LICENSE: GPLv2 # require("dbconnect.php"); $PHP_AUTH_USER=$_SERVER['PHP_AUTH_USER']; $PHP_AUTH_PW=$_SERVER['PHP_AUTH_PW']; $PHP_SELF=$_SERVER['PHP_SELF']; if (isset($_GET["vendor_id"])) {$vendor_id=$_GET["vendor_id"];} elseif (isset($_POST["vendor_id"])) {$vendor_id=$_POST["vendor_id"];} if (isset($_GET["phone"])) {$phone=$_GET["phone"];} elseif (isset($_POST["phone"])) {$phone=$_POST["phone"];} if (isset($_GET["lead_id"])) {$lead_id=$_GET["lead_id"];} elseif (isset($_POST["lead_id"])) {$lead_id=$_POST["lead_id"];} if (isset($_GET["first_name"])) {$first_name=$_GET["first_name"];} elseif (isset($_POST["first_name"])) {$first_name=$_POST["first_name"];} if (isset($_GET["last_name"])) {$last_name=$_GET["last_name"];} elseif (isset($_POST["last_name"])) {$last_name=$_POST["last_name"];} if (isset($_GET["phone_number"])) {$phone_number=$_GET["phone_number"];} elseif (isset($_POST["phone_number"])) {$phone_number=$_POST["phone_number"];} if (isset($_GET["end_call"])) {$end_call=$_GET["end_call"];} elseif (isset($_POST["end_call"])) {$end_call=$_POST["end_call"];} if (isset($_GET["DB"])) {$DB=$_GET["DB"];} elseif (isset($_POST["DB"])) {$DB=$_POST["DB"];} if (isset($_GET["dispo"])) {$dispo=$_GET["dispo"];} elseif (isset($_POST["dispo"])) {$dispo=$_POST["dispo"];} if (isset($_GET["list_id"])) {$list_id=$_GET["list_id"];} elseif (isset($_POST["list_id"])) {$list_id=$_POST["list_id"];} if (isset($_GET["campaign_id"])) {$campaign_id=$_GET["campaign_id"];} elseif (isset($_POST["campaign_id"])) {$campaign_id=$_POST["campaign_id"];} if (isset($_GET["phone_code"])) {$phone_code=$_GET["phone_code"];} elseif (isset($_POST["phone_code"])) {$phone_code=$_POST["phone_code"];} if (isset($_GET["server_ip"])) {$server_ip=$_GET["server_ip"];} elseif (isset($_POST["server_ip"])) {$server_ip=$_POST["server_ip"];} if (isset($_GET["extension"])) {$extension=$_GET["extension"];} elseif (isset($_POST["extension"])) {$extension=$_POST["extension"];} if (isset($_GET["channel"])) {$channel=$_GET["channel"];} elseif (isset($_POST["channel"])) {$channel=$_POST["channel"];} if (isset($_GET["call_began"])) {$call_began=$_GET["call_began"];} elseif (isset($_POST["call_began"])) {$call_began=$_POST["call_began"];} if (isset($_GET["parked_time"])) {$parked_time=$_GET["parked_time"];} elseif (isset($_POST["parked_time"])) {$parked_time=$_POST["parked_time"];} if (isset($_GET["tsr"])) {$tsr=$_GET["tsr"];} elseif (isset($_POST["tsr"])) {$tsr=$_POST["tsr"];} if (isset($_GET["address1"])) {$address1=$_GET["address1"];} elseif (isset($_POST["address1"])) {$address1=$_POST["address1"];} if (isset($_GET["address2"])) {$address2=$_GET["address2"];} elseif (isset($_POST["address2"])) {$address2=$_POST["address2"];} if (isset($_GET["address3"])) {$address3=$_GET["address3"];} elseif (isset($_POST["address3"])) {$address3=$_POST["address3"];} if (isset($_GET["city"])) {$city=$_GET["city"];} elseif (isset($_POST["city"])) {$city=$_POST["city"];} if (isset($_GET["state"])) {$state=$_GET["state"];} elseif (isset($_POST["state"])) {$state=$_POST["state"];} if (isset($_GET["postal_code"])) {$postal_code=$_GET["postal_code"];} elseif (isset($_POST["postal_code"])) {$postal_code=$_POST["postal_code"];} if (isset($_GET["province"])) {$province=$_GET["province"];} elseif (isset($_POST["province"])) {$province=$_POST["province"];} if (isset($_GET["country_code"])) {$country_code=$_GET["country_code"];} elseif (isset($_POST["country_code"])) {$country_code=$_POST["country_code"];} if (isset($_GET["alt_phone"])) {$alt_phone=$_GET["alt_phone"];} elseif (isset($_POST["alt_phone"])) {$alt_phone=$_POST["alt_phone"];} if (isset($_GET["email"])) {$email=$_GET["email"];} elseif (isset($_POST["email"])) {$email=$_POST["email"];} if (isset($_GET["security"])) {$security=$_GET["security"];} elseif (isset($_POST["security"])) {$security=$_POST["security"];} if (isset($_GET["comments"])) {$comments=$_GET["comments"];} elseif (isset($_POST["comments"])) {$comments=$_POST["comments"];} if (isset($_GET["status"])) {$status=$_GET["status"];} elseif (isset($_POST["status"])) {$status=$_POST["status"];} if (isset($_GET["submit"])) {$submit=$_GET["submit"];} elseif (isset($_POST["submit"])) {$submit=$_POST["submit"];} if (isset($_GET["SUBMIT"])) {$SUBMIT=$_GET["SUBMIT"];} elseif (isset($_POST["SUBMIT"])) {$SUBMIT=$_POST["SUBMIT"];} if (isset($_GET["CBchangeUSERtoANY"])) {$CBchangeUSERtoANY=$_GET["CBchangeUSERtoANY"];} elseif (isset($_POST["CBchangeUSERtoANY"])) {$CBchangeUSERtoANY=$_POST["CBchangeUSERtoANY"];} if (isset($_GET["CBchangeUSERtoUSER"])) {$CBchangeUSERtoUSER=$_GET["CBchangeUSERtoUSER"];} elseif (isset($_POST["CBchangeUSERtoUSER"])) {$CBchangeUSERtoUSER=$_POST["CBchangeUSERtoUSER"];} if (isset($_GET["CBchangeANYtoUSER"])) {$CBchangeANYtoUSER=$_GET["CBchangeANYtoUSER"];} elseif (isset($_POST["CBchangeANYtoUSER"])) {$CBchangeANYtoUSER=$_POST["CBchangeANYtoUSER"];} if (isset($_GET["callback_id"])) {$callback_id=$_GET["callback_id"];} elseif (isset($_POST["callback_id"])) {$callback_id=$_POST["callback_id"];} if (isset($_GET["CBuser"])) {$CBuser=$_GET["CBuser"];} elseif (isset($_POST["CBuser"])) {$CBuser=$_POST["CBuser"];} if (isset($_GET["modify_logs"])) {$modify_logs=$_GET["modify_logs"];} elseif (isset($_POST["modify_logs"])) {$modify_logs=$_POST["modify_logs"];} $PHP_AUTH_USER = ereg_replace("[^0-9a-zA-Z]","",$PHP_AUTH_USER); $PHP_AUTH_PW = ereg_replace("[^0-9a-zA-Z]","",$PHP_AUTH_PW); ### AST GUI database administration modify lead in vicidial_list ### admin_modify_lead.php # this is the administration lead information modifier screen, the administrator just needs to enter the leadID and then they can view and modify the information in the record for that lead # CHANGES # # 60419-1705 - Added ability to change lead callback record from USERONLY to ANYONE or USERONLY-user # 60421-1459 - check GET/POST vars lines with isset to not trigger PHP NOTICES # 60609-1112 - Added DNC list addition if status changed to DNC # 60619-1539 - Added variable filtering to eliminate SQL injection attack threat # 61130-1639 - Added recording_log lookup and list for this lead_id # 61201-1136 - Added recording_log user(TSR) display and link # 70305-1133 - Changed to default CHECKED modify logs upon status change # $STARTtime = date("U"); $TODAY = date("Y-m-d"); $NOW_TIME = date("Y-m-d H:i:s"); $stmt="SELECT count(*) from vicidial_users where user='$PHP_AUTH_USER' and pass='$PHP_AUTH_PW' and user_level > 7 and modify_leads='1';"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); $row=mysql_fetch_row($rslt); $auth=$row[0]; if ($WeBRooTWritablE > 0) {$fp = fopen ("./project_auth_entries.txt", "a");} $date = date("r"); $ip = getenv("REMOTE_ADDR"); $browser = getenv("HTTP_USER_AGENT"); if( (strlen($PHP_AUTH_USER)<2) or (strlen($PHP_AUTH_PW)<2) or (!