Sh3ll
OdayForums


Server : Apache
System : Linux profile 3.10.0-1160.88.1.el7.x86_64 #1 SMP Tue Mar 7 15:41:52 UTC 2023 x86_64
User : apache ( 48)
PHP Version : 8.0.28
Disable Function : NONE
Directory :  /var/www/html/mmishra/erp-19-12-2019/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : //var/www/html/mmishra/erp-19-12-2019/inner.php.bak
<?php
if (isset($_SERVER['PATH_INFO'])) {
	$url 						= explode('/', $_SERVER['PATH_INFO']);
	// incoming request format https://baseurl/app/interface/action/tuple/params
	// app is application MVC to be invoked
	// interface is View method to be called
	// action is Controller action to be performed
	// tuple is record ID of Model for Controller action
	list($root, $app, $intface, $action, $tuple) = array_slice($url, 0, 5);
	$params						= array_slice($url, 5);	// rest of the elements

	// Initiate the appropriate controller and render the required view
    // Check if controller exists. NB: it is needed to check for model and view too
    
	if ($app != 'erp') {
		// include parent classes so that classes can extend them
		require_once(__DIR__ .'/models/erp_model.php');
		require_once(__DIR__ .'/views/erp_view.php');
		require_once(__DIR__ .'/controllers/erp_controller.php');
	}

    $appModel 					= __DIR__ .'/models/' .$app. '_model.php';
    $appView 					= __DIR__ .'/views/' .$app. '_view.php';
    $appController 				= __DIR__ .'/controllers/' .$app. '_controller.php';

    if (file_exists($appController) && file_exists($appModel) && file_exists($appView)) {
        require_once($appModel);
        require_once($appView);
        require_once($appController);

        $modelName      		= $app. 'Model';
        $viewName       		= $app. 'View';
        $controllerName 		= $app. 'Controller';

        $appModel       		= new $modelName();
        $appView        		= new $viewName($appModel);

		// set appID and interfaceID
		$appView->app 			= $app;
		$appView->intface		= $intface;
		$appView->action 		= $action;
		$appView->tuple	 		= $tuple;//intval($tuple);
		$appView->params		= $params;

        $appController  		= new $controllerName($appModel, $appView);

		if ($appModel->getIntfaceType($appView->intface) == 'O') {
			$appView->action	= $intface;
			$appView->intface 	= 'report';
		}
        $render		 			= 'manage' .ucwords($appView->intface); // first and second parameter

		// This is the requirements of ERP Framework 
		if ($appController->checkProtection($appView->intface) && empty($_SESSION['sessionID'])) {
			echo "<script language='text/javascript'>alert('Session Over! Re-login Please.'); window.location='/';</script>";
			session_destroy();
			header("Location: /", true, 'Login');
		}
		//header('WWW-Authenticate: Negotiate');//header('WWW-Authenticate: NTLM', false);//

		$header = "<html><head>
	    <base href='https://erp.iiita.ac.in/' />
		<link rel='stylesheet' type='text/css' href='css/erp_style.css' media='screen' />
		<link rel='stylesheet' type='text/css' href='css/fontawesome-all.css' media='screen' integrity='sha384-hWVjflwFxL6sNzntih27bfxkr27PmbbK/iSvJ+a4+0owXq79v+lsFkW54bOGbiDQ' crossorigin='anonymous' />

		<script type='text/javascript' src='js/erp_ajax.js'></script>
		<script type='text/javascript' src='js/fontawesome-all.js'></script>
		<script type='text/javascript' src='js/jquery.min.js'></script>
		</head><body>
		<script type='text/javascript' src='js/erp_body.js'></script>
		<form id='erpForm' name='erpForm' method='POST' action='inner/$app/$interface/$action/$tuple/" .$params[0]. '/' .$params[1]. "' enctype='multipart/form-data'>";
		$footer = "</form></body></html>";
		
       	if ($appView->intface == 'helper' && $appView->action == 'render') {
			print $appController->erpHelper();
    	} else if (in_array($appView->intface, ['photograph']) || in_array($appView->action, ['dataUpload1', 'signUpload', 'photoUpload', 'docUpload', 'photosUpload', 'photosupload', 'exemption'])) {
            print $header;												// iframe loading
			print $appController->$render(); 		   
			print $footer;			
    	} else if ($appController->checkPermission($appView->intface) == TRUE) {
	        print $appController->$render(); 		
		} else {
			print "<h1>Access permission denied [ $app ].</h1>";
		}
	} else {
		print '<h1>ERP detects unsupported URL [ ' .$_SERVER['PATH_INFO']. ' ]</h1>';
	}    
} else {
	print '<h1>ERP detects unsupported URL [ ' .$_SERVER['PATH_INFO']. ' ]</h1>';
}

?>



ZeroDay Forums Mini