!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/cvc/application/views/version/   drwxr-xr-x
Free 50.65 GB of 127.8 GB (39.63%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     v_his_ag_update_system.php (3.55 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<div class="ver_header">ประวัติการดาวน์โหลด / อัพเดทระบบ</div>
<p>&nbsp;</p>
<?php 
    $sys_row 
= (isset($qu_sys2)) ? $qu_sys2->row() : null
    
//$flag = (isset($flag)) ? $flag : null;
?>
<?php 
echo form_open($this->config->item("ver_folder").'history/ag_update_system');?>
<table border="0" width="90%" align="center">
    <tr class="light1">
        <td height="30" width="20%"><b>ชื่อระบบ : </b></td>
        <td align="left">
            <?php
                $sys_js 
'id="system_select"';
                echo 
form_dropdown('system_select'$qu_sysgetval('system_select'$sys_row), $sys_js);
            
?>
        </td>
    </tr>
    <tr class="light1">
        <td>
            <table border="0" width="100%">
                <tr><td rowspan="2" width="50" align="center"><b>วันที่</b></td><td><b><input type="radio" id="datetype" name="datetype" value="download" <?php if($flag == 1) echo "checked";?> />&nbsp;ดาวน์โหลด</b></td></tr>
                <tr><td><b><input type="radio" id="datetype" name="datetype" value="update" <?php if($flag == 2) echo "checked";?> />&nbsp;อัพเดท</b></td></tr>
            </table>
        </td>
        <td align="left"><script>DateInput('fdate', true, 'DD/MM/YYYY','<?php echo (set_value("fdate")=="") ? getNowDateFw2() : set_value("fdate");?>');</script>&nbsp;ถึง<script>DateInput('tdate', true, 'DD/MM/YYYY','<?php echo (set_value("tdate")=="") ? getNowDateFw2() : set_value("tdate");?>');</script></td>
    </tr>
    <tr><td colspan="2">&nbsp;</td></tr>
    <tr>
        <td class="ver_center" colspan="2"><input type="submit" id="btnOK" name="btnOK" value="ค้นหา" /></td>
    </tr>
</table>
<?php echo form_close();?>
<p>&nbsp;</p>
<table class="ver_table" style="width:90%;">
        <thead>     
            <tr>
                <th>ลำดับที่</th>
                <th>เวอร์ชันแพคเกจ</th>
                <th>รายละเอียดแพคเกจ</th>
                <th>วันที่ดาวน์โหลด</th>
                <th>สถานะการดาวน์โหลด</th>
                <th>วันที่อัพเดท</th>
                <th>สถานะการอัพเดท</th>
            </tr>
        </thead>
        <tbody>
<?php
        
if(isset($qu_by_ag) && $qu_by_ag->num_rows != 0){
            
$i 1;
            foreach(
$qu_by_ag->result() as $row)
            {
?>
                <tr>
                    <td class="ver_center"><?php echo $i++;?></td>
                    <td class="ver_center"><?php echo $row->pkg_version?></td>
                    <td><?php echo $row->pkg_detail?></td>
                    <td class="ver_center"><?php echo abbreDate(splitDateDb2($row->pkg_download_date)); ?></td>
                    <td class="ver_center"><?php     if ($row->pkg_download_status == '2') {
                                    echo 
"<img src=".base_url().'images/right.jpg'.">";
                                } else {
                                    echo 
"<img src=".base_url().'images/delete.gif'.">";
                                }
                        
?>
                    </td>
                    <td class="ver_center"><?php echo ($row->pkg_update_date != '0000-00-00') ? abbreDate(splitDateDb2($row->pkg_update_date)) : '-'?></td>
                    <td class="ver_center"><?php     if ($row->pkg_update_status == 'Y') {
                                    echo 
"<img src=".base_url().'images/right.jpg'.">";
                                } else {
                                    echo 
"<img src=".base_url().'images/delete.gif'.">";
                                    echo 
"<br />";
                                    echo 
"<a href=".site_url().$this->config->item('ver_folder').'updateversion/download_pkg'."><span style='color:red;'>คลิกที่นี่เพื่ออัพเดทระบบ</span></a>";
                                }
                        
?>
                    </td>
                </tr>
<?php        }
        } else {
?>
            <tr>
                <td class="ver_center" colspan="8">
                    <span class="ver_error">
                    <?php echo $this->config->item('ver_not_found');?>
                    </span>
                </td>
            </tr>
<?php
        
}
?>
    </tbody>
</table>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0063 ]--