?

áEÓê¤ÎïLwebshll2019

Current Path : /home/webyoo/www/backup/allback/docteur-site/cv/sym/a/backup/allback/myagenda/admin/
Upload File :
Current File : /home/webyoo/www/backup/allback/docteur-site/cv/sym/a/backup/allback/myagenda/admin/events.php

<?php
if (!defined('IN_WWW') || !defined('IN_ADMIN'))
    exit();

$site_Content .= '<h2>Gestion des taches</h2>
                  <p><a href="./?a=events&op=all" style="padding:12px 27px;background: url(http://web4yoo.com/myagenda/images/submit.png) no-repeat scroll 0 0 transparent; border: 0 none; cursor: pointer; height: 39px; width: 168px;">Toutes les taches</a> <a href="./?a=events" style="padding:12px 38px;background: url(http://web4yoo.com/myagenda/images/submit.png) no-repeat scroll 0 0 transparent; border: 0 none; cursor: pointer; height: 39px; width: 168px;">Taches &agrave; venir</a></p>';


$site_Content .= '<br><br>Rechercher une tache pr&eacute;cise (selon le titre)
<form name="form2" id="form2" method="post" action="./?a=events&op=all2">
    <br>Mot cl&eacute; : <input name="search" type="hidden" id="search" value="'.$_POST['titre'].'" /><input name="titre_tache" type="text" value="'.$_POST['titre_tache'].'" /> <br><br><input type="submit" name="Submit" value="Chercher" />
</form>';




$today = mktime(0, 0, 0, date('m'), date('d'), date('Y'));

if (!isset($_GET['l']))
    $limite = 0;
else
    $limite = (int)$_GET['l'];

$nombre = 10;



if (!isset($_GET['op']))
{
    $site_Content .= '<br /><span class="operation">Liste des taches &agrave; venir</span><br /><br />';


    $extraire = mysql_query("SELECT id,date FROM agenda_events WHERE date>'$today'");
    $total = mysql_numrows($extraire);

    $verifLimite = verifLimite($limite, $total, $nombre);
    if (!$verifLimite) {
        $limite = 0;
    }

    if ($total > $nombre) {
        $site_Content .= '<p>Pages : ';
        $site_Content .= affichePages($nombre, $total, $limite, "./?a=events&l=[l]").'</p>';
    }

    $select = "select * FROM agenda_events WHERE date>='$today' ORDER BY date LIMIT $limite,$nombre";
    $result = mysql_query($select) or die('<b>Erreur MySQL [S&eacute;lection des taches]</b> : <br />' . mysql_error());
    $nbrEvents = mysql_num_rows($result);

    if ($nbrEvents > 0)
    {

        $site_Content .= '<table width="100%" class="tableau">';
        while ($row = mysql_fetch_array($result))
        {
            $id = $row["id"];
            $titre = safest($row["titre"]);
            $type = safest($row["type"]);
            $texte = safest($row["texte"]);
            $idDept = $row["num_dept"];
            $date = $row["date"];
            $texteDate = date('d', $date) . ' / ' . date('m', $date) . ' / ' . date('Y', $date);

            $req = "SELECT am.login FROM agenda_membre am, agenda_dept ad WHERE ad.id_membre = am.id AND ad.num_dept ='".$idDept."'";
            $sql = mysql_query($req);
            $User = mysql_fetch_assoc($sql);

            $site_Content .= '
            <tr valign="top">
                <td>
                    <p style="margin-bottom:0"><b>' . $titre . '</b>, affect&eacute; a ' . safest($User['login']) . ' pour le <i><b>' . $texteDate . '</b></i></p>
                </td>
                <td align="center">
                    <span><a href="./?a=events&op=edit&k=' . $id . '" title="Editer cette tache">Modifier</a> |
                        <a href="./?a=events&op=erase&k=' . $id . '" title="Supprimer cette tache">Supprimer</a></span>
                </td>
            </tr>';
        }
        $site_Content .= '</table>';
    } else {
        $site_Content .= 'Aucune tache enregistr&eacute;e';
    }

