403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.156
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/news/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/news//edit_news_save_backup.php
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />

<?php
include('db.php');
$id =$_GET['id'];
$uid =$_GET['uid'];
$storytitle= $_POST['storytitle'];
$detail= $_POST['detail'];
$storyurl=$_POST['storyurl'];

$filcheck=$_FILES["fileUpload"]["name"];

if ($filcheck==""){
$mysqli->query("UPDATE posts SET title='$storytitle',description='$detail',url='$storyurl' WHERE id='$id'");		
}else{
$news = $mysqli->query("SELECT * FROM posts WHERE id='$id'");
$row = mysqli_fetch_array($news);
$oldfile=$row['image'];
unlink("uploads/$oldfile");	
	$file_tmp=$_FILES["fileUpload"]["tmp_name"];	
	$filename = $_FILES["fileUpload"]["name"];
	$file_basename = substr($filename, 0, strripos($filename, '.')); // get file extention
	$file_ext = substr($filename, strripos($filename, '.')); // get file name
	$filesize = $_FILES["fileUpload"]["size"];
	$filenew =date("dmY-His"). "_$uid" .$file_ext;
	move_uploaded_file($file_tmp,"uploads/".$filenew);
	
		
	ini_set('memory_limit','1000M');
	set_time_limit(200);	  
	$images = "uploads/$filenew";
	$size=getimagesize($images);
	$img_w=$size[0];
	if ($img_w >690) { 
	$new_images = "uploads/$filenew";
	$width=750; 
	$size=GetimageSize($images);
	$height=round($width*$size[1]/$size[0]);
	$images_orig = ImageCreateFromJPEG($images);
	$photoX = ImagesX($images_orig);
	$photoY = ImagesY($images_orig);
	$images_fin = ImageCreateTrueColor($width, $height);
	ImageCopyResampled($images_fin, $images_orig, 0, 0, 0, 0, $width+1, $height+1, $photoX, $photoY);				
	ImageJPEG($images_fin,$new_images);
	ImageDestroy($images_orig);
	ImageDestroy($images_fin);			
	} else {}
$mysqli->query("UPDATE posts SET title='$storytitle',image='$filenew',description='$detail',url='$storyurl' WHERE id='$id'");	
}

echo "<script>window.parent.location=\"allnews_edit.php?id=$uid\"</script>";		
?>

Youez - 2016 - github.com/yon3zu
LinuXploit