default.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341
  1. <?php
  2. include("../config/conn.php");
  3. include("../config/function.php");
  4. AdminSes_audit();
  5. $sj=date("Y-m-d H:i:s");
  6. $today1=dateYMD($sj)." 00:00:00";
  7. $today2=dateYMD($sj)." 23:59:59";
  8. if($_GET[control]=="ret"){deletetable("yjcode_update");php_toheader("default.php");}
  9. ?>
  10. <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
  11. <html xmlns="http://www.w3.org/1999/xhtml">
  12. <head>
  13. <meta http-equiv="x-ua-compatible" content="ie=7" />
  14. <meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
  15. <title><?=webname?>管理系统</title>
  16. <link href="css/basic.css" rel="stylesheet" type="text/css" />
  17. <script type="text/javascript" src="js/jquery.min.js"></script>
  18. <script language="javascript" src="js/basic.js"></script>
  19. <script language="javascript" src="js/layer.js"></script>
  20. <script language="javascript" src="js/gx.js"></script>
  21. <script language="javascript">
  22. function retgx(){
  23. if(confirm("建议在升级失败的情况下才提交重新升级,确定吗?")){location.href="default.php?control=ret";}else{return false;}
  24. }
  25. </script>
  26. </head>
  27. <body>
  28. <? include("top.php");?>
  29. <script language="javascript">
  30. document.getElementById("menu1").className="a1";
  31. </script>
  32. <div class="yjcode">
  33. <? $leftid=1;include("menu_quan.php");?>
  34. <div class="right">
  35. <div class="bqu1">
  36. <a class="a1" href="default.php">全局管理</a>
  37. </div>
  38. <!--B-->
  39. <div class="rkuang">
  40. <!--基础数据B-->
  41. <div class="ishuju">
  42. <ul class="u1 u11">
  43. <li class="l1"><img src="img/icon1.png" /></li>
  44. <li class="l2"><strong><?=sprintf("%.1f",returnsum("moneynum","yjcode_moneyrecord where sj>='".$today1."' and sj<='".$today2."'"));?></strong> 元<br>今日收入总额</li>
  45. </ul>
  46. <ul class="u1 u12">
  47. <li class="l1"><img src="img/icon2.png" /></li>
  48. <li class="l2"><strong><?=returncount("yjcode_user where shopzt=2 and sj>='".$today1."' and sj<='".$today2."'")?></strong> 家<br>今日新增商家</li>
  49. </ul>
  50. <ul class="u1 u13">
  51. <li class="l1"><img src="img/icon3.png" /></li>
  52. <li class="l2"><strong><?=returncount("yjcode_pro where zt=0 and lastsj>='".$today1."' and lastsj<='".$today2."'")?></strong> 个<br>今日更新商品</li>
  53. </ul>
  54. <ul class="u1 u14">
  55. <li class="l1"><img src="img/icon4.png" /></li>
  56. <li class="l2"><strong><?=returncount("yjcode_news where zt=0 and lastsj>='".$today1."' and lastsj<='".$today2."'")?></strong> 篇<br>今日更新资讯</li>
  57. </ul>
  58. <ul class="u1 u15">
  59. <li class="l1"><img src="img/icon5.png" /></li>
  60. <li class="l2"><strong><?=returncount("yjcode_order where sj>='".$today1."' and sj<='".$today2."'")?></strong> 个<br>今日订单总数</li>
  61. </ul>
  62. <ul class="u1 u16">
  63. <li class="l1"><img src="img/icon6.png" /></li>
  64. <li class="l2"><strong><?=$rowcontrol[smskc]?></strong> 条<br>短信剩余库存</li>
  65. </ul>
  66. </div>
  67. <!--基础数据E-->
  68. <!--会员走势B-->
  69. <div class="iuser">
  70. <div class="d1">会员注册数据走势图</div>
  71. <iframe marginwidth="1" marginheight="1" width="100%" height="141px" border="0" frameborder="0" src="iuser.php"></iframe>
  72. </div>
  73. <!--会员走势E-->
  74. <!--开始判断高危-->
  75. <? $errnum=0;?>
  76. <div class="gaowei" id="gaowei" style="display:none;">
  77. <span class="gaocap">您的网站发现<strong id="errnum"></strong>个高危漏洞,请尽快修复,避免严重损失</span>
  78. <?
