Bug #76099 [Com]: HTML <select> tag request problem at PHP server side

From: Date: Thu, 15 Mar 2018 10:37:32 +0000
Subject: Bug #76099 [Com]: HTML <select> tag request problem at PHP server side
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214368@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76099&edit=1 ID: 76099 Comment by: spam2 at rhsoft dot net Reported by: hrushiemail at gmail dot com Summary: HTML <select> tag request problem at PHP server side Status: Open Type: Bug Package: Performance problem Operating System: windows 7 64bit PHP Version: 7.2.3 Block user comment: N Private report: N New Comment: that desert of tags and code with a little SQL is a joke for a bugreport until you can provide a small and standalone runable reproducer i pretend your code is just broken and interactes with browser/proxy caches badly given that the var-name contains $row['p_token_id'] P.S.: output data directly to the client without entity encoding is prone for XSS and hidden errors like a " somewhere closing a attribute premature and so on _____________________ "HTML <select> tag value not get at server side sometime it gets but when i do long refresh then it gets" <select name="update_status<?php echo $row['p_token_id'];?>" class="form-control" onChange="check_error(<?php echo $row['p_token_id'];?>)"> Previous Comments: ------------------------------------------------------------------------ [2018-03-15 08:59:57] hrushiemail at gmail dot com Description: ------------ <?php include('common/header.php'); ?> <!-- ============================================================== --> <!-- Page Content --> <!-- ============================================================== --> <div id="page-wrapper"> <div class="container-fluid"> <div class="row bg-title"> <div class="col-lg-3 col-md-4 col-sm-4 col-xs-12"> <h4 class="page-title">Dashboard 1</h4> </div> <div class="col-lg-9 col-sm-8 col-md-8 col-xs-12"> <!--<button class="right-side-toggle waves-effect waves-light btn-info btn-circle pull-right m-l-20"><i class="ti-settings text-white"></i></button>--> <ol class="breadcrumb"> <li><a href="javascript:void(0)">MMP BIZ</a></li> <li class="active">Dashboard</li> </ol> </div> <!-- /.col-lg-12 --> </div> <!-- /.row --> <!-- ============================================================== --> <!-- Different data widgets --> <!-- ============================================================== --> </div> <div class="container-fluid"> <div class="row"> <div class="col-lg-12 text-center"> <h1 class="page-header">Pending Transactions Report</h1> </div> </div><!--/.row--> <div class="row"> <div class="col-lg-12"> <div class="col-md-12"> <div class="panel panel-default"> <div class="panel-heading"> Pending Transactions Report </div> <div class="panel-body"> <form method="post" action="export_pending_transactions.php"> <input type="submit" class="btn btn-success" name="pending_transactions_report" value="Export to Excel (.xls)"> </form> <div class="table-responsive"> <table class="table table-hover table-responsive"> <tr> <td><b>Token id</b></td> <td><b>Associate id</b></td> <td><b>Sponsor id</b></td> <td><b>Type of Payment</b></td> <td><b>Amount</b></td> <td><b>Status</b></td> <td><b>Date</b></td> <td><b>Place Reason</b></td> <td><b>Submit</b></td> </tr> <?php $query="Select * From payment_info where status!='paid'"; $result = mysqli_query($con,$query); while($row = mysqli_fetch_assoc($result)) { ?> <tr> <td> <?php echo $row['p_token_id'];?> </td> <td> <?php echo $row['associate_id'];?> </td> <td> <?php echo $row['sponsor'];?> </td> <td> <?php echo $row['type_of_payment']; ?> </td> <td> <?php echo $row['balance_amount']; ?> </td> <td> <?php echo $row['status']; ?> </td> <td> <?php echo $row['date']; ?> </td> <form method="post" name="form1"> <td> <select name="update_status<?php echo $row['p_token_id'];?>" class="form-control" onChange="check_error(<?php echo $row['p_token_id'];?>)"> <option value="paid">Paid</option> <option value="unpaid">Un-Paid</option> <option value="technical_error">Technical error</option> </select> </td> <td> <input type="hidden" name="update_type_of_payment" value="<?php echo $row['type_of_payment'];?>"/> <input type="hidden" name="update_balance_amount" value="<?php echo $row['balance_amount'];?>"/> <input type="hidden" name="update_associate_id" value="<?php echo $row['associate_id'];?>"/> <input type="hidden" name="update_sponsor" value="<?php echo $row['sponsor'];?>"/> <input type="hidden" name="update_token_id" value="<?php echo $row['p_token_id'];?>"/> <input type="hidden" name="error"/> <input type="submit" class="btn btn-danger" name="change_status" value="Submit"> </td> </form> </tr> <script language="javascript"> function check_error(demo) { var status=document.getElementsByName("update_status"+demo)[0].value; if(status=="technical_error") { var message=prompt("Enter Technical Error",""); //alert(message); document.getElementsByName("error")[0].value=message; document.form1.submit(); } } </script> <?php } @mysqli_free_result($result); ?> </table> </div> <?php if(isset($_POST['change_status'])) { $val1='update_status'.$_POST['update_token_id']; $update_status=mysqli_real_escape_string($con,$_POST[$val1]);//$_POST[$val1]; //$update_status=$_POST['update_status']; //echo "<script language='javascript'>alert('".$update_status."');</script>"; $update_associate_id=mysqli_real_escape_string($con,$_POST['update_associate_id']); $update_sponsor_id=mysqli_real_escape_string($con,$_POST['update_sponsor']); $update_type_of_payment=mysqli_real_escape_string($con,$_POST['update_type_of_payment']); $error=mysqli_real_escape_string($con,$_POST['error']); if($_POST['error']!='' && $_POST['error'] != ' ') { $update_status=$error; } //echo "<script language='javascript'>alert('".$update_status."');</script>"; if($update_type_of_payment=="Direct Joining") { $paying_associate_id=$update_sponsor_id; } if($update_type_of_payment=="Pair Completed") { $paying_associate_id=$update_associate_id; } $update_token_id=mysqli_real_escape_string($con,$_POST['update_token_id']); $update_balance_amount=mysqli_real_escape_string($con,$_POST['update_balance_amount']); $query="update payment_info set status='$update_status' where associate_id='$update_associate_id' and p_token_id='$update_token_id'"; //echo "<script language='javascript'>alert('s');</script>"; $result=mysqli_query($con,$query) or die(mysqli_error($con));//issue ite ahe 1 min tite isssue nahiye if(!$result) { echo mysqli_error($con); } if($update_status="paid") { date_default_timezone_set('UTC'); $current_date=date('Y-m-d',time()); $query2="insert into withdraw_payment values('','$update_balance_amount','$current_date','$update_token_id','$paying_associate_id')"; $result2=mysqli_query($con,$query2); if(!$result2) { echo mysqli_error($con); } } header("Refresh:0"); } ?> </div> </div> </div><!--/.row--> </div> </div> Test script: --------------- HTML <select> tag value not get at server side sometime it gets but when i do long refresh then it gets.....it sucessfully done in php5.6 version but not work properly with php 7.3 and php 7.2 version.... Expected result: ---------------- HTML <select> tag request get at sever side (per request should work properly) Actual result: -------------- please provide us patch for that ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76099&edit=1

« previous php.bugs (#214368) next »