Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
config.php
8 changes: 4 additions & 4 deletions add_cat.php
Original file line number Diff line number Diff line change
Expand Up @@ -158,10 +158,10 @@
} else {


$name=mysql_real_escape_string($_POST['name']);
$address=mysql_real_escape_string($_POST['address']);
$contact1=mysql_real_escape_string($_POST['contact1']);
$contact2=mysql_real_escape_string($_POST['contact2']);
$name=mysqli_real_escape_string($db->conn, $_POST['name']);
$address=mysqli_real_escape_string($db->conn, $_POST['address']);
$contact1=mysqli_real_escape_string($db->conn, $_POST['contact1']);
$contact2=mysqli_real_escape_string($db->conn, $_POST['contact2']);

$count = $db->countOf("customer_details", "customer_name='$name'");
if($count==1)
Expand Down
4 changes: 2 additions & 2 deletions add_category.php
Original file line number Diff line number Diff line change
Expand Up @@ -148,8 +148,8 @@
} else {


$name=mysql_real_escape_string($_POST['name']);
$address=mysql_real_escape_string($_POST['address']);
$name=mysqli_real_escape_string($db->conn, $_POST['name']);
$address=mysqli_real_escape_string($db->conn, $_POST['address']);


$count = $db->countOf("category_details", "category_name='$name'");
Expand Down
8 changes: 4 additions & 4 deletions add_customer.php
Original file line number Diff line number Diff line change
Expand Up @@ -285,10 +285,10 @@
} else {


$name=mysql_real_escape_string($_POST['name']);
$address=mysql_real_escape_string($_POST['address']);
$contact1=mysql_real_escape_string($_POST['contact1']);
$contact2=mysql_real_escape_string($_POST['contact2']);
$name=mysqli_real_escape_string($db->conn, $_POST['name']);
$address=mysqli_real_escape_string($db->conn, $_POST['address']);
$contact1=mysqli_real_escape_string($db->conn, $_POST['contact1']);
$contact2=mysqli_real_escape_string($db->conn, $_POST['contact2']);

$count = $db->countOf("customer_details", "customer_name='$name'");
if($count==1)
Expand Down
22 changes: 11 additions & 11 deletions add_purchase.php
Original file line number Diff line number Diff line change
Expand Up @@ -421,12 +421,12 @@ function balance_amount(){
} else {
$username = $_SESSION['username'];

$stockid=mysql_real_escape_string($_POST['stockid']);
$stockid=mysqli_real_escape_string($db->conn, $_POST['stockid']);

$bill_no =mysql_real_escape_string($_POST['bill_no']);
$supplier=mysql_real_escape_string($_POST['supplier']);
$address=mysql_real_escape_string($_POST['address']);
$contact=mysql_real_escape_string($_POST['contact']);
$bill_no =mysqli_real_escape_string($db->conn, $_POST['bill_no']);
$supplier=mysqli_real_escape_string($db->conn, $_POST['supplier']);
$address=mysqli_real_escape_string($db->conn, $_POST['address']);
$contact=mysqli_real_escape_string($db->conn, $_POST['contact']);
$stock_name=$_POST['stock_name'];

$count = $db->countOf("supplier_details", "supplier_name='$supplier'");
Expand All @@ -440,11 +440,11 @@ function balance_amount(){
$cost=$_POST['cost'];
$total=$_POST['total'];
$subtotal=$_POST['subtotal'];
$description=mysql_real_escape_string($_POST['description']);
$due=mysql_real_escape_string($_POST['duedate']);
$payment=mysql_real_escape_string($_POST['payment']);
$balance=mysql_real_escape_string($_POST['balance']);
$mode=mysql_real_escape_string($_POST['mode']);
$description=mysqli_real_escape_string($db->conn, $_POST['description']);
$due=mysqli_real_escape_string($db->conn, $_POST['duedate']);
$payment=mysqli_real_escape_string($db->conn, $_POST['payment']);
$balance=mysqli_real_escape_string($db->conn, $_POST['balance']);
$mode=mysqli_real_escape_string($db->conn, $_POST['mode']);

$autoid=$_POST['stockid'];
$autoid1=$autoid;
Expand Down Expand Up @@ -484,7 +484,7 @@ function balance_amount(){
}
}
$msg="<br><font color=green size=6px >Parchase order Added successfully Ref: [". $_POST['stockid']."] !</font>" ;
header("Location: add_purchase.php?msg=$msg");
//header("Location: add_purchase.php?msg=$msg");
}

}
Expand Down
85 changes: 41 additions & 44 deletions add_sales.php
Original file line number Diff line number Diff line change
Expand Up @@ -12,8 +12,8 @@
<!-- Stylesheets -->
<link href='http://fonts.googleapis.com/css?family=Droid+Sans:400,700' rel='stylesheet'>
<link rel="stylesheet" href="css/style.css">
<link rel="stylesheet" href="js/date_pic/date_input.css">
<link rel="stylesheet" href="lib/auto/css/jquery.autocomplete.css">
<link rel="stylesheet" href="js/date_pic/date_input.css">
<link rel="stylesheet" href="lib/auto/css/jquery.autocomplete.css">

<!-- Optimize for mobile devices -->
<meta name="viewport" content="width=device-width, initial-scale=1.0"/>
Expand Down Expand Up @@ -469,50 +469,49 @@ function discount_type(){
} else {
$username = $_SESSION['username'];

$stockid=mysql_real_escape_string($_POST['stockid']);
$stockid=mysqli_real_escape_string($db->conn, $_POST['stockid']);

$bill_no =mysql_real_escape_string($_POST['bill_no']);
$customer=mysql_real_escape_string($_POST['supplier']);
$address=mysql_real_escape_string($_POST['address']);
$contact=mysql_real_escape_string($_POST['contact']);
$bill_no =mysqli_real_escape_string($db->conn, $_POST['bill_no']);
$customer=mysqli_real_escape_string($db->conn, $_POST['supplier']);
$address=mysqli_real_escape_string($db->conn, $_POST['address']);
$contact=mysqli_real_escape_string($db->conn, $_POST['contact']);
$count = $db->countOf("customer_details", "customer_name='$customer'");
if($count==0)
{
$db->query("insert into customer_details(customer_name,customer_address,customer_contact1) values('$customer','$address','$contact')");
}
$stock_name=$_POST['stock_name'];
if((int)$count==0)
{ $db->query("insert into customer_details(customer_name,customer_address,customer_contact1) values('$customer','$address','$contact')");
}
$stock_name=$_POST['stock_name'];
$quty=$_POST['quty'];
$date=mysql_real_escape_string($_POST['date']);
$date=mysqli_real_escape_string($db->conn, $_POST['date']);
$sell=$_POST['sell'];
$total=$_POST['total'];
$payable=$_POST['subtotal'];
$description=mysql_real_escape_string($_POST['description']);
$due=mysql_real_escape_string($_POST['duedate']);
$payment=mysql_real_escape_string($_POST['payment']);
$discount=mysql_real_escape_string($_POST['discount']);
$description=mysqli_real_escape_string($db->conn, $_POST['description']);
$due=mysqli_real_escape_string($db->conn, $_POST['duedate']);
$payment=mysqli_real_escape_string($db->conn, $_POST['payment']);
$discount=mysqli_real_escape_string($db->conn, $_POST['discount']);
if($discount==""){
$discount=00;
}
$dis_amount=mysql_real_escape_string($_POST['dis_amount']);
$dis_amount=mysqli_real_escape_string($db->conn, $_POST['dis_amount']);
if($dis_amount==""){
$dis_amount=00;
}
$subtotal=mysql_real_escape_string($_POST['payable']);
$balance=mysql_real_escape_string($_POST['balance']);
$mode=mysql_real_escape_string($_POST['mode']);
$tax=mysql_real_escape_string($_POST['tax']);
if($tax==""){
$tax=00;
}
$tax_dis=mysql_real_escape_string($_POST['tax_dis']);
$temp_balance = $db->queryUniqueValue("SELECT balance FROM customer_details WHERE customer_name='$customer'");
$temp_balance = (int) $temp_balance + (int) $balance;
$db->execute("UPDATE customer_details SET balance=$temp_balance WHERE customer_name='$customer'");
$selected_date=$_POST['due'];
$selected_date=strtotime( $selected_date );
$mysqldate = date( 'Y-m-d H:i:s', $selected_date );
$due=$mysqldate;
$max = $db->maxOfAll("id", "stock_entries");
$dis_amount=00;
}
$subtotal=mysqli_real_escape_string($db->conn, $_POST['payable']);
$balance=mysqli_real_escape_string($db->conn, $_POST['balance']);
$mode=mysqli_real_escape_string($db->conn, $_POST['mode']);
$tax=mysqli_real_escape_string($db->conn, $_POST['tax']);
if($tax==""){
$tax=00;
}
$tax_dis=mysqli_real_escape_string($db->conn, $_POST['tax_dis']);
$temp_balance = $db->queryUniqueValue("SELECT balance FROM customer_details WHERE customer_name='$customer'");
$temp_balance = (int) $temp_balance + (int) $balance;
$db->execute("UPDATE customer_details SET balance=$temp_balance WHERE customer_name='$customer'");
$selected_date=$_POST['due'];
$selected_date=strtotime( $selected_date );
$mysqldate = date( 'Y-m-d H:i:s', $selected_date );
$due=$mysqldate;
$max = $db->maxOfAll("id", "stock_entries");
$max=$max+1;
$autoid="SD".$max."";
for($i=0;$i<count($stock_name);$i++)
Expand All @@ -530,7 +529,7 @@ function discount_type(){

