Sh3ll
OdayForums


Server : Apache
System : Linux profile 3.10.0-1160.88.1.el7.x86_64 #1 SMP Tue Mar 7 15:41:52 UTC 2023 x86_64
User : apache ( 48)
PHP Version : 8.0.28
Disable Function : NONE
Directory :  /var/www/html/mmishra/erp-15-06-18/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : //var/www/html/mmishra/erp-15-06-18/outer.php
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
  	<title>ERP @ IIITA</title>
	<base href="https://erp.iiita.ac.in/" />
	<meta charset="utf-8">
  	<meta http-equiv="content-type" content="text/html; charset=utf-8" />
	<meta name="viewport" content="width=device-width, initial-scale=1.0" />
	<meta name="description" content="enterprise resource planning, institute resource planning, iiita resource planning" />
	<meta name="author" content="Dr. M.K. Mishra, System Analyst" />
	
	<link rel='SHORTCUT ICON' href="images/logo.ico" />
	<link rel="stylesheet" type="text/css" href="css/erp_style.css" media="screen" />
	<link rel="stylesheet" type="text/css" href="css/erp_menu.css" media="screen" />
	<link rel="stylesheet" type="text/css" href="css/calendar.css" media="screen" />
	<link rel="stylesheet" type="text/css" href="css/fontawesome-all.css" media="screen" />

  	<script type="text/javascript" src="js/calendar.js"></script>
	<script type="text/javascript" src="js/fontawesome-all.js"></script>
	<script type="text/javascript" src="js/jquery.min.js"></script>
	<script type="text/javascript" src="js/erp_ajax.js"></script>
	<!--<script type="text/javascript" src="js/jquery-1.10.2.js"></script>-->
</head>
<body>
<?php
// This is the requirements for ERP Framework
session_start(); 

//if (!$_SESSION['sessionID'] && $_SERVER["HTTP_REFERER"] == 'https://erp.iiita.ac.in/') {
if (!$_SESSION['sessionID']) {
	print "<h1>Unauthorised access. Please login first.</h1>";
	exit;	// exit brutally
}
echo $_SERVER["HTTP_REFERER"];

$url = isset($_SERVER['PATH_INFO']) ? explode('/', ltrim($_SERVER['PATH_INFO'],'/')) : '/';
//echo $url[0].'-'.$url[1].'-'.$url[2].'-'.$url[3].'<br>';

if ($url[0] == '/') {
	header("Location: /");

} else if ($url[0] != '' && $url[1] != ''  && $url[2] != ''  && $url[3] != '' ) {
	// incoming request format /app/menu/action/tuple
	// app is application MVC to be invoked
	// menu is MVC method to be called
	// action is MVC action to be performed
	// tuple is record no. the MVC action is performed on
	//echo $_SERVER['PATH_INFO'];

    $app 						= $url[0]; 	// The first element should be an application controller
    $menu 						= $url[1];	// The second element should be a view method
    $action 					= $url[2];	// The third element should be a model action
    $tuple 						= $url[3];	// The fourth element should be a tuple 
	$params						= $url[4];	// rest of the elements
    if (!$tuple) {
		$params					= array_slice($url, 3); 
    }
	// Initiate the appropriate controller and render the required view
    // Check if controller exists. NB: it is needed to check for model and view too
    
	if ($app != 'erp') {
		// include parent class files prior to child class file
		require_once(__DIR__.'/models/erp_model.php');
		require_once(__DIR__.'/controllers/erp_controller.php');
		require_once(__DIR__.'/views/erp_view.php');
	}
    $appModel 					= __DIR__.'/models/'.$app.'_model.php';
    $appController 				= __DIR__.'/controllers/'.$app.'_controller.php';
    $appView 					= __DIR__.'/views/'.$app.'_view.php';

    if (file_exists($appController) && file_exists($appModel) && file_exists($appView)) {

        require_once($appModel);
        require_once($appController);
        require_once($appView);

        $modelName      		= $app.'Model';
        $controllerName 		= $app.'Controller';
        $viewName       		= $app.'View';

        $appModel       		= new $modelName();
        $appController  		= new $controllerName($appModel);
        $appView        		= new $viewName($appController, $appModel);

		// set controllers appID and menuID
		$appController->app 	= $app;
		$appController->menu 	= $menu;
		$appController->action 	= $action;
		$appController->tuple 	= $tuple;
		$appController->params	= $params;
        $viewMethod 			= $app.ucwords($menu); // first and second parameter


		// render ERP Header
		print $appView->erpBanner();
		print $appView->erpHeader();
	
	    // render ERP index, if no specific application is requested
    	print "<div class='contentbar' id='contentbar'>";
        // then we call the method via the view, dynamic call of the view
	    print "<form id='erpForm' name='erpForm' method='POST' action='inner/$app/$menu/$action/$tuple' enctype='multipart/form-data' autocomplete='on'>";
		print $appView->$viewMethod($action, $tuple); // third and fourth parameter   
		print "</form>
		</div>";			
	} else {
		$erpController->errorText = "Controller for this ERP application does not exist.";
		print $appView->erpError();
	}    
} else {
	print 'Unsupported URL ' .$_SERVER['PATH_INFO'];
}
print $appView->erpFooter();

?>
</body>
</html>



ZeroDay Forums Mini