!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/person/admin/   drwxr-xr-x
Free 50.96 GB of 127.8 GB (39.87%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     processEntryDoc.php (14.14 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
include_once("../../class/clsConnection.php");
include_once(
"../../class/clsDB.php");
include_once 
"../global.php";
include_once 
"../class/clsDepartment.php";
include_once 
"../class/clsPerson.php";
include_once 
"../link/function.php";
include_once 
"../link/functionshow.php";
include_once 
"../class/clsDocLinePosition.php";
include_once 
"../class/clsDocLineConfig.php";
include_once 
"../class/clsReceiveSendType.php";
include_once 
"../class/clsDocType.php";
include_once 
"../class/clsDocSpeedLevel.php";
include_once 
"../class/clsDocSecreLevel.php";
include_once 
"../class/clsDocattatchesTmp.php";
include_once 
"../class/clsDocuments.php";
include_once 
"../class/clsDocattatches.php";
include_once 
"../class/clsDocReceiveSend.php";
include_once 
"../class/clsRunningDoc.php";
include_once 
"funct.php";
include_once 
"../class/clsDocInbox.php";

$oC = new clsConnection($GLOBALS['DBHOST'], $GLOBALