])){
    
    $description = strip_tags($_POST['description']);
    $unit = strip_tags($_POST['unit']);
    $unitprice = strip_tags($_POST['unitprice']);
    $activity = strip_tags($_POST['activity']);
      
      
    $code=$_POST['code'];
    
    

    



   



    // $sql = "INSERT INTO items(description,units,unitprice,code,activityid) VAlUES('$description','$unit','$unitprice','$code','$activity')";
     $sql = "UPDATE items SET description='$description',units ='$unit',unitprice='$unitprice',activityid='$activity' WHERE id='$cid'";

    
    mysqli_query($conn,$sql);
   

    echo "<script>alert('Item Edited')</script>";
        echo"<script>
            window.open('index.php?p=edititem&cid=$cid','_self');
            </script>"; 


 






}


?>

            <?}?>

LittleDemon - FACEBOOK
[ KELUAR ]