!C99Shell v. 1.0 pre-release build #16!

Software: Apache/2.0.54 (Fedora). PHP/5.0.4 

uname -a: Linux mina-info.me 2.6.17-1.2142_FC4smp #1 SMP Tue Jul 11 22:57:02 EDT 2006 i686 

uid=48(apache) gid=48(apache) groups=48(apache)
context=system_u:system_r:httpd_sys_script_t
 

Safe-mode: OFF (not secure)

/home/mnnews/public_html/mina/minaeng/admin/   drwxr-xr-x
Free 3.9 GB of 27.03 GB (14.42%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     addImage.inc.php3 (2.23 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |

<?
  
require("$mysqlCall");
  if(
checkSuperSession($superSession, $REMOTE_ADDR))
    {

      include(
"include/rootGui.inc.php3");
      
      
$userId = getUserSUId($superSession);
      
$userInfo = getUserInfo($userId);

      if((
$userInfo[SuperUser]==1) && ($userInfo[manageImages]==1) && ($userInfo[active]==1))
    {

      if(
$addImage)
        {
      

          
$data = addslashes(fread(fopen($form_data,  "r"), filesize($form_data)));
          
          
$result=MYSQL_QUERY(
                  
"INSERT INTO $images (description,bin_data,filename,filesize,filetype) ".
                  
                  
"VALUES ('$form_description','$data','$form_data_name','$form_data_size','$form_data_type')");
          
          
$id= mysql_insert_id();
          print  
"<p>This file has the following Database ID: <b>$id</b>";
        }

      else
        {


          print(
"<form enctype=\"multipart/form-data\" action=\"index.php3?mode=addImage&superSession=$superSession&addImage=1\" method=POST>");
      
          print(
"<table  border=0 cellpadding=3 cellspacing=0 >");
          print(
"<tr><td bgcolor=$border_colour align=center>");
          
          print(
"<table width=100% border=0 cellpadding=5 cellspacing=0 >");
          
          print(
"<tr>\n");
          print(
"<td bgcolor=$table_colour>Description</td>");
          print(
"<td bgcolor=$bgcolour><input type=text name='form_description' size=\"25\" ></td>");
          print(
"</tr>\n");
          
          print(
"<tr>\n");
          print(
"<td bgcolor=$table_colour>File</td>");
          print(
"<td bgcolor=$bgcolour><input type=\"file\" name=\"form_data\"  size=\"25\"></td>");
          print(
"</tr>\n");
          
          print(
"<tr>\n");
          print(
"<td colspan=2 align=right bgcolor=$table_colour2><input type=submit></td>");
          print(
"</tr>\n");
          
          print(
"</table>");
          print(
"<tr><td>");
          print(
"</table>");
          print(
"<br><br>");
          print(
"<INPUT TYPE=\"hidden\" name=\"MAX_FILE_SIZE\" value=\"1000000\"></form>");
          
        }

    }
      else
    {
      print(
"You do no thave access to this function");
      
    }

      include(
"include/guiBase.inc.php3");

    }
  else
    {
      
/*  session is bad */
      
print("Bad Session ID ($superSession)!<BR>\n");
      
$superSession = "";
    }
  
  
?>




:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0036 ]--