$auth)) { Header("WWW-Authenticate: Basic realm=\"VICI-PROJECTS\""); Header("HTTP/1.0 401 Unauthorized"); echo "Invalid Username/Password: |$PHP_AUTH_USER|$PHP_AUTH_PW|\n"; exit; } else { if($auth>0) { $stmt="SELECT full_name,modify_leads from vicidial_users where user='$PHP_AUTH_USER' and pass='$PHP_AUTH_PW'"; $rslt=mysql_query($stmt, $link); $row=mysql_fetch_row($rslt); $LOGfullname =$row[0]; $LOGmodify_leads =$row[1]; if ($WeBRooTWritablE > 0) { fwrite ($fp, "VICIDIAL|GOOD|$date|$PHP_AUTH_USER|$PHP_AUTH_PW|$ip|$browser|$LOGfullname|\n"); fclose($fp); } } else { if ($WeBRooTWritablE > 0) { fwrite ($fp, "VICIDIAL|FAIL|$date|$PHP_AUTH_USER|$PHP_AUTH_PW|$ip|$browser|\n"); fclose($fp); } } } ?> VICIDIAL ADMIN: Lead record modification
VICIDIAL ADMIN: Lead record modification
\n"; if ($end_call > 0) { $call_length = ($STARTtime - $call_began); ### insert a NEW record to the vicidial_closer_log table $stmt="INSERT INTO vicidial_closer_log (lead_id,list_id,campaign_id,call_date,start_epoch,end_epoch,length_in_sec,status,phone_code,phone_number,user,comments,processed) values('" . mysql_real_escape_string($lead_id) . "','" . mysql_real_escape_string($list_id) . "','" . mysql_real_escape_string($campaign_id) . "','" . mysql_real_escape_string($parked_time) . "','" . mysql_real_escape_string($call_began) . "','$STARTtime','" . mysql_real_escape_string($call_length) . "','" . mysql_real_escape_string($status) . "','" . mysql_real_escape_string($phone_code) . "','" . mysql_real_escape_string($phone_number) . "','$PHP_AUTH_USER','" . mysql_real_escape_string($comments) . "','Y')"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); ### update the lead record in the vicidial_list table $stmt="UPDATE vicidial_list set status='" . mysql_real_escape_string($status) . "',first_name='" . mysql_real_escape_string($first_name) . "',last_name='" . mysql_real_escape_string($last_name) . "',address1='" . mysql_real_escape_string($address1) . "',address2='" . mysql_real_escape_string($address2) . "',address3='" . mysql_real_escape_string($address3) . "',city='" . mysql_real_escape_string($city) . "',state='" . mysql_real_escape_string($state) . "',province='" . mysql_real_escape_string($province) . "',postal_code='" . mysql_real_escape_string($postal_code) . "',country_code='" . mysql_real_escape_string($country_code) . "',alt_phone='" . mysql_real_escape_string($alt_phone) . "',email='" . mysql_real_escape_string($email) . "',security_phrase='" . mysql_real_escape_string($security) . "',comments='" . mysql_real_escape_string($comments) . "' where lead_id='" . mysql_real_escape_string($lead_id) . "'"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); echo "information modified

