!C99Shell v. 1.0 pre-release build #16!

Software: Apache/2.0.54 (Fedora). PHP/5.0.4 

uname -a: Linux mina-info.me 2.6.17-1.2142_FC4smp #1 SMP Tue Jul 11 22:57:02 EDT 2006 i686 

uid=48(apache) gid=48(apache) groups=48(apache)
context=system_u:system_r:httpd_sys_script_t
 

Safe-mode: OFF (not secure)

/home/mnnews/public_html/mina/minaalb/admin/   drwxr-xr-x
Free 3.9 GB of 27.03 GB (14.42%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     changePass.inc.php3 (1.89 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?

if((checkSuperSession($superSession, $REMOTE_ADDR) || (checkNormalSession($session, $REMOTE_ADDR))))
    {
      
      require(
"$mysqlCall");
      
      if(isset(
$superSession))
    {
      include(
"include/rootGui.inc.php3");
      
$userId = getUserSUId($superSession);
    }
      else
    {
      include(
"include/userGui.inc.php3");
      
$userId = getUserId($session);
    }
      
      
$userInfo = getUserInfo($userId);
      
      
$oldPass = crypt($oldPass, $userInfo[user]);
      
     
/*  print("<br>old pass =  $oldPass, user = $userInfo[user], curr pass = $userInfo[pass] <br>"); */

      
      
      
if($oldPass != $userInfo[pass])
    {
      
          print(
"Current password provided is incorect.<br>Go Back and try again");    
    }
      
      else if(
$newPass1 != $newPass2)
    {
          print(
"The second new password entery does not match the first new password entry<br>Go Back and try again");     
    }
      
      
      else if((
strlen($newPass1) <=5)  || (strlen($newPass2) <=5 ))
        {
          print(
"New password is to short, must at least 6 char long<br>Go Back and try again");      
        }
      
      else
    {
      
      require(
"$mysqlCall");
        
/* print("email = $item_email"); */  
      
      
$newPass1 = crypt($newPass1, $userInfo[user]);
      
      
$query = "replace into $users values('$userInfo[ID]', '$userInfo[user]', '$newPass1', '$userInfo[SuperUser]', '$userInfo[email]', '$userInfo[notify]', '$userInfo[active]','$userInfo[manageUsers]', '$userInfo[addNews]', '$userInfo[manageNews]','$userInfo[manageNewsSpool]','$userInfo[manageTopics]', '$userInfo[manageImages]')";


      
$mysql_result=mysql_query($query) or die(mysql_error());
      
      if(
$mysql_result)
        {
          print(
"Looks as though that worked :)");
        }
      
      else
        {
          print(
"Something Wrong Here");
        }
    }
       include(
"include/guiBase.inc.php3");
    }
      
     



?>

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0035 ]--