  79. if(empty($rowcontrol[ifshell])){
  80. $testv="yes";
  81. $dirarr=array("img/",
  82. returnjgdw($rowcontrol[addir],"","gg")."/",
  83. "ckeditor/attached/",
  84. "config/ueditor/php/upload/",
  85. "config/ueditor/php/upload1/",
  86. "config/ueditor/php/upload2/",
  87. "config/ueditor/php/upload3/",
  88. "config/ueditor_mini/php/upload/",
  89. "config/ueditor_mini/php/upload1/",
  90. "config/ueditor_mini/php/upload2/",
  91. "config/ueditor_mini/php/upload3/",
  92. "upload/"
  93. );
  94. for($i=0;$i<count($dirarr);$i++){
  95. createDir("../".$dirarr[$i]);
  96. $fp= fopen("../".$dirarr[$i]."sqltest.php","w");fwrite($fp,$testv);fclose($fp);if(@htmlget(weburl.$dirarr[$i]."sqltest.php")=="yes"){
  97. $errnum++;
  98. ?>
  99. <ul class="u1" onmouseover="this.className='u1 u2';" onmouseout="this.className='u1';">
  100. <li class="l1"><a href="http://yj.928vip.cn/faq/view20.html" target="_blank">修复方法</a></li>
  101. <li class="l2">文件夹:<strong><?=$dirarr[$i]?></strong> 存在可执行脚本权限漏洞,有被注入并运行木马的风险</li>
  102. </ul>
  103. <? }}}else{?>
  104. <ul class="u1" onmouseover="this.className='u1 u2';" onmouseout="this.className='u1';">
  105. <li class="l1"><a href="inf1.php">启动检测</a></li>
  106. <li class="l2">您的后台关闭了 [脚本执行权限检测开关],如果确保该类漏洞已经修复,可忽略本条提示</li>
  107. </ul>
  108. <? $errnum++;}?>
  109. <?
  110. while1("*","yjcode_admin where adminuid='".$_SESSION["SHOPADMIN"]."'");$row1=mysql_fetch_array($res1);
  111. if(strcmp("admin",$row1[adminuid])==0){$errnum++;
  112. ?>
  113. <ul class="u1" onmouseover="this.className='u1 u2';" onmouseout="this.className='u1';">
  114. <li class="l1"><a href="adminlist.php">立即修复</a></li>
  115. <li class="l2">请不要采用admin之类的容易被猜到的字符做为管理员账号</li>
  116. </ul>
  117. <? }?>
  118. <?
  119. if(strcmp(sha1("admin"),$row1[adminpwd])==0 || strcmp(sha1("123456"),$row1[adminpwd])==0 || strcmp(sha1("admin888"),$row1[adminpwd])==0){$errnum++;
  120. ?>
  121. <ul class="u1" onmouseover="this.className='u1 u2';" onmouseout="this.className='u1';">
  122. <li class="l1"><a href="pwd.php">立即修复</a></li>
  123. <li class="l2">请不要采用admin、123456、admin888之类的容易被猜到的字符做为密码</li>
  124. </ul>
  125. <? }?>
  126. <?
  127. if(@htmlget(weburl."config/conn.php?id=1%20and%201=1")=="4004"){$errnum++;
  128. ?>
  129. <ul class="u1" onmouseover="this.className='u1 u2';" onmouseout="this.className='u1';">
  130. <li class="l1"><a href="http://yj.928vip.cn/faq/view129.html" target="_blank">点击修复</a></li>
  131. <li class="l2">您的主机/服务器未安装网站安全防护软件,建议安装,避免遭受攻击</li>
  132. </ul>
  133. <? }?>
  134. </div>
  135. <script language="javascript">
  136. if(<?=$errnum?>==0){document.getElementById("gaowei").style.display="none";}else{document.getElementById("gaowei").style.display="";document.getElementById("errnum").innerHTML=<?=$errnum?>;}
  137. </script>
  138. <!--结束判断高危-->
  139. <!--更新B-->
  140. <form name="f1" method="post" onsubmit="return callServer()">
  141. <div class="gx" id="gx1" style="display:none;">
  142. <span class="gxts">检测到有新补丁发布,建议升级</span>
  143. <ul class="uk">
  144. <li class="l1">后台密码:</li>
  145. <li class="l2"><input type="password" class="inp" name="t1" size="20" onfocus="inpf(this)" onblur="inpb(this)" /></li>
  146. <li class="l1"></li>
  147. <li class="l21">
  148. 升级后,会同步到官网最新版本,<strong class="red">如您有过二次开发,请先做好备份</strong>,
  149. 【<a href="http://yj.928vip.cn/faq/view35.html" class="blue" target="_blank">关于在线升级的详细说明</a>】