\n"; echo "
\n"; if ( ($dispo != $status) and ($dispo == 'CBHOLD') ) { ### inactivate vicidial_callbacks record for this lead $stmt="UPDATE vicidial_callbacks set status='INACTIVE' where lead_id='" . mysql_real_escape_string($lead_id) . "' and status='ACTIVE';"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); echo "
vicidial_callback record inactivated: $lead_id
\n"; } if ( ($dispo != $status) and ($dispo == 'CALLBK') ) { ### inactivate vicidial_callbacks record for this lead $stmt="UPDATE vicidial_callbacks set status='INACTIVE' where lead_id='" . mysql_real_escape_string($lead_id) . "' and status IN('ACTIVE','LIVE');"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); echo "
vicidial_callback record inactivated: $lead_id
\n"; } if ( ($dispo != $status) and ($status == 'DNC') ) { ### add lead to the internal DNC list $stmt="INSERT INTO vicidial_dnc (phone_number) values('" . mysql_real_escape_string($phone_number) . "');"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); echo "
Lead added to DNC List: $lead_id - $phone_number
\n"; } ### update last record in vicidial_agent_log and vicidial_log tables if (($dispo != $status) and ($modify_logs > 0)) { $stmt="UPDATE vicidial_log set status='" . mysql_real_escape_string($status) . "' where lead_id='" . mysql_real_escape_string($lead_id) . "' order by call_date desc limit 1"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); $stmt="UPDATE vicidial_agent_log set status='" . mysql_real_escape_string($status) . "' where lead_id='" . mysql_real_escape_string($lead_id) . "' order by agent_log_id desc limit 1"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); } } else { if ($CBchangeUSERtoANY == 'YES') { ### inactivate vicidial_callbacks record for this lead $stmt="UPDATE vicidial_callbacks set recipient='ANYONE' where callback_id='" . mysql_real_escape_string($callback_id) . "';"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); echo "
vicidial_callback record changed to ANYONE
\n"; } if ($CBchangeUSERtoUSER == 'YES') { ### inactivate vicidial_callbacks record for this lead $stmt="UPDATE vicidial_callbacks set user='" . mysql_real_escape_string($CBuser) . "' where callback_id='" . mysql_real_escape_string($callback_id) . "';"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); echo "
vicidial_callback record user changed to $CBuser
\n"; } if ($CBchangeANYtoUSER == 'YES') { ### inactivate vicidial_callbacks record for this lead $stmt="UPDATE vicidial_callbacks set user='" . mysql_real_escape_string($CBuser) . "',recipient='USERONLY' where callback_id='" . mysql_real_escape_string($callback_id) . "';"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); echo "
vicidial_callback record changed to USERONLY, user: $CBuser
\n"; } $stmt="SELECT count(*) from vicidial_list where lead_id='" . mysql_real_escape_string($lead_id) . "'"; $rslt=mysql_query($stmt, $link); if ($DB) {echo "$stmt\n";} $row=mysql_fetch_row($rslt); $lead_count = $row[0]; if ($lead_count > 0) { $stmt="SELECT * from vicidial_list where lead_id='" . mysql_real_escape_string($lead_id) . "'"; $rslt=mysql_query($stmt, $link); if ($DB) {echo "$stmt\n";} $row=mysql_fetch_row($rslt); $lead_id = "$row[0]"; $dispo = "$row[3]"; $tsr = "$row[4]"; $vendor_id = "$row[5]"; $list_id = "$row[7]"; $campaign_id = "$row[8]"; $phone_code = "$row[10]"; $phone_number = "$row[11]"; $title = "$row[12]"; $first_name = "$row[13]"; # $middle_initial = "$row[14]"; $last_name = "$row[15]"; # $address1 = "$row[16]"; # $address2 = "$row[17]"; # $address3 = "$row[18]"; # $city = "$row[19]"; # $state = "$row[20]"; # $province = "$row[21]"; # $postal_code = "$row[22]"; # $country_code = "$row[23]"; # $gender = "$row[24]"; $date_of_birth = "$row[25]"; $alt_phone = "$row[26]"; # $email = "$row[27]"; # $security = "$row[28]"; # $comments = "$row[29]"; # echo "
Call information: $first_name $last_name - $phone_number