}

elseif (!empty($_GET['op']) && $_GET['op'] == 'all')
{
    $site_Content .= '<br /><span class="operation">Toutes les taches ...</span><br /><br />';


    $extraire = mysql_query("SELECT id FROM agenda_events");
    $total = mysql_numrows($extraire);

    $verifLimite = verifLimite($limite, $total, $nombre);
    if (!$verifLimite) {
        $limite = 0;
    }

    if ($total > $nombre) {
        $site_Content .= '<p>Pages : ';
        $site_Content .= affichePages($nombre, $total, $limite, "./?a=events&op=all&l=[l]").'</p>';
    }

    $select = "select * FROM agenda_events ORDER BY date LIMIT $limite,$nombre";
    $result = mysql_query($select) or die('<b>Erreur MySQL [S&eacute;lection des taches]</b> : <br />' . mysql_error());
    $nbrEvents = mysql_numrows($result);

    if ($nbrEvents > 0)
    {

        $site_Content .= '<table width="100%" class="tableau">';
        while ($row = mysql_fetch_array($result))
        {
            $id = $row["id"];
            $titre = safest($row["titre"]);
            $type = safest($row["type"]);
            $texte = safest($row["texte"]);
            $idDept = $row["num_dept"];
            $date = $row["date"];
            $texteDate = date('d', $date) . ' / ' . date('m', $date) . ' / ' . date('Y', $date);

            $req = "SELECT am.login FROM agenda_membre am, agenda_dept ad WHERE ad.id_membre = am.id AND ad.num_dept ='".$idDept."'";
            $sql = mysql_query($req);
            $User = mysql_fetch_assoc($sql);

            $site_Content .= '
            <tr valign="top">
                <td>
                    <p style="margin-bottom:0"><b>' . $titre . '</b>, affect&eacute; a ' . safest($User['login']) . ' pour le <i><b>' . $texteDate . '</b></i></p>
                </td>
                <td align="center">
                    <span><a href="./?a=events&op=edit&k=' . $id . '" title="Editer cette tache">Modifier</a> |
                        <a href="./?a=events&op=erase&k=' . $id . '" title="Supprimer cette tache">Supprimer</a></span>
                </td>
            </tr>';
        }
        $site_Content .= '</table>';
    } else {
        $site_Content .= 'Aucune tache enregistr&eacute;e';
    }
}elseif (!empty($_GET['op']) && $_GET['op'] == 'all2')
{
    $site_Content .= '<br /><span class="operation">Toutes les taches de votre recherche...</span><br /><br />';
	//print_r($_POST);
	if(isset($_POST['search']))
	{
		$_SESSION['titre_tache'] = $_POST['titre_tache'];
		
	}
	//echo $_SESSION['titre_tache'];
	
    $extraire = mysql_query("SELECT id FROM agenda_events WHERE titre like '%".$_SESSION['titre_tache']."%'");
    $total = mysql_numrows($extraire);

    $verifLimite = verifLimite($limite, $total, $nombre);
    if (!$verifLimite) {
        $limite = 0;
    }

    if ($total > $nombre) {
        $site_Content .= '<p>Pages : ';
        $site_Content .= affichePages($nombre, $total, $limite, "./?a=events&op=all2&l=[l]").'</p>';
    }

    $select = "select * FROM agenda_events WHERE titre like '%".$_SESSION['titre_tache']."%' ORDER BY date LIMIT $limite,$nombre";
    $result = mysql_query($select) or die('<b>Erreur MySQL [S&eacute;lection des taches]</b> : <br />' . mysql_error());
    $nbrEvents = mysql_numrows($result);

    if ($nbrEvents > 0)
    {

        $site_Content .= '<table class="tableau" width="100%">';
        while ($row = mysql_fetch_array($result))
        {
            $id = $row["id"];
            $titre = safest($row["titre"]);
            $type = safest($row["type"]);
            $texte = safest($row["texte"]);
            $idDept = $row["num_dept"];
            $date = $row["date"];
            $texteDate = date('d', $date) . ' / ' . date('m', $date) . ' / ' . date('Y', $date);

            $req = "SELECT am.login FROM agenda_membre am, agenda_dept ad WHERE ad.id_membre = am.id AND ad.num_dept ='".$idDept."'";
            $sql = mysql_query($req);
            $User = mysql_fetch_assoc($sql);

