403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.156
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  E:/Inetpub/www/news/move/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : E:/Inetpub/www/news/move//file_school_save.php
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Untitled Document</title>
</head>

<body>
<?php 
include("db.php");  
$id = $mysqli->escape_string($_GET['id']);
$title= $_POST['title'];
$detail= $_POST['detail'];



$user2 = $mysqli->query("SELECT * FROM users WHERE id='$id'");
$userrow2 = mysqli_fetch_array($user2);
$school=$userrow2['school'];

$user1 = $mysqli->query("SELECT * FROM categories WHERE c_name='$school' LIMIT 1");
$userrow1 = mysqli_fetch_array($user1);
$cat_id=$userrow1['id'];

//echo "$id <br>$title<br>$detail<br>$school<br>$cat_id";

		$file_tmp=$_FILES["fileUpload"]["tmp_name"];	
		$file_name=$_FILES["fileUpload"]["name"];
			$array_last = explode(".",$file_name);
			$c=count($array_last) - 1;
			$lastname=strtolower($array_last[$c]);
		    $filenew =date("Ydm-His"). "_$id." .$lastname;
 

		if(move_uploaded_file($file_tmp,"schoolfile/".$filenew))
		{

$mysqli->query("INSERT INTO sc_news(title, detail, uid, cat_id, file_name) VALUES ('$title','$detail','$id','$cat_id', '".$filenew."' )") or die (mysqli_error());				
			} 

		

$SQL= $mysqli->query("SELECT * FROM sc_news where uid='$id' ORDER BY id DESC");
$Row = mysqli_fetch_array($SQL);
$ids = $Row['id'];

/// line API  
/* $lineapi = "9MTPj1L5V50h1Yrd660TKAagfa37PmBFMBddecV9xLk";

date_default_timezone_set("Asia/Bangkok");
$chOne = curl_init();
curl_setopt( $chOne, CURLOPT_URL, "https://notify-api.line.me/api/notify");
curl_setopt( $chOne, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt( $chOne, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt( $chOne, CURLOPT_POST, 1); 

// Message
curl_setopt( $chOne, CURLOPT_POSTFIELDS, "message=\n $title \n http://news.sesao8.go.th/view.php?id=$ids \n\n $school");
curl_setopt( $chOne, CURLOPT_FOLLOWLOCATION, 1);
$headers = array( 'Content-type: application/x-www-form-urlencoded', 'Authorization: Bearer '.$lineapi.'', );
curl_setopt($chOne, CURLOPT_HTTPHEADER, $headers);
curl_setopt( $chOne, CURLOPT_RETURNTRANSFER, 1);
$result = curl_exec( $chOne );
if(curl_error($chOne)) { echo 'error:' . curl_error($chOne); }
else { $result_ = json_decode($result, true);
echo "status : ".$result_['status']; echo "message : ". $result_['message']; }
curl_close( $chOne );
*/

//echo "<meta http-equiv=refresh content=0;URL=news_office.php?id=$id>";

//}


?>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit