?

áEÓê¤ÎïLwebshll2019

Current Path : /home/webyoo/www/backup/allback/myagenda/
Upload File :
Current File : /home/webyoo/www/backup/allback/myagenda/search.php

<?php
if (!defined('IN_WWW'))
    exit();
	
if (!$_Connected)
{
	//exit('Espace r?serv? : acc?s interdit');
	?><script type="text/javascript">
	alert('Espace réservé : accès interdit');
	document.location.href="http://web4yoo.com/myagenda/";
	</script><?
}

$site_Content .= '<h2><img src="http://web4yoo.com/myagenda/images/Search-64.png" align="absmiddle" class="rotate"/>&nbsp;&nbsp;Recherche Avanc&eacute;e</h2>';



$listeSelect = '';

$select = "SELECT * FROM agenda_theme ORDER BY titre ASC";
$result = mysql_query($select) or die('<b>Erreur MySQL [S&eacute;lection des th&egrave;mes]</b> : <br />' . mysql_error());
$nbr = mysql_numrows($result);

if ($nbr > 0)
{
	
	while ($row = mysql_fetch_array($result))
	{
		$idCat = $row["id"];
		$titre = safest($row["titre"]);

		if(isset($_POST['type'])) {
			$type = $_POST['type'];
		}else{
			$type = '';
		}
		
		if ($idCat == $type)
			$listeSelect.='<option value="' . $idCat . '" selected="selected">' . $titre . '</option>';
		else
			$listeSelect.='<option value="' . $idCat . '">' . $titre . '</option>';
	}
	
	
}


$listeDept = '';

if(is_admin())
{
	$selwhere = "";
}else{
	$selwhere = "WHERE id_membre='{$_SESSION['mbr_id']}'";
}

$selectdep = "SELECT * FROM agenda_dept $selwhere ORDER BY num_dept ASC";
$resultdep = mysql_query($selectdep) or die('<b>Erreur MySQL </b> : <br />' . mysql_error());
$nbrdep = mysql_numrows($resultdep);

if ($nbrdep > 0)
{
	
	while ($rowdep = mysql_fetch_array($resultdep))
	{
		$num_dept = safest($rowdep["num_dept"]);

		if(isset($_POST['dept'])) {
			$dept = $_POST['dept'];
		}else{
			$dept = '';
		}
		
		if ($num_dept == $dept)
			$listeDept.='<option value="' . $num_dept . '" selected="selected">' . $num_dept . '</option>';
		else
			$listeDept.='<option value="' . $num_dept . '">' . $num_dept . '</option>';
	}
}

$disp = 'none';

if(isset($_POST['type']) && $_POST['c_statut']=='on')
{
	$disp0 = 'block';
	$check0 = "checked='checked'";
	$disp = 'block';
}else
{
	$disp0 = 'none';
	$check0 = "";
}


if(isset($_POST['dept']) && $_POST['c_dept']=='on')
{
	$disp1 = 'block';
	$check1 = "checked='checked'";
	$disp = 'block';
}else
{
	$disp1 = 'none';
	$check1 = "";
}


if(isset($_POST['datepicker']) && $_POST['datepicker']!='' && $_POST['c_date']=='on')
{
	$disp2 = 'block';
	$check2 = "checked='checked'";
	$disp = 'block';
}else
{
	$disp2 = 'none';
	$check2 = "";
}

$site_Content .= '<br><br><span style="font-size:14px; font-weight:bold;">Moteur de Recherche Avanc&eacute;e Multicrit&egrave;res</span><br>
<form name="form2" id="form2" method="post" action="./?a=search" style="display:block;border: 2px solid rgb(255, 255, 255); border-radius: 4px 4px 4px 4px; padding: 5px; margin: 5px; width: 70%;">
    <br><input name="search" type="hidden" id="search" />
	<div class="ui-widget" style="text-align:left !important;">
	<input name="titre_tache" id="titre_tache" type="text" placeholder="Tapez le titre de la tache ici..." value="'.$_POST['titre_tache'].'" style="width:426px;"/>
	</div>
	
	
	
	<br><br>&nbsp;&nbsp;<span id="bt_crit" style="cursor:pointer;"><img src="http://web4yoo.com/myagenda/images/Plus-32.png" align="absmiddle" class="rotate"/>&nbsp;&nbsp;Ajoutez un ou plusieurs crit&egrave;res de recherche:</span>
	<div id="criteres" style="display:'.$disp.';font-size:11px; font-weight:bold;padding:5px 26px;">
	<br><input type="checkbox" '.$check0.' name="c_statut" id="c_statut"/> Statut
	<br><select class="crit" style="display:'.$disp0.';" name="type" id="select">' . $listeSelect . '</select>
	<br><input type="checkbox" '.$check1.'  name="c_dept" id="c_dept"/> D&eacute;partement D&eacute;part
	<br><select class="crit" style="display:'.$disp1.';" name="dept" id="dept">' . $listeDept . '</select>
	<br><input type="checkbox" '.$check2.'  name="c_date" id="c_date"/> Date r&eacute;alisation tache
	<br><input class="crit" style="display:'.$disp2.';padding: 2px;" name="datepicker" type="text" id="datepicker" value="'.$_POST['datepicker'].'"/>
	
	</div>
	<br><br><input type="submit" name="Submit" value="Chercher" />
</form>';	
	
if (!isset($_GET['l']))
    $limite = 0;
else
    $limite = (int)$_GET['l'];

$nombre = 5;
//print_r($_POST);	
if(isset($_POST['search']) || isset($_GET['l']))
{
    $site_Content .= '<br /><span class="operation">Toutes les taches de votre recherche:</span><br /><br />';
	
	if($_POST['titre_tache']!="")
	{
		$_SESSION['titre_tache'] = $_POST['titre_tache'];
		$seltitre = "AND titre like '%".$_SESSION['titre_tache']."%'";
	}else
	{
		$seltitre = "";
	}
	
	if($_POST['c_statut']=='on')
	{
		$seltype = "AND ae.type = ".$_POST['type'];
	}else
	{
		$seltype = "";
	}
	
	if($_POST['c_dept']=='on')
	{
		$seldep = "AND ae.num_dept = ".$_POST['dept'];
	}else
	{
		$seldep = "";
	}
	
	if($_POST['datepicker']!='')
	{
		
		
		$exp = explode("/", $_POST['datepicker']);
		$j = $exp[0];
		$m = $exp[1];
		$a = $exp[2];
		$tdate = mktime(0, 0, 0, $m, $j,$a);
		$seldate = "AND ae.date = ".$tdate;
	}else
	{
		$seldate = "";
	}
	
	if(is_admin())
	{
		$extraire = mysql_query("SELECT * FROM agenda_events ae WHERE 1=1 $seltitre $seltype $seldep $seldate");
    }else
	{
		
		$extraire = mysql_query("select ae.id FROM agenda_events ae, agenda_dept ad, agenda_membre am 
					WHERE ae.num_dept = ad.num_dept
					AND ad.id_membre = am.id
					AND am.id ='{$_SESSION['mbr_id']}' $seltitre $seltype $seldep $seldate");
	}
	
    $total = mysql_numrows($extraire);

    $verifLimite = verifLimite($limite, $total, $nombre);
    if (!$verifLimite) {
        $limite = 0;
    }

    if ($total > $nombre) {
        $site_Content .= '<p>Pages : ';
        $site_Content .= affichePages($nombre, $total, $limite, "./?a=search&l=[l]").'</p>';
    }

	if(is_admin())
	{
		$select = "select ae.id as ide,ae.* FROM agenda_events ae WHERE 1=1 $seltitre $seltype $seldep $seldate ORDER BY date LIMIT $limite,$nombre";
    }else
	{
		$select = "select ae.id as ide, ae.num_dept as num_dept,ae.*,ad.*,am.* FROM agenda_events ae, agenda_dept ad, agenda_membre am 
					WHERE ae.num_dept = ad.num_dept
					AND ad.id_membre = am.id
					AND ad.id_membre='{$_SESSION['mbr_id']}' $seltitre $seltype $seldep $seldate
					ORDER BY ae.date LIMIT $limite,$nombre";
	}
    $result = mysql_query($select) or die('<b>Erreurs MySQL [S&eacute;lection des taches]</b> : <br />' . mysql_error());
    $nbrEvents = mysql_numrows($result);

    if ($nbrEvents > 0)
    {

        $site_Content .= '<table class="tableau" width="100%"><tr valign="top" style="height:26px; background:#DEDEDE;">
                <td>
                    D&eacute;tails
                </td>
                <td align="center">
                    Actions
                </td>
            </tr>';
        while ($row = mysql_fetch_array($result))
        {
            $id = $row["ide"];
            $titre = safest($row["titre"]);
            $type = safest($row["type"]);
			$idDept = $row["num_dept"];
            $date = $row["date"];
            $texteDate = date('d', $date) . ' / ' . date('m', $date) . ' / ' . date('Y', $date);

            $req = "SELECT am.login FROM agenda_membre am, agenda_dept ad WHERE ad.id_membre = am.id AND ad.num_dept ='".$idDept."'";
            $sql = mysql_query($req);
            $User = mysql_fetch_assoc($sql);

            $site_Content .= '
            <tr valign="top">
                <td>
                    <p style="margin-bottom:0"><b>' . $titre . '</b>, affect&eacute; a ' . safest($User['login']) . ' pour le <i><b>' . $texteDate . '</b></i></p>
                </td>
                <td align="center">
                    <span><a href="./?a=events&op=edit&k=' . $id . '" title="Editer cette tache">Modifier</a> |
                        <a href="./?a=events&op=erase&k=' . $id . '" title="Supprimer cette tache">Supprimer</a></span><b>
                </td>
            </tr>';
        }
        $site_Content .= '</table>';
    } else {
        $site_Content .= 'Aucune tache trouv&eacute;e';
    }
}



web shell, Coded By 2019