            $site_Content .= '
            <tr valign="top">
                <td>
                    <p style="margin-bottom:0"><b>' . $titre . '</b>, affect&eacute; a ' . safest($User['login']) . ' pour le <i><b>' . $texteDate . '</b></i></p>
                </td>
                <td align="center">
                    <span><a href="./?a=events&op=edit&k=' . $id . '" title="Editer cette tache">Modifier</a> |
                        <a href="./?a=events&op=erase&k=' . $id . '" title="Supprimer cette tache">Supprimer</a></span>
                </td>
            </tr>';
        }
        $site_Content .= '</table>';
    } else {
        $site_Content .= 'Aucune tache enregistr&eacute;e';
    }
}
elseif(!empty($_GET['op']) && $_GET['op'] == "edit" && !empty($_GET['k']))
{

    $id = (int)$_GET['k'];

    if (!$_POST)
    {

        $extraire = mysql_query("SELECT id FROM agenda_events WHERE id='$id'");
        $nbr = mysql_numrows($extraire);
        if ($nbr != 1) {
            $site_Content .= '<br /><span class="erreurTexte">R&eacute;f&eacute;rence invalide.</span>';
        }
        else
        {
            $select = "SELECT * FROM agenda_events WHERE id='$id' LIMIT 0,1";
            $result = mysql_query($select);
            $row = mysql_fetch_array($result);


            $titreEvents = safest($row['titre']);
            $texteEvents = safest($row['texte']);
			$date = date("d/m/Y", $row['date']);
            $type = $row['type'];
            $idEvents = $row['id'];
			$numdep = $row['num_dept'];
			$numarr = $row['dept_arrivee'];
			$nom = $row['nom'];
			$prenom = $row['prenom'];
			$email = $row['email'];
			$historique = $row['historique'];
			$date_crea = date("d/m/Y", $row['date_crea']);

            $listeSelect = '';
            
            $select = "SELECT * FROM agenda_theme ORDER BY titre ASC";
            $result = mysql_query($select) or die('<b>Erreur MySQL [S&eacute;lection des th&egrave;mes]</b> : <br />' . mysql_error());
            $nbr = mysql_numrows($result);

            if ($nbr > 0)
            {
                while ($row = mysql_fetch_array($result))
                {
                    $idCat = $row["id"];
                    $titre = safest($row["titre"]);

                    if ($idCat == $type)
                        $listeSelect.='<option value="' . $idCat . '" selected="selected">' . $titre . '</option>';
                    else
                        $listeSelect.='<option value="' . $idCat . '">' . $titre . '</option>';
                }
            }
			
			$listeDept = '';

			$selectdep = "SELECT * FROM agenda_dept ORDER BY num_dept ASC";
			$resultdep = mysql_query($selectdep);
			$nbrdep = mysql_numrows($resultdep);

			if ($nbrdep > 0)
			{
				while ($rowdep = mysql_fetch_assoc($resultdep))
				{
					$idDept = $rowdep["num_dept"];
					if ($idDept == $numdep)
					$listeDept.='<option value="' . $rowdep["num_dept"] . '" selected="selected">' . safest($rowdep["num_dept"]) . '</option>';
					else
					$listeDept.='<option value="' . $rowdep["num_dept"] . '">' . safest($rowdep["num_dept"]) . '</option>';
				}
			}
			
			$selectarr = "SELECT * FROM agenda_dept ORDER BY num_dept ASC";
			$resultarr = mysql_query($selectarr);
			$nbrarr = mysql_numrows($resultarr);

			if ($nbrarr > 0)
			{
				while ($rowarr = mysql_fetch_assoc($resultarr))
				{
					$idArr = $rowarr["num_dept"];
					if ($idArr == $numarr)
					$listeArr.='<option value="' . $rowarr["num_dept"] . '" selected="selected">' . safest($rowarr["num_dept"]) . '</option>';
					else
					$listeArr.='<option value="' . $rowarr["num_dept"] . '">' . safest($rowarr["num_dept"]) . '</option>';
				}
			}

