UnknownSec Bypass
403
:
/
home
/
growthpharma
/
public_html
/
Master@Growth
/ [
drwxr-xr-x
]
Menu
Upload
Mass depes
Mass delete
Terminal
Info server
About
name :
addadmin.php
<?php include_once("config.php"); //include_once("session_check.php"); if(isset($_POST['mode']) && ($_POST['mode']=="addrecord")) { $userid = trim($_POST['userid']); $email = trim($_POST['email']); $mobile = trim($_POST['mobile']); $password = strrev(base64_encode($_POST['password'])); $status = $_POST['status']; $date=date("Ymd"); $usertype = trim($_POST['usertype']); $admincheck=mysql_fetch_array(mysql_query("select * from admininfo where userid='$userid'")); /*echo "select * from admininfo where userid='$userid'"; die;*/ if($admincheck) { echo "<script>location.href='javascript:history.go(-1)'</script>"; $_SESSION['notDone'] = "User Id Already Exists."; exit(); } else { if($usertype=='Admin') { $sqladdadmin = mysql_query("insert into admininfo set userid='$userid',password='$password',name='$name',email='$email',mobile=$mobile,status='$status',datecreated='$date',mainadmin='no',type='$usertype'"); $lastid=mysql_insert_id(); //$setpermissions=mysql_query("insert into userpermission set userid='$lastid',addadmin='1',editadmin='1',viewadmin='1',deleteadmin='1'"); if($sqladdadmin) { header("location:manageadmin.php"); $_SESSION['mode'] = "Record Reserved Successfully."; exit; } } if($usertype!='Admin') { $sqladdadmin1 = mysql_query("insert into admininfo set userid='$userid', password='$password',name='$name',email='$email',mobile=$mobile,status='$status',datecreated='$date',mainadmin='no',type='$usertype'"); $lastid=mysql_insert_id(); if($sqladdadmin1) { header("location:manageadmin.php"); $_SESSION['mode'] = "Record Reserved Successfully."; exit; } } else { header("location:manageadmin.php"); $_SESSION['mode1'] = "Some Error Occured!"; exit; } } } ?> <!doctype html> <!-- paulirish.com/2008/conditional-stylesheets-vs-css-hacks-answer-neither/ --> <!--[if lt IE 7]> <html class="no-js ie6 oldie" lang="en"> <![endif]--> <!--[if IE 7]> <html class="no-js ie7 oldie" lang="en"> <![endif]--> <!--[if IE 8]> <html class="no-js ie8 oldie" lang="en"> <![endif]--> <!--[if gt IE 8]><!--> <html class="no-js" lang="en"> <!--<![endif]--> <head> <meta charset="utf-8"> <!-- DNS prefetch --> <link rel=dns-prefetch href="//fonts.googleapis.com"> <!-- Use the .htaccess and remove these lines to avoid edge case issues. More info: h5bp.com/b/378 --> <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"> <title>Admin User :: Growth Pharmaceuticals Pvt. Ltd. </title> <meta name="description" content=""> <meta name="author" content=""> <!-- Mobile viewport optimized: j.mp/bplateviewport --> <meta name="viewport" content="width=device-width,initial-scale=1"> <!-- Place favicon.ico and apple-touch-icon.png in the root directory: mathiasbynens.be/notes/touch-icons --> <!-- CSS: implied media=all --> <!-- CSS concatenated and minified via ant build script--> <link rel="stylesheet" href="css/style.css"> <!-- Generic style (Boilerplate) --> <link rel="stylesheet" href="css/960.fluid.css"> <!-- 960.gs Grid System --> <link rel="stylesheet" href="css/main.css"> <!-- Complete Layout and main styles --> <link rel="stylesheet" href="css/buttons.css"> <!-- Buttons, optional --> <link rel="stylesheet" href="css/lists.css"> <!-- Lists, optional --> <link rel="stylesheet" href="css/icons.css"> <!-- Icons, optional --> <link rel="stylesheet" href="css/notifications.css"> <!-- Notifications, optional --> <link rel="stylesheet" href="css/typography.css"> <!-- Typography --> <link rel="stylesheet" href="css/forms.css"> <!-- Forms, optional --> <link rel="stylesheet" href="css/tables.css"> <!-- Tables, optional --> <link rel="stylesheet" href="css/charts.css"> <!-- Charts, optional --> <link rel="stylesheet" href="css/jquery-ui-1.8.15.custom.css"> <!-- jQuery UI, optional --> <!-- end CSS--> <!-- Fonts --> <link href="//fonts.googleapis.com/css?family=PT+Sans" rel="stylesheet" type="text/css"> <!-- end Fonts--> <!-- More ideas for your <head> here: h5bp.com/d/head-Tips --> <!