PNG IHDR x sBIT|d pHYs + tEXtSoftware www.inkscape.org< ,tEXtComment
<?php
session_start();
require('includes/connect.php');
require('includes/functions.php');
if (!isset($_SESSION["username"])) {
header("location: ../../home/index.html");
exit;
}
$user = GetAllMemberArray($_SESSION["username"]);
$acc = Getaccount($_SESSION["username"]);
$accdd = Getaccountrow($_SESSION["username"]);
// Generate CSRF token if not set
if (empty($_SESSION['csrf_token'])) {
$_SESSION['csrf_token'] = bin2hex(random_bytes(32));
}
// Handle form submission
if (isset($_POST["Request"])) {
// CSRF token verification
if (!isset($_POST['csrf_token']) || $_POST['csrf_token'] !== $_SESSION['csrf_token']) {
die("Invalid CSRF token.");
}
// Honeypot field check (should be empty)
if (!empty($_POST['honeypot'])) {
die("Bot detected!");
}
$accd = $accdd["acc_num"];
$irate = $_POST["irate"];
$occ = $_POST["occ"];
$due = $_POST["due"];
$sym = $_POST["sym"];
$amt = $_POST["amt"];
$res = $_POST["res"];
$ltype = $_POST["ltype"];
$cid = $user["id"];
$uun = $user["Uname"];
$sta = "Pending";
$_SESSION['cot'] = rand(10, 10000);
$sql = "INSERT INTO loan
(acctno, uname, loantype, customerid, interest, occ, due, sym, loanamt, status, reason)
VALUES ('$accd','$uun','$ltype', '$cid','$irate', '$occ', '$due', '$sym', '$amt', '$sta', '$res')";
if (mysqli_query($conn, $sql)) {
$_SESSION['cot'] = rand(10, 10000);
$to = $user["email"];
$subject = 'Loan Request Sent';
$message = 'Dear Customer, Your loan request is being reviewed. Any other requirements will be communicated to you. Please use ' . $_SESSION['cot'] . ' OTP for your transfer. Thank you.';
$headers = "MIME-Version: 1.0\r\n";
$headers .= "From: richardmooresmith<support@richardmooresmith.org>\r\n";
$headers .= "Reply-To: support@richardmooresmith.org\r\n";
$headers .= "X-Mailer: PHP/" . phpversion();
mail($to, $subject, $message, $headers);
echo '<script>alert("Loan Request Sent");</script>';
header("location: loans.php");
exit;
} else {
die('Error: ' . mysqli_error($conn));
}
}
?>
<!DOCTYPE html>
<html lang="en">
<!-- Mirrored from www.multipurposethemes.com/admin/eduadmin-template/main/index4.html by HTTrack Website Copier/3.x [XR&CO'2014], Mon, 23 Nov 2020 07:24:15 GMT -->
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="description" content="">
<meta name="author" content="">
<link rel="icon" href="https://www.multipurposethemes.com/admin/eduadmin-template/images/favicon.ico">
<title>Richard Moore Smith</title>
<!-- Vendors Style-->
<link rel="stylesheet" href="css/vendors_css.css">
<!-- Style-->
<link rel="stylesheet" href="css/style.css">
<link rel="stylesheet" href="css/skin_color.css">
</head>
<body class="hold-transition light-skin sidebar-mini theme-primary">
<div class="wrapper">
<!-- <div id="loader"></div>---->
<?php
require("includes/header.php");
?>
<aside class="main-sidebar">
<!-- sidebar-->
<section class="sidebar">
<!-- sidebar menu-->
<?php
require("includes/menu.php");
?>
</section>
<div class="sidebar-footer">
<!-- item-->
<a href="javascript:void(0)" class="link" data-toggle="tooltip" title="" data-original-title="Settings" aria-describedby="tooltip92529"><span class="icon-Settings-2"></span></a>
<!-- item-->
<!-- item-->
<a href="javascript:void(0)" class="link" data-toggle="tooltip" title="" data-original-title="Logout"><span class="icon-Lock-overturning"><span class="path1"></span><span class="path2"></span></span></a>
</div>
</aside>
<!-- Content Wrapper. Contains page content -->
<div class="content-wrapper">
<div class="container-full">
<!-- Main content -->
<section class="content">
<div class="row">
<div class="col-12">
<div class="box bg-gradient-danger overflow-hidden pull-up">
<div class="box-body pr-0 pl-lg-50 pl-15 py-0">
<div class="row align-items-center">
<div class="col-12 col-lg-8">
<h1 class="font-size-40 text-white">
<?php include("includes/time.php")?>
<?php echo $user["fname"];?>!</h1>
<p class="text-white mb-0 font-size-15">
At Richard Moore Smith, Solving your Finacial needs!!!
