!C99Shell v. 1.0 pre-release build #16!

Software: Apache/2.0.54 (Fedora). PHP/5.0.4 

uname -a: Linux mina-info.me 2.6.17-1.2142_FC4smp #1 SMP Tue Jul 11 22:57:02 EDT 2006 i686 

uid=48(apache) gid=48(apache) groups=48(apache)
context=system_u:system_r:httpd_sys_script_t
 

Safe-mode: OFF (not secure)

/home/mnnews/public_html/mina/test/admin/   drwxr-xr-x
Free 3.9 GB of 27.03 GB (14.41%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     addUser.inc.php3 (3.52 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?
require("$mysqlCall");
if(
checkSuperSession($superSession, $REMOTE_ADDR))
{
  
  include(
"include/rootGui.inc.php3");
  
  
$userId = getUserSUId($superSession);
  
$userInfo = getUserInfo($userId);
  
  if((
$userInfo[SuperUser] == 1) && ($userInfo[manageUsers]==1) && ($userInfo[active]==1))
    {
      
      if(
$addValues)
    {
      
$email2 = strstr($email, "@");
      
      
      if(
strlen($email2)==0)
        {
          
          print(
"Ovo nije e-mail adresa. Probajte ponovo<br><br>");
          
$ddb=0;
        }
          

      
      else
        {  
          require(
"$mysqlCall");
         
          
$query = "SELECT * FROM $users where user=\"$user\"  OR email=\"$email\"";
          
          
$mysql_result = mysql_query($query, $mysql_link);
              
          if(
$row = mysql_fetch_row($mysql_result))
        {
          print(
"Username ili e-mail adresa vec postoje u sistemu.<br>");
          
$ddb=1;
        }
          
          require(
"$mysqlCall");
          
$query = "SELECT * FROM $spooledUsers where user=\"$user\"  OR email=\"$email\"  ";
          
$mysql_result = mysql_query($query, $mysql_link);
          
          if(
$row = mysql_fetch_row($mysql_result))
        {    
           print(
"Username ili e-mail adresa vec postoje u sistemu.<br>");
           
$ddb=1;
        
        }
          
          if(!isset(
$ddb))
        {      
          
$zero=0;
          
$one=1;
          
          require(
"$mysqlCall");

          
$pass= SessionID(8);
          
        
/*   print("$pass<br>"); */

            
            
          
$pass1 = crypt($pass, $user);
          
          
$insert = "insert into $users values('', '$user', '$pass1', '$zipo', '$email', '$zipo', '$one','$zipo', '$zipo', '$zipo','$zipo', '$zipo','$zipo')";
          print
"<br>";


          
mail($email, "password", "You password is: $pass");
        

          
          
$result = MYSQL_QUERY($insert);

          if(
$result)
            {
              print(
"Unijeto");
            }
          else
            {
              print(
"Doslo je do greske");
            }



          print(
"Unijet je obican korisnik<br> Sada mu mozete dodijeliti druge privliegije ako zelite");

          
$query = "SELECT * FROM $users where user=\"$user\"";
          
          
$mysql_result = mysql_query($query, $mysql_link);
          
          if(
$row = mysql_fetch_row($mysql_result))
            {
              
$userId2 = $row[0];
            }

          
$userInfo = getUserInfo($userId2);

          include(
"userValues.inc.php3");
          
          
          print(
"user = $user");
          
          include(
"users.php3");
          
          
        }
        }
    }
  else
    {
      
      print(
"Password je kreiran i bice poslat e-mail-om korisniku<br>");

      print(
"<form method=\"post\" action=\"index.php3?mode=addUser&superSession=$superSession&addValues=1\">");
      
      print(
"<table  border=0 cellpadding=3 cellspacing=0 >");
      print(
"<tr><td bgcolor=$border_colour align=center>");
      
      print(
"<table width=100% border=0 cellpadding=5 cellspacing=0 >");
      
      print(
"<tr>\n");
      print(
"<td bgcolor=$table_colour>Korisnik</td>");
      print(
"<td bgcolor=$bgcolour><input type=text name='user'></td>");
      print(
"</tr>\n");
      
      print(
"<tr>\n");
      print(
"<td bgcolor=$table_colour>E-Mail</td>");
      print(
"<td bgcolor=$bgcolour><input type=text name='email'></td>");
      print(
"</tr>\n");
      
      print(
"<tr>\n");
      print(
"<td colspan=2 align=right bgcolor=$table_colour2><input type=submit></td>");
      print(
"</tr>\n");
      
      print(
"</table>");
      print(
"<tr><td>");
      print(
"</table>");
      print(
"<br><br>");
      
      
    }
}
else
{
  print(
"Nemate pristup ovoj funkciji<br>");
}
include(
"include/guiBase.inc.php3");


}

?>

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #16 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0033 ]--