403Webshell
Server IP : 103.234.187.230  /  Your IP : 216.73.216.216
Web Server : Apache
System : Linux lserver42043-ind.megavelocity.net 3.10.0-1160.108.1.el7.x86_64 #1 SMP Thu Jan 25 16:17:31 UTC 2024 x86_64
User : apache ( 48)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/html/rsdgroup/adminPanel/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/rsdgroup/adminPanel/write_winner.php
<?php
include_once("session.php");
include_once("settings.php");

//echo '<pre>';
//print_r($_REQUEST);die;
$prefix=time();
$target_path = "../cat_images/winner/";
$target_path = $target_path . basename($prefix.$_FILES['winnerpic']['name']); 
    

    if($_FILES['winnerpic']['name']!="")
            {
               if(move_uploaded_file($_FILES['winnerpic']['tmp_name'], $target_path)) 
                    {
                            chmod($target_path,0777); 
                            //echo "The file ". basename( $_FILES['file']['name']). " has been uploaded";
                            $upload_image=basename($prefix.$_FILES['winnerpic']['name']);				
                    }

                  //  mysql_query("update  `tblProduct` set `Product_Name`='$Product_Name',`Product_Image`='$upload_image',`Species_Id`='$Species_Id',`Category_Id`='$Category_Id',`Product_Description`='$Product_Description',`Benefits`='$Benefits',`Dosage`='$Dosage',`Specification`='$Specification',`metaDescription`='$metaDescription',`metaTitle`='$metaTitle',`metaKeyword`='$metaKeyword' where `Product_Id`='$id'");
            }else{
                $upload_image = $_REQUEST['image'];
            }
            if(empty($upload_image)){
                $upload_image = 'no_img.jpg';
            }
if($_REQUEST['mode']=="Edit"){
	 $sql="Update winner_table set name = '".$_REQUEST['name']."',award = '".$_REQUEST['award']."',location = '".$_REQUEST['location']."',"
                  . "image = '".$upload_image."' where winner_id = '".$_REQUEST['winner_id']."'";
         //echo $sql;die;
}
else{
          
	  $sql="INSERT INTO winner_table set name = '".$_REQUEST['name']."',award = '".$_REQUEST['award']."',location = '".$_REQUEST['location']."',"
                  . "image = '".$upload_image."',news_id = '".$_REQUEST['id']."'";
          
}
$result=mysql_query($sql);
?>
<script>
document.location="winner_list.php?page=listwinner&id=<?=$_REQUEST['id']?>"
</script>

Youez - 2016 - github.com/yon3zu
LinuXploit