403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.155
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/news/elearning/admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/news/elearning/admin//manage_profile_auth.php
<?php

require '../configs/app_top.php';
if(!is_admin_logged_in()) { redirect(generate_admin_link("login")); exit;}
if (isset($_POST['mode']) && $_POST['mode'] == 'mp') {
  $redirectTo = "manage_profile";


  $full_name = safe_input($_POST['full_name']);
  $uemail = safe_input($_POST['uemail']);
  $new_password1 = safe_input($_POST['new_password1']);
  $new_password2 = safe_input($_POST['new_password2']);

  if ($full_name == '' || $uemail == '') {
    $_SESSION["errorMsg"] = "Please provide the required fields";
    $_SESSION["errorType"] = "danger";
  } else {

    try {

      if ($new_password1 == $new_password2 && ($new_password1 <> "")) {

        $sql = "UPDATE " . TBL_ADMIN . " SET adm_pass = :pass, adm_full_name = :uname, adm_email = :uemail  WHERE admin_id = :adm_id";
        $stmt = $DB->prepare($sql);
        $stmt->bindValue(":pass", md5($new_password1));
      } else {
       
        $sql = "UPDATE " . TBL_ADMIN . " SET adm_full_name = :uname, adm_email = :uemail WHERE admin_id = :adm_id";
        $stmt = $DB->prepare($sql);
      }

      $stmt->bindValue(":uname", $full_name);
      $stmt->bindValue(":uemail", $uemail);
      $stmt->bindValue(":adm_id", $_SESSION["admin_id"]);
      $stmt->execute();
      $retval = $stmt->rowCount();
    
      if ($retval > 0) {

        $_SESSION["errorMsg"] = "Profile has been updated successfully.";
        $_SESSION["errorType"] = "success";
        
        $_SESSION["admin_full_name"] = $full_name;
        $_SESSION["admin_email"] = $uemail;
      
      } else if ($retval == 0) {
        $_SESSION["errorMsg"] = "No changes has been made";
        $_SESSION["errorType"] = "info";
      } else {
        $_SESSION["errorMsg"] = "Failed to update profile. Try Again";
        $_SESSION["errorType"] = "danger";
      }
    } catch (Exception $ex) {
      $_SESSION["errorMsg"] = $ex->getMessage();
      $_SESSION["errorType"] = "danger";
    }
  }
  redirect(generate_admin_link($redirectTo));
}
redirect(generate_admin_link("home"));
?>

Youez - 2016 - github.com/yon3zu
LinuXploit