  150. </li>
  151. <li class="l3"><input type="submit" value="开始升级" class="btn1" /></li>
  152. </ul>
  153. </div>
  154. <div class="gx" id="gx2" style="display:none;">
  155. <span class="gxts">您的版本已是最新版 <span style="font-size:12px;color:#94B5DC;font-weight:100;cursor:pointer;" onClick="retgx()">[重新升级]</span></span>
  156. </div>
  157. <div class="gx" id="gx3" style="display:;">
  158. <span class="gxts">正在获取最新版本信息……</span>
  159. </div>
  160. </form>
  161. <script language="javascript">gxchk();</script>
  162. <!--更新E-->
  163. <!--待办事宜B-->
  164. <div class="idai">
  165. <div class="d1">待办事项和数据统计</div>
  166. <? $anum=returncount("yjcode_user where shopzt=1");?>
  167. <ul class="u2">
  168. <li class="l1">开店审核</li>
  169. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="userlist.php?shopzt=1">(<?=$anum?>)</a> 家</li>
  170. </ul>
  171. <? $anum=returncount("yjcode_baomoneyrecord where zt=1");?>
  172. <ul class="u2">
  173. <li class="l1">解冻保证金</li>
  174. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="baomoneylist.php?zt=1">(<?=$anum?>)</a> 笔</li>
  175. </ul>
  176. <? $anum=returncount("yjcode_tixian where zt=4");?>
  177. <ul class="u2">
  178. <li class="l1">需要处理提现</li>
  179. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="txlist.php?zt=4">(<?=$anum?>)</a> 笔</li>
  180. </ul>
  181. <? $anum=returncount("yjcode_user where sfzrz=0");?>
  182. <ul class="u2">
  183. <li class="l1">实名认证审核</li>
  184. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="userlist.php?rz=xy">(<?=$anum?>)</a> 位</li>
  185. </ul>
  186. <? $anum=returncount("yjcode_payreng where ifok=1");?>
  187. <ul class="u2">
  188. <li class="l1">人工对账审核</li>
  189. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="renglist.php?zt=1">(<?=$anum?>)</a> 笔</li>
  190. </ul>
  191. <? $anum=returncount("yjcode_user");?>
  192. <ul class="u2">
  193. <li class="l1">总用户数</li>
  194. <li class="l2"><a href="userlist.php">(<?=$anum?>)</a> 位</li>
  195. </ul>
  196. <? $anum=returncount("yjcode_pro where zt=1");?>
  197. <ul class="u2">
  198. <li class="l1">需要审核商品</li>
  199. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="productlist.php?zt=1">(<?=$anum?>)</a> 个</li>
  200. </ul>
  201. <? $anum=returncount("yjcode_pro where zt<>99");?>
  202. <ul class="u2">
  203. <li class="l1">所有商品</li>
  204. <li class="l2"><a href="productlist.php">(<?=$anum?>)</a> 个</li>
  205. </ul>
  206. <? $anum=returncount("yjcode_server where zt=1");?>
  207. <ul class="u2">
  208. <li class="l1">需要审核服务</li>
  209. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="serverlist.php?zt=1">(<?=$anum?>)</a> 个</li>
  210. </ul>
  211. <? $anum=returncount("yjcode_order where ddzt='wait'");?>
  212. <ul class="u2">
  213. <li class="l1">等待发货订单</li>
  214. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="orderlist.php?ddzt=wait">(<?=$anum?>)</a> 单</li>
  215. </ul>
  216. <? $anum=returncount("yjcode_order where ddzt='jf'");?>
  217. <ul class="u2">
  218. <li class="l1">交易纠纷</li>
  219. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="orderlist.php?ddzt=jf">(<?=$anum?>)</a> 笔</li>
  220. </ul>
  221. <? $anum=returncount("yjcode_jubao where zt=1");?>
  222. <ul class="u2">
  223. <li class="l1">需要处理举报</li>
  224. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="jubaolist.php?zt=1">(<?=$anum?>)</a> 件</li>