\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "
Vendor ID: $vendor_id     Lead ID: $lead_id
Fronter: $tsr     List ID: $list_id
First Name:   \n"; echo " Last Name:
Address 1 :
Address 2 :
Address 3 :
City :
State:   \n"; echo " Postal Code:
Province :
Country :
Alt Phone :
Email :
Security :
Comments :
Disposition:
Modify agent and vicidial logs
\n"; echo "


\n"; if ( ($dispo == 'CALLBK') or ($dispo == 'CBHOLD') ) { ### find any vicidial_callback records for this lead $stmt="select * from vicidial_callbacks where lead_id='" . mysql_real_escape_string($lead_id) . "' and status IN('ACTIVE','LIVE') order by callback_id desc LIMIT 1;"; if ($DB) {echo "|$stmt|\n";} $rslt=mysql_query($stmt, $link); $CB_to_print = mysql_num_rows($rslt); $rowx=mysql_fetch_row($rslt); if ($CB_to_print>0) { if ($rowx[9] == 'USERONLY') { echo "
\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "

\n"; echo "
\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "New Callback Owner UserID: \n"; echo "

\n"; } else { echo "
\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "New Callback Owner UserID: \n"; echo "

\n"; } } else { echo "
No Callback records found
\n"; } } } else { echo "lead lookup FAILED for lead_id $lead_id       $NOW_TIME\n

\n"; # echo "Close this window\n

\n"; } echo "

\n"; echo "
\n"; echo "CALLS TO THIS LEAD:\n"; echo "\n"; echo "\n"; $stmt="select * from vicidial_log where lead_id='" . mysql_real_escape_string($lead_id) . "' order by uniqueid desc limit 500;"; $rslt=mysql_query($stmt, $link); $logs_to_print = mysql_num_rows($rslt); $u=0; while ($logs_to_print > $u) { $row=mysql_fetch_row($rslt); if (eregi("1$|3$|5$|7$|9$", $u)) {$bgcolor='bgcolor="#B9CBFD"';} else {$bgcolor='bgcolor="#9BB9FB"';} $u++; echo ""; echo ""; echo ""; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; } echo "
# DATE/TIME LENGTH STATUS TSR CAMPAIGN LIST LEAD
$u$row[4] $row[7] $row[8] $row[11] $row[3] $row[2] $row[1]
\n"; echo "

\n"; echo "RECORDINGS FOR THIS LEAD:\n"; echo "\n"; echo "\n"; $stmt="select * from recording_log where lead_id='" . mysql_real_escape_string($lead_id) . "' order by recording_id desc limit 500;"; $rslt=mysql_query($stmt, $link); $logs_to_print = mysql_num_rows($rslt); $u=0; while ($logs_to_print > $u) { $row=mysql_fetch_row($rslt); if (eregi("1$|3$|5$|7$|9$", $u)) {$bgcolor='bgcolor="#B9CBFD"';} else {$bgcolor='bgcolor="#9BB9FB"';} $u++; echo ""; echo ""; echo ""; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo ""; echo "\n"; } echo "
# LEADDATE/TIME SECONDS   RECIDFILENAMELOCATIONTSR
$u $row[12] $row[4] $row[8] $row[0] $row[10] $row[11] $row[13]
\n"; } $ENDtime = date("U"); $RUNtime = ($ENDtime - $STARTtime); echo "\n\n\n


\n\n"; echo "\n\n\n


\nscript runtime: $RUNtime seconds
"; ?>