!C99Shell v. 1.0 pre-release build #16!

Software: Apache/2.0.54 (Fedora). PHP/5.0.4 

uname -a: Linux mina-info.me 2.6.17-1.2142_FC4smp #1 SMP Tue Jul 11 22:57:02 EDT 2006 i686 

uid=48(apache) gid=48(apache) groups=48(apache)
context=system_u:system_r:httpd_sys_script_t
 

Safe-mode: OFF (not secure)

/home/mnnews/public_html/dwmail/   drwxr-xr-x
Free 4.04 GB of 27.03 GB (14.95%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     source.php (3.55 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
/*
############################################################################
# DWmail
#      - version 4.0
#      - Copyright (c) 2003-2006 Dominion Web Design
#      - http://www.dominion-web.com/products/dwmail/
############################################################################
#
# The contents of this file are subject to the DWmail License version
# 2.2 ('License'). You may not use this file except in compliance with
# the License. You may obtain a copy of the License at
# http://www.dominion-web.com/products/dwmail/license.php

# Software distributed under the License is distributed on an "AS IS" basis,
# without warranty of any kind, either express or implied.
#
# This code is Copyright (c) 2003-2006 Dominion Web Design.
# All rights reserved.
#
# This software may not be redistributed outside the terms of the
# license agreement.
#
############################################################################
*/
require ("./includes/init.inc.php");
require (
"./includes/global.inc.php");
require (
"./includes/imap.inc.php");
require (
"./includes/functions.inc.php");
require (
"./includes/config.inc.php");

$MainSettings = new GlobalInit();
$TransIDEnabled = $MainSettings->INIGet('session.use_trans_sid');

session_cache_limiter($DefaultSessionCache);
session_start();

if (!
$_SESSION['DefaultLang']) {
    
$_SESSION['DefaultLang'] = $DefaultLang;
}
require (
"./lang/" . strip_tags(str_replace("..", "", trim($_SESSION['DefaultLang']))) . "/global.inc.php");
@
setlocale(LC_TIME, $AvailLangs[$_SESSION['DefaultLang']]['locale']);

require (
"./includes/options.inc.php");

$id = $_GET['id'];

if (
$_GET['f']) {
    
$_SESSION['folder'] = strip_tags(trim($_GET['f']));
}

if ((
$_SESSION['sess_u'] == "") && ($_SESSION['sess_p'] == "")) {
    echo (
"<p>" . $lang['SErrors']['Session'] . "</p>");
    exit;
}

$IMAPConnection = new WM_IMAPConnection($_SESSION);

$securitycheck = $IMAPConnection->WM_IMAPCheckSecurity();
if (
$securitycheck == 0) {
    echo (
"<p>" . $lang['SErrors']['IP'] . "</p>");
    exit;
}

$mailbox = $IMAPConnection->WM_IMAPConnect();

$crlf = $MainSettings->GetCRLF();
$IMAPConnection->_crlf = $crlf;

$header = $IMAPConnection->WM_IMAPRFCHeader($id);

$action = $_GET['action'];

if (
$action == "save") {
    
$fileoutput = "$header\r\n\r\n";
    unset (
$header);
    
$fileoutput .= $IMAPConnection->WM_IMAPGetBody($id, -1, -1);
    
$IMAPConnection->WM_IMAPGetHeader($id);
    
// Bizarre Internet Explorer bug here.
    // If you try to use a content-disposition of attachment under SSL it fails
    // Unless you specify a blank cache-control and Pragma header
    // Under standard http all is OK.  Mozilla is not affected by this.
    // We recommend forwarding this to an HTTP connection rather than HTTPS

    
header("Cache-Control: "); // leave blank to avoid IE errors
    
header("Pragma: "); // leave blank to avoid IE errors
    
header("Content-type: message/rfc822");
    
header("Content-Disposition: attachment; filename=\"email_" . $id . ".eml\"");
    
header("Content-Length: " . strlen($fileoutput));
    
header("Content-Description: Email Message");
    echo (
$fileoutput);
    unset (
$fileoutput);
}

else {
    
// A message source should be in standard ASCII therefore there is no need to change language or character sets here
    
echo ("<html lang=\"en\" dir=\"ltr\"><head><title>" . $lang['MessageSource'] . "</title></head><body><pre>" . htmlspecialchars($header) . "

"
);
    unset (
$header);
    echo (
htmlspecialchars($IMAPConnection->WM_IMAPGetBody($id, -1, -1)) . "</pre></body></html>");
}

$IMAPConnection->WM_IMAPClose();
?>

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0037 ]--