  225. </ul>
  226. <? $anum=returncount("yjcode_news where zt=1");?>
  227. <ul class="u2">
  228. <li class="l1">需要审核稿件</li>
  229. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="newslist.php?zt=1">(<?=$anum?>)</a> 篇</li>
  230. </ul>
  231. <? $anum=returncount("yjcode_task where zt=1 and taskty=0");?>
  232. <ul class="u2">
  233. <li class="l1">审核单人任务</li>
  234. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="tasklist.php?zt=1">(<?=$anum?>)</a> 个</li>
  235. </ul>
  236. <? $anum=returncount("yjcode_task where zt=1 and taskty=1");?>
  237. <ul class="u2">
  238. <li class="l1">审核多人任务</li>
  239. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="tasklist1.php?zt=1">(<?=$anum?>)</a> 个</li>
  240. </ul>
  241. <? $anum=returncount("yjcode_task where zt=8");?>
  242. <ul class="u2">
  243. <li class="l1">有纠纷的任务</li>
  244. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="tasklist.php?zt=8">(<?=$anum?>)</a> 个</li>
  245. </ul>
  246. <? $anum=returncount("yjcode_gd where gdzt=1 and zt<>99");?>
  247. <ul class="u2">
  248. <li class="l1">等待受理工单</li>
  249. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="gdlist.php?gdzt=1">(<?=$anum?>)</a> 个</li>
  250. </ul>
  251. <? $anum=returncount("yjcode_newspj where zt=1");?>
  252. <ul class="u2">
  253. <li class="l1">审核资讯评价</li>
  254. <li class="l2"><a class="<? if($anum>0){?>red<? }?>" href="newspjlist.php?zt=1">(<?=$anum?>)</a> 个</li>
  255. </ul>
  256. </div>
  257. <!--待办事宜E-->
  258. <!--系统参数B-->
  259. <div class="isys">
  260. <div class="d1">系统信息</div>
  261. <ul class="u2">
  262. <li class="l1">PHP版本</li>
  263. <li class="l2"><? if(strstr($adminqx,",0,") || strstr($adminqx,",0301,")){echo phpversion();}else{echo "查看权限不够";}?></li>
  264. </ul>
  265. <ul class="u2">
  266. <li class="l1">MYSQL版本</li>
  267. <li class="l2"><? if(strstr($adminqx,",0,") || strstr($adminqx,",0301,")){echo mysql_get_server_info();}else{echo "查看权限不够";}?></li>
  268. </ul>
  269. <ul class="u2">
  270. <li class="l1">服务器系统</li>
  271. <li class="l2"><? if(strstr($adminqx,",0,") || strstr($adminqx,",0301,")){echo php_uname('s').php_uname('r');}else{echo "查看权限不够";}?></li>
  272. </ul>
  273. <ul class="u2">
  274. <li class="l1">PHP运行环境</li>
  275. <li class="l2"><? if(strstr($adminqx,",0,") || strstr($adminqx,",0301,")){echo $_SERVER['SERVER_SOFTWARE'];}else{echo "查看权限不够";}?></li>
  276. </ul>
  277. <ul class="u2">
  278. <li class="l1">服务器IP</li>
  279. <li class="l2"><?=GetHostByName($_SERVER['SERVER_NAME'])?></li>
  280. </ul>
  281. <ul class="u2">
  282. <li class="l1">PHP最大上传</li>
  283. <li class="l2"><?=ini_get('upload_max_filesize')?></li>
  284. </ul>
  285. <ul class="u2">
  286. <li class="l1">是否支持CURL</li>
  287. <li class="l2"><? $a=function_exists('curl_init');if($a==1){echo "支持";}else{echo "<span class=red>不支持</span>";}?></li>
  288. </ul>
  289. <ul class="u2">
  290. <li class="l1">当前系统时间</li>
  291. <li class="l2"><?=getsj()?></li>
  292. </ul>
  293. <ul class="u2">
  294. <li class="l1">网站文件目录</li>
  295. <li class="l2"><? if(strstr($adminqx,",0,") || strstr($adminqx,",0301,")){echo str_replace('\\','/',realpath(dirname(__FILE__).'/'))."/";}else{echo "查看权限不够";}?></li>
  296. </ul>
  297. </div>
  298. <!--系统参数E-->
  299. </div>
  300. <!--E-->
  301. </div>
  302. </div>
  303. <? include("bottom.php");?>
  304. </body>
  305. </html>