$count = $db->queryUniqueValue("SELECT quantity FROM stock_avail WHERE name='$name1'");

if($count >= 1)
if((int)$count >= 1)
{


Expand Down Expand Up @@ -565,13 +564,11 @@ function discount_type(){



}
$msg="<br><font color=green size=6px >Sales Added successfully Ref: [". $_POST['stockid']."] !</font>" ;
header("Location: add_sales.php?msg=$msg");



echo "<script>window.open('add_sales_print.php?sid=$autoid','myNewWinsr','width=620,height=800,toolbar=0,menubar=no,status=no,resizable=yes,location=no,directories=no');</script>";
}
$msg="<br><font color=green size=6px >Sales Added successfully Ref: [". $_POST['stockid']."] !</font>" ;
echo $msg;
//header("Location: add_sales.php?msg=$msg");
echo "<script>window.open('add_sales_print.php?sid=$autoid','myNewWinsr','width=620,height=800,toolbar=0,menubar=no,status=no,resizable=yes,location=no,directories=no');</script>";
//echo "<script>window.open('add_sales_print.php?sid=$autoid','myNewWinsr','width=620,height=800,toolbar=0,menubar=no,status=no,resizable=yes,location=no,directories=no');</script>";
//$msg="<br><font color=green size=6px >Parchase order Added successfully Ref: [". $_POST['stockid']."] !</font>" ;
//header("Location: add_purchase.php?msg=$msg");
Expand Down
12 changes: 6 additions & 6 deletions add_stock.php
Original file line number Diff line number Diff line change
Expand Up @@ -199,12 +199,12 @@ function numbersonly(e){
} else {


$name=mysql_real_escape_string($_POST['name']);
$stockid=mysql_real_escape_string($_POST['stockid']);
$sell=mysql_real_escape_string($_POST['sell']);
$cost=mysql_real_escape_string($_POST['cost']);
$supplier=mysql_real_escape_string($_POST['supplier']);
$category=mysql_real_escape_string($_POST['category']);
$name=mysqli_real_escape_string($db->conn, $_POST['name']);
$stockid=mysqli_real_escape_string($db->conn, $_POST['stockid']);
$sell=mysqli_real_escape_string($db->conn, $_POST['sell']);
$cost=mysqli_real_escape_string($db->conn, $_POST['cost']);
$supplier=mysqli_real_escape_string($db->conn, $_POST['supplier']);
$category=mysqli_real_escape_string($db->conn, $_POST['category']);