</p>
</div>
<div class="col-12 col-lg-4"><img src="https://www.multipurposethemes.com/admin/eduadmin-template/images/svg-icon/color-svg/custom-15.svg" alt=""></div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="row">
<div class="col-xl-2 col-12"></div>
<div class="col-xl-8 col-12">
<div class="box">
<div class="box-header with-border">
<h2 class="box-title" style="align:center">Request Loan </h2>
</div>
<!-- /.box-header -->
<form action="loan.php" method="post">
<input type="hidden" name="csrf_token" value="<?php echo $_SESSION['csrf_token']; ?>">
<input type="text" name="honeypot" style="display:none;">
<div class="box-body">
<div class="row">
<div class="col-12">
<div class="form-group row">
<label class="col-sm-4 col-form-label">Account(s)</label>
<div class="col-sm-8">
<select name="acc" class="form-control">
<?php while ($row = mysqli_fetch_assoc($acc)) { ?>
<option value="<?php echo $row["acc_num"] . "/" . $row["sym"] . "/" . $row["balance"]; ?>" class="form-control">
<?php echo $row["acc_num"] . " - " . $row["sym"] . number_format($row["balance"]); ?>
</option>
<?php } ?>
</select>
</div>
</div>
<div class="form-group row">
<label class="col-sm-4 col-form-label">Loan Type</label>
<div class="col-sm-8">
<select name="ltype" class="form-control">
<option value="House Loan">House Loan</option>
<option value="Car Loan">Car Loan</option>
<option value="Business Loan">Business Loan</option>
<option value="Other Loan">Other Loan</option>
</select>
</div>
</div>
<div class="form-group row">
<label class="col-sm-4 col-form-label">Interest Rate %</label>
<div class="col-sm-8">
<input class="form-control" name="irate" readonly value="15" type="number">
</div>
</div>
<div class="form-group row">
<label class="col-sm-4 col-form-label">Loan Term</label>
<div class="col-sm-4">
<select name="occ" class="form-control">
<option value="Week">Week</option>
<option value="Month">Month</option>
<option value="Year">Year</option>
</select>
</div>
<div class="col-sm-4">
<input name="due" class="form-control" placeholder="Duration" type="number">
</div>
</div>
<div class="form-group row">
<label class="col-sm-4 col-form-label">Amount</label>
<div class="col-sm-4">
<select name="sym" class="form-control">
<option value="$">$</option>
<option value="£">£</option>
<option value="€">€</option>
</select>
</div>
<div class="col-sm-4">
<input name="amt" class="form-control" placeholder="Amount" type="number">
</div>
</div>
<div class="form-group row">
<label class="col-sm-4 col-form-label">Reason For Loan</label>
<div class="col-sm-8">
<textarea class="form-control" name="res"></textarea>
</div>
</div>
<input type="submit" name="Request" value="Request" class="btn btn-block btn-danger">
</div>
</div>
</div>
</form>
</div></div>
<?php
require("includes/footer.php");
?>
</div>
</section>
<!-- /.content -->
</div>
</div>
<!-- /.content-wrapper -->
<!-- Control Sidebar -->
<!-- /.control-sidebar -->
<!-- Add the sidebar's background. This div must be placed immediately after the control sidebar -->
<div class="control-sidebar-bg"></div>
</div>
<!-- ./wrapper -->
<!-- Page Content overlay -->
<!-- Vendor JS -->
<script src="js/vendors.min.js"></script>
<script src="js/pages/chat-popup.js"></script>
<script src="../assets/icons/feather-icons/feather.min.js"></script>
<script src="../assets/vendor_components/apexcharts-bundle/dist/apexcharts.js"></script>
<!-- EduAdmin App -->
<script src="js/template.js"></script>
<script src="js/pages/dashboard4.js"></script>
</body>
<!-- Mirrored from www.multipurposethemes.com/admin/eduadmin-template/main/index4.html by HTTrack Website Copier/3.x [XR&CO'2014], Mon, 23 Nov 2020 07:26:25 GMT -->
</html>
b IDATxytVսϓ22 A@IR:hCiZ[v*E:WũZA ^dQeQ @ !jZ'>gsV仿$|?g)&x-E