-- All JavaScript at the bottom, except for Modernizr / Respond. Modernizr enables HTML5 elements & feature detects; Respond is a polyfill for min/max-width CSS3 Media Queries For optimal performance, use a custom Modernizr build: www.modernizr.com/download/ --> <script src="js/libs/modernizr-2.0.6.min.js"></script> <script type="text/javascript"> var message=""; function ajaxcheck(sText) { var ajaxRequest; // The variable that makes Ajax possible! try { // Opera 8.0+, Firefox, Safari ajaxRequest = new XMLHttpRequest(); } catch (e) { // Internet Explorer Browsers try { ajaxRequest = new ActiveXObject("Msxml2.XMLHTTP"); } catch (e) { try { ajaxRequest = new ActiveXObject("Microsoft.XMLHTTP"); } catch (e){ // Something went wrong alert("Your browser browser is not compitable for the page on which you are working!"); return false; } } } // Create a function that will receive data sent from the server ajaxRequest.onreadystatechange = function() { if(ajaxRequest.readyState == 4) { document.getElementById("texthint").innerHTML=ajaxRequest.responseText; if(ajaxRequest.responseText) { //alert(ajaxRequest.responseText); document.getElementById("userid").value=""; document.getElementById("userid").focus(); } } } var userid = document.getElementById("userid").value; var queryString = "?userid=" + userid; //alert (queryString); ajaxRequest.open("GET", "checkuser.php" + queryString, true); ajaxRequest.send(null); } function chkvalue1() { var status=0; if(document.getElementById("userid").value=="") { document.getElementById("uid_error").style.display="block"; document.getElementById("uid_error").innerHTML="This field is required."; status=1; } if(document.getElementById("userid").value!="") { document.getElementById("uid_error").style.display="none"; document.getElementById("uid_error").innerHTML=""; } if(document.getElementById("password").value=="") { document.getElementById("pass_error").style.display="block"; document.getElementById("pass_error").innerHTML="This field is required."; status=1; } if(document.getElementById("password").value!="") { document.getElementById("pass_error").style.display="none"; document.getElementById("pass_error").innerHTML=""; } if(document.getElementById("name").value=="") { document.getElementById("name_error").style.display="block"; document.getElementById("name_error").innerHTML="This field is required."; status=1; } if(document.getElementById("name").value!="") { document.getElementById("name_error").style.display="none"; document.getElementById("name_error").innerHTML=""; } if(document.getElementById("mobile").value=="") { document.getElementById("mobile_error").style.display="block"; document.getElementById("mobile_error").innerHTML="This field is required."; status=1; } if(document.getElementById("mobile").value!="") { document.getElementById("mobile_error").style.display="none"; document.getElementById("mobile_error").innerHTML=""; } if(document.getElementById("email").value=="") { document.getElementById("email_error").style.display="block"; document.getElementById("email_error").innerHTML="This field is required."; status=1; } if(document.getElementById("email").value!="") { document.getElementById("email_error").style.display="none"; document.getElementById("email_error").innerHTML=""; } if(document.getElementById("email").value!="") { var x=document.forms["frm"]["email"].value; var atpos=x.indexOf("@"); var dotpos=x.lastIndexOf("."); if (atpos<1 || dotpos<atpos+2 || dotpos+2>=x.length) { document.getElementById("emailvalid_error").style.display="block"; document.getElementById("emailvalid_error").innerHTML="Not a valid e-mail address."; return false; } } if(status==1) { return false; } } </script> <script type="text/javascript"> function formReset() { document.getElementById("frm").reset(); } </script> </head> <body id="top"> <!-- Begin of #container --> <div id="container"> <!-- Begin of #header --> <?php include_once("header.php");?> <!--! end of #header --> <div class="fix-shadow-bottom-height"></div> <!-- Begin of Sidebar --> <?php include_once("navigation.php");?> <!--! end of #sidebar --> <!-- Begin of #main --> <div id="main" ROLE="main"> <!-- Begin of titlebar/breadcrumbs --> <div id="title-bar"> <ul id="breadcrumbs"> <li><a href="dashboard.php" title="Home"><span id="bc-home"></span></a></li> <li class="no-hover">Admin Control</li> </ul> </div> <!--! end of #title-bar --> <div class="shadow-bottom shadow-titlebar"></div> <!-- Begin of #main-content --> <div id="main-content"> <div class="container_12"> <div class="grid_12"> <h1>Create Admin User</h1> <p></p> </div> <div class="grid_6"> <div class="block-border"> <div class="block-header"> <h1>Enter Details</h1><span></span> </div> <form id="frm" name="frm" class="block-content form" action="" method="post" enctype="multipart/form-data" onSubmit="return chkvalue1();"> <input type="hidden" name="mode" id="mode" value="addrecord" /> <?php if(isset($_SESSION['mode']) && ($_SESSION['mode']!='')) { ?> <div class="alert success"> <span class="hide">x</span> <?php echo $_SESSION['mode']; unset ($_SESSION['mode']); ?> </div> <?php } ?> <?php if(isset($_SESSION['mode1']) && ($_SESSION['mode1']!='')) { ?> <div class="alert error"> <span class="hide">x</span> <?php echo $_SESSION['mode1']; unset ($_SESSION['mode1']); ?> </div> <?php } ?> <?php if(isset($_SESSION['notDone']) && ($_SESSION['notDone']!='')) { ?> <div class="alert error"> <span class="hide">x</span> <?php echo $_SESSION['notDone']; unset ($_SESSION['notDone']); ?> </div> <?php } ?> <div class="_100"> <p> <label for="User Id">User Id</label><input id="userid" name="userid" class="''" type="text" value="" onBlur="ajaxcheck(userid);" /> <span style="padding-left:0px;" id="texthint"></span> <span style="font-family:Arial; font-size:11px; font-weight:bold; color:#993300;" id="uid_error"></span> </p> </div> <div class="_100"> <p><label for="Password">Password</label><input id="password" name="password" class="" type="password" value="" /></p> <span style="font-family:Arial; font-size:11px; font-weight:bold; color:#993300;" id="pass_error"></span> </div> <!-- <div class="_100"> <p><label for="Password">Confirm Password</label><input id="password" name="password" class="equalTo" type="password" value="" /></p> </div>--> <div class="_100"> <p><label for="Name">Name</label><input id="name" name="name" class="" type="text" value="" /></p> <span style="font-family:Arial; font-size:11px; font-weight:bold; color:#993300;" id="name_error"></span> </div> <div class="_100"> <p><label for="Email">Email</label><input id="email" name="email" class=" " type="text" value="" /></p> <span style="font-family:Arial; font-size:11px; font-weight:bold; color:#993300;" id="email_error"></span> <span style="font-family:Arial; font-size:11px; font-weight:bold; color:#993300;" id="emailvalid_error"></span> </div> <div class="_100"> <p><label for="Mobile">Mobile</label><input id="mobile" name="mobile" class=" " type="text" value="" onKeyUp="this.value=this.value.replace(/[^\d]/,'')" maxlength="12" /></p> <span style="font-family:Arial; font-size:11px; font-weight:bold; color:#993300;" id="mobile_error"></span> </div> <!--<div class="_100"> <p><label for="textarea">Textarea</label><textarea id="textarea" name="textarea" class="" rows="5" cols="40"></textarea></p> </div>--> <!--<div class="_100"> <p><label for="datepicker">Datepicker</label><input id="datepicker" name="datepicker" class="required" type="text" value="" /></p> </div>--> <!--<div class="_100"> <p> <label for="select">Type</label> <select name="usertype"> <?php $sqlrole = mysql_query("select * from usertype where status='Active' order by id desc"); $sqfrole = mysql_fetch_array($sqlrole); while($sqfrole) { ?> <option value="<?php echo $sqfrole['id'];?>"><?php echo $sqfrole['usertype'];?></option> <?php $sqfrole = mysql_fetch_array($sqlrole); } ?> </select> </p> </div>--> <!--<div class="_100"> <p> <label for="file">Upload a file</label> <input type="file"> </p> </div>--> <div class="_50"> <p> <span class="label">Status</span> <label><input type="radio" name="status" value="Active" checked/> Active</label> <label><input type="radio" name="status" value="Blocked" /> Blocked</label> <!