$count = $db->countOf("stock_details", "stock_id ='$stockid'");
Expand Down
8 changes: 4 additions & 4 deletions add_supplier.php
Original file line number Diff line number Diff line change
Expand Up @@ -162,10 +162,10 @@
} else {


$name=mysql_real_escape_string($_POST['name']);
$address=mysql_real_escape_string($_POST['address']);
$contact1=mysql_real_escape_string($_POST['contact1']);
$contact2=mysql_real_escape_string($_POST['contact2']);
$name=mysqli_real_escape_string($db->conn, $_POST['name']);
$address=mysqli_real_escape_string($db->conn, $_POST['address']);
$contact1=mysqli_real_escape_string($db->conn, $_POST['contact1']);
$contact2=mysqli_real_escape_string($db->conn, $_POST['contact2']);

$count = $db->countOf("supplier_details", "supplier_name='$name'");
if($count==1)
Expand Down
14 changes: 5 additions & 9 deletions checklogin.php
Original file line number Diff line number Diff line change
Expand Up @@ -12,19 +12,15 @@
// To protect MySQL injection (more detail about MySQL injection)
$myusername = stripslashes($myusername);
$mypassword = stripslashes($mypassword);
$myusername = mysql_real_escape_string($myusername);
$mypassword = mysql_real_escape_string($mypassword);

$myusername = mysqli_real_escape_string($db->conn, $myusername);
$mypassword = mysqli_real_escape_string($db->conn, $mypassword);
$sql="SELECT * FROM $tbl_name WHERE username='$myusername' and password='$mypassword'" ;
$result=mysql_query($sql);
$result=mysqli_query($db->conn, $sql);

// Mysql_num_row is counting table row
$count=mysql_num_rows($result);
// If result matched $myusername and $mypassword, table row must be 1 row

if($count==1){
if($result->num_rows){
// Register $myusername, $mypassword and redirect to file "dashboard.php"
$row = mysql_fetch_row($result);
$row = mysqli_fetch_row($result);

$_SESSION['id']=$row[0];
$_SESSION['username']=$row[1];
Expand Down
2 changes: 1 addition & 1 deletion database_install.php
Original file line number Diff line number Diff line change
Expand Up @@ -116,7 +116,7 @@ function select_data(){
$user= trim($_POST['username']);
$pass= trim($_POST['password']);
}
$link = mysql_connect("$host","$user","$pass");
$link = mysqli_connect("$host","$user","$pass");
if (!$link) {
$data="Database Configration is Not vaild";
header("location:instal.php?msg=$data");
Expand Down
4 changes: 2 additions & 2 deletions deleteselected.php
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
{

$SQL = "SELECT * FROM $tablename where id=$singleVar";
$result=mysql_query($SQL) or die(mysql_error());
$result=mysqli_query($db->conn, $SQL) or die(mysqli_error());
$checkuser=mysql_num_rows($result);
if($checkuser>0) {

Expand Down Expand Up @@ -59,7 +59,7 @@
}


mysql_query("DELETE FROM $tablename WHERE id=$singleVar") or die(mysql_error());
mysqli_query($db->conn, "DELETE FROM $tablename WHERE id=$singleVar") or die(mysqli_error());

$i++;
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,4 +35,4 @@

$validator->filter($_POST, $filters);

echo mysql_real_escape_string($_POST['password']);
echo mysqli_real_escape_string($db->conn, $_POST['password']);
2 changes: 1 addition & 1 deletion init.php
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

require "lib/gump.class.php";

$gump = new GUMP();
$gump = new GUMP($config['database'], $config['host'], $config['username'], $config['password']);


// Messages Settings
Expand Down
Loading