                $site_Content .= '<br /><br />Edition de la tache <b>' . $idEvents . '</b> (' . $titreEvents . ') <br />';

                $site_Content .= '
                <form name="form1" id="form1" method="post" action="">
                    <table width="250" border="0" cellspacing="0" cellpadding="0">
                    <tr>
                        <td width="130" height="30">Titre</td>
                        <td width="169" height="31"><input name="titre" type="text" id="titre" value="' . stripslashes($titreEvents) . '" /></td>
                    </tr>
                    <tr>
                        <td height="30">Statut</td>
                        <td width="169" height="31"><select name="type" id="select">' . $listeSelect . '</select></td>
                    </tr>
					<tr>
                        <td height="30">D&eacute;partement D&eacute;part</td>
                        <td width="169" height="31"><select name="dept" id="dept">' . $listeDept . '</select></td>
                    </tr>
					<tr>
                        <td colspan="2" ><br><br>
						<div id="bloc_lead1" style="text-align: left; font-size: 12px; padding: 10px; border: 1px solid white; background: none repeat scroll 0px 0px #A3A3A3;">
						<p style="font-weight:bold">D&eacute;tails du Lead</p>
						<table border="0" cellspacing="0" cellpadding="0">
							<tr>
								<td width="238">Lead cr&eacute;&eacute; le:</td>
								<td><input name="date_c" type="text" value="'.$date_crea.'" disabled="disabled" /><input name="date_crea" type="hidden" value="'.$date_crea.'" /></td>
							</tr>
							<tr>
								<td>Type Prospect:</td>
								<td><select name="prospect"><option value="1">Particulier</option><option value="2">Societe</option><option value="3">International</option></select></td>
							</tr>
							<tr>
								<td>Nom:</td>
								<td><input name="nom" type="text" value="'.$nom.'"/></td>
							</tr>
							<tr>
								<td>Prenom:</td>
								<td><input name="prenom" type="text" value="'.$prenom.'" /></td>
							</tr>
							<tr>
								<td>Email:</td>
								<td><input name="email" type="text" value="'.$email.'" /></td>
							</tr>
							<tr>
								<td>D&eacute;partement Arriv&eacute;e:</td>
								<td><select name="dept_arrivee" id="dept_arrivee">' . $listeArr . '</select></td>
							</tr>
						</table>
						</div><br><br>
						</td>
                    </tr>
					
                    <tr>
                        <td colspan="2" ><br><br>
						<div id="bloc_lead2" style="text-align: left; font-size: 12px; padding: 10px; border: 1px solid white; background: none repeat scroll 0px 0px #A3A3A3;">
						<p style="font-weight:bold">Suivi du Lead</p>
						<span style="font-weight:bold">Historique de la tache li&eacute;e au lead:</span>
						<textarea name="historique" id="textarea" disabled="disabled" COLS=80 ROWS=6 wrap="on">' . stripslashes($historique) . '</textarea>
						<span style="font-weight:bold">Ajouter les nouvelles modifications:</span>
						<textarea name="newhistorique" id="textarea" COLS=80 ROWS=3></textarea>
						</div>
						<br><br>
						</td>
                    </tr>
                    <tr>
                        <td><div align="left">Date de relance</div></td>
                        <td width="169"><input name="datepicker" type="text" id="datepicker" value="' .$date. '" /></td>
                    </tr>
                    <tr>
                        <td></td>
                        <td width="169"><input type="submit" name="Submit" value="Envoyer" /></td>
                    </tr>
					
                    </table>
                </form>';
        }

    }
    else
    {

        if(!empty($_POST['titre']))
        {
            
			$date = (int)$_GET['date'];
			$type = (int)$_POST['type'];
			$dept = $_POST['dept'];
			$titre = smartQuote($_POST['titre']);
			$nom = smartQuote($_POST['nom']);
			$prenom = smartQuote($_POST['prenom']);
			$email = smartQuote($_POST['email']);
			$dept_arrivee = smartQuote($_POST['dept_arrivee']);
			$historique = smartQuote($_POST['historique']);
			
			$datenow = time();
			
