!C99Shell v. 1.0 pre-release build #16!

Software: Apache/2.0.54 (Fedora). PHP/5.0.4 

uname -a: Linux mina-info.me 2.6.17-1.2142_FC4smp #1 SMP Tue Jul 11 22:57:02 EDT 2006 i686 

uid=48(apache) gid=48(apache) groups=48(apache)
context=system_u:system_r:httpd_sys_script_t
 

Safe-mode: OFF (not secure)

/home/mnnews/public_html/mina/minaeng/admin/   drwxr-xr-x
Free 3.9 GB of 27.03 GB (14.41%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     addingSpooledNews.inc.php3 (4.29 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?    


  
if(checkSuperSession($superSession, $REMOTE_ADDR))


    {


      include(
"include/rootGui.inc.php3");


      


      require(
"$mysqlCall");








      
$userId = getUserSUId($superSession);


      
$userInfo = getUserInfo($userId);


      


      if((
$userInfo[SuperUser] == 1) && ($userInfo[manageNewsSpool] == 1) && ($userInfo[active]==1))


    {


      


      
$query = "SELECT * FROM $spooledNews WHERE ID=$spooledNewsId";


      


      
$mysql_result = mysql_query($query, $mysql_link);


      


      


      if(
$row = mysql_fetch_row($mysql_result))


        {


          


          
$item_ID =    $row[0];


          
$item_title =     $row[1];


          
$item_details =   $row[2];


          
$item_date =      $row[3];


          
$userId =         $row[4];


          
$topicId =         $row[5];

             
$item_slag =         $row[6];

        





          
printf("unosim vijest....");


          
$item_details = eregi_replace("'","\'",$details);


          
//$details = eregi_replace("\"","\\\"",$details);


          





          
print("


$item_ID ,        


$item_title ,     


      $item_details ,       


          
$item_slag ,

      userId = $userId     "
);        


      


          if(
$edit)


        {


          
$insert = "insert into $news values('', '$title_edit', '$details_edit', '$item_date', '$topicId', '$userId', '$item_slag')";


          print(
"<br><br>Made sql query for edited new item<br><br>");


$extra_headers1 = "From: MINA <mnnews@mnnews.net> \n";
$extra_headers1 .= "MIME-Version: 1.0\n";
$extra_headers1 .= "Content-Type: text/plain; \n";
$extra_headers1 .= " charset=windows-1250";
$body = "<START>\n\n";
$body .= "$item_date\n\n";
$body .= "*";
$body .= "$slag_edit\n";
$body .= "$title_edit * \n\n";
$body .= "$details_edit \n\n";
$body .= "<END>";
$message = "$body";
include(
"/home/mnnews/public_html/login/adresefax.inc");
$adresa1 ="$adresa";
$extra_headers = "$extra_headers1";         

        }


          else


        {


          
$insert = "insert into $news values('', '$item_title', '$item_details', '$item_date', '$topicId', '$userId', '$item_slag')";


$extra_headers1 = "From: MINA <mnnews@mnnews.net> \n";
$extra_headers1 .= "MIME-Version: 1.0\n";
$extra_headers1 .= "Content-Type: text/plain; \n";
$extra_headers1 .= " charset=windows-1250";
$body = "<START>\n\n";
$body .= "$item_date\n\n";
$body .= "*";
$body .= "$item_slag\n";
$body .= "$item_title * \n\n";
$body .= "$item_details\n\n";
$body .= "<END>";
$message = "$body";
include(
"/home/mnnews/public_html/login/adresefax.inc");
$adresa1 ="$adresa";  
$extra_headers = "$extra_headers1";         



        }


          


          print
"<br>";


          
$result = MYSQL_QUERY($insert);        


          if(
$result)


        {print(
"Unijeto");


mail("agencija@mnnews.net", "MINA $item_date", "$message", "$extra_headers" );



}


          else


        {


          print(
"Something rather wrong here. -> Adding<br>");


          
$noAdd = 1;


        }


          


      


          if(!isset(
$noAdd))


        {


          
$query =  "SELECT * FROM $spooledNews WHERE(ID LIKE '%$spooledNewsId%')";


          


          
$insert = MYSQL_QUERY($query);


          


          
$ID = mysql_result($insert,$i, "ID");


          


          


          
$result = MYSQL_QUERY($insert);


          
$query = "DELETE FROM $spooledNews WHERE(ID=$spooledNewsId)";


          
$insert = MYSQL_QUERY($query);


          


          if(
$insert)


            {  


              print(
"Obrisano.");


            }


        }


          else


        {


          print(
"An error occured while moving news item, thus item not deleated <br>");


        }








          
/*   print "<META HTTP-EQUIV=\"Refresh\" CONTENT=\"1; URL=index.php3?mode=listNews&superSession=$superSession\">"; */


          


          
$noItems=0;        


          


        }


      


      else


        {


          


          print(
"something is wrong here");


          


        }


      


      


    }


      else


    {


      print(
"You do not have access to this function");


    }


      include(
"include/guiBase.inc.php3");


    }


  else


    {


      
//session is bad


      
print("Bad Session ID ($superSesion)!<BR>\n");


      
$superSession = "";


    }


?>


:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0036 ]--