--<label><input type="radio" name="radio" /> Justo duo</label>--> </p> </div> <!--<div class="_50"> <p> <span class="label">Checkboxes</span> <label><input type="checkbox" name="checkbox" /> Check me</label> <label><input type="checkbox" /> Or me</label> <label><input type="checkbox" /> Lorem ipsum</label> </p> </div>--> <div class="clear"></div> <div class="block-actions"> <ul class="actions-left"> <li><a class="button red" onClick="formReset();">Reset</a></li> </ul> <ul class="actions-right"> <li><input type="submit" class="button" value="Proceed"></li> <li><a class="button red" id="reset-validate-form" onClick="javascript:window.location.href='manageadmin.php'">Manage Admin Users</a></li> </ul> </div> </form> </div> </div> <div class="clear"></div> <div class="clear height-fix"></div> </div></div> <!--! end of #main-content --> </div> <!--! end of #main --> <!--<footer id="footer"><div class="container_12"> <div class="grid_12"> <div class="footer-icon align-center"><a class="top" href="#top"></a></div> </div> </div></footer>--> </div> <!--! end of #container --> <!-- JavaScript at the bottom for fast page loading --> <!-- Grab Google CDN's jQuery, with a protocol relative URL; fall back to local if offline --> <script src="//ajax.googleapis.com/ajax/libs/jquery/1.6.2/jquery.min.js"></script> <script>window.jQuery || document.write('<script src="js/libs/jquery-1.6.2.min.js"><\/script>')</script> <!-- scripts concatenated and minified via ant build script--> <script defer src="js/plugins.js"></script> <!-- lightweight wrapper for consolelog, optional --> <script defer src="js/mylibs/jquery-ui-1.8.15.custom.min.js"></script> <!-- jQuery UI --> <script defer src="js/mylibs/jquery.notifications.js"></script> <!-- Notifications --> <script defer src="js/mylibs/jquery.uniform.min.js"></script> <!-- Uniform (Look & Feel from forms) --> <script defer src="js/mylibs/jquery.validate.min.js"></script> <!-- Validation from forms --> <script defer src="js/mylibs/jquery.dataTables.min.js"></script> <!-- Tables --> <script defer src="js/mylibs/jquery.tipsy.js"></script> <!-- Tooltips --> <script defer src="js/mylibs/excanvas.js"></script> <!-- Charts --> <script defer src="js/mylibs/jquery.visualize.js"></script> <!-- Charts --> <script defer src="js/mylibs/jquery.slidernav.min.js"></script> <!-- Contact List --> <script defer src="js/common.js"></script> <!-- Generic functions --> <script defer src="js/script.js"></script> <!-- Generic scripts --> <script type="text/javascript"> $().ready(function() { /* * Form Validation */ $.validator.setDefaults({ submitHandler: function(e) { $.jGrowl("Form was successfully submitted.", { theme: 'success' }); $(e).parent().parent().fadeOut(); v.resetForm(); v2.resetForm(); v3.resetForm(); } }); var v = $("#create-user-form").validate(); jQuery("#reset").click(function() { v.resetForm(); $.jGrowl("User was not created!", { theme: 'error' }); }); var v2 = $("#write-message-form").validate(); jQuery("#reset2").click(function() { v2.resetForm(); $.jGrowl("Message was not sent.", { theme: 'error' }); }); var v3 = $("#create-folder-form").validate(); jQuery("#reset3").click(function() { v3.resetForm(); $.jGrowl("Folder was not created!", { theme: 'error' }); }); var validateform = $("#validate-form").validate(); $("#reset-validate-form").click(function() { validateform.resetForm(); $.jGrowl("You resetted the form.", { theme: 'error' }); }); /* * Datepicker */ $( "#datepicker" ).datepicker(); }); </script> <!-- end scripts--> <!-- Prompt IE 6 users to install Chrome Frame. Remove this if you want to support IE 6. chromium.org/developers/how-tos/chrome-frame-getting-started --> <!--[if lt IE 7 ]> <script src="//ajax.googleapis.com/ajax/libs/chrome-frame/1.0.3/CFInstall.min.js"></script> <script>window.attachEvent('onload',function(){CFInstall.check({mode:'overlay'})})</script> <![endif]--> </body> </html>
Copyright © 2024 - UnknownSec