			$seltype = "SELECT * FROM agenda_events WHERE titre='$titre'";
			$restype = mysql_query($seltype);
			$rowtype = mysql_fetch_assoc($restype);
			
			$num_relance = $rowtype['num_relance'];

			if($rowtype['type']==$type)
			{
				$selectcat = "SELECT titre FROM agenda_theme WHERE id=".$type;
				$resultcat = mysql_query($selectcat);
				$rowcat = mysql_fetch_assoc($resultcat);
				
				$statut = "Statut inchang&eacute;: ".$rowcat['titre'];
			}else
			{
				$selectcat = "SELECT titre FROM agenda_theme WHERE id=".$type;
				$resultcat = mysql_query($selectcat);
				$rowcat = mysql_fetch_assoc($resultcat);
				
				$statut = "Nouveau Statut: ".$rowcat['titre'];
			}
			
			$newhistorique = smartQuote($_POST['newhistorique']);
			
			
			if($newhistorique!="")
			{
				$modif = "---------Modification du ".date('d/m/Y h:i:s')."---------\n";
				$modif .= $statut."\n";
				$modif .= $newhistorique;
				$selhisto = ", historique=CONCAT(historique,'\n\n$modif')";
			}else
			{
				$selhisto = "";
			}

			
			
			$exp = explode("/", $_POST['datepicker']);
			$j = $exp[0];
			$m = $exp[1];
			$a = $exp[2];
			$date = mktime(0, 0, 0, $m, $j,$a);
			
			
            if (mysql_query("UPDATE agenda_events SET titre='$titre', type='$type',nom='$nom',prenom='$prenom',email='$email', date='$date' $selhisto, num_dept='$dept',dept_arrivee='$dept_arrivee' WHERE id='$id'")) {
                 $site_Content .= '<br /><center><span class="erreurTexte">Tache' . $id . ' bien mise &agrave; jour.</span><br /><br /><a href="./?a=events">Retour aux taches</a><br /><br /><a href="/myagenda/?a=agenda">Retour a l\'agenda</a></center>';
				
				if(($type==2 || $type==3) && $email!="")
				{
					
					$headers  = "MIME-Version: 1.0\r\n";
					$headers .= "Content-type: text/html; charset=UTF-8\r\n";
					$headers .= "From: contact@lacompagnieeuropeenne.com\r\n";

					$result = mysql_query("SELECT * FROM agenda_type_mail WHERE id={$type}");
					$row = mysql_fetch_assoc($result);
					$message = $row['message'];

					
					echo $type;
					echo '<br>'.$num_relance;
					
					if( ($type==2 && $num_relance < 2) || ($type==3 && $num_relance < 3))
					{	
						echo '<br>envoi';
						
						if(!mail($email, "Relance - La Compagnie Europeenne de Stockage", $message, $headers)) {
							$error = "Echec d'envoi du mail. Verifiez la validite de l'adresse du client.";
						}else
						{
							mysql_query("UPDATE agenda_events SET num_relance='{$type}' WHERE id='$id'");
						}
						exit;
					}
					
				}
			}

        } 
        else
        {
            $site_Content .= 'Titre requis!';
        }
    }


//Cas ou l'on supprime un events
}
elseif (!empty($_GET['op']) && $_GET['op'] == "erase" && !empty($_GET['k']))
{
    $id = (int)$_GET['k'];

    $extraire = mysql_query("SELECT id FROM agenda_events WHERE id='$id'");
    if (mysql_numrows($extraire) != 1) {
        Exit("Cette tache n'existe pas");
    }

    if (empty($_GET['verif']))
    {
        $site_Content .= '<br /><br />Confirmez-vous la suppression ? - <a href="?a=events&op=erase&k='.$id.'&verif=1">Oui</a> - <a href="./?a=events&op=all">Non</a>';
    }
    else
    {
        if (mysql_query("DELETE FROM agenda_events WHERE id='$id'")) {
            $site_Content .= '<br /><center><span class="erreurTexte">Tache ' . $id . ' bien supprim&eacute;e.</span> <br />
          <a href="./?a=events&op=all">Retour</a></center>';
        }
    }
}



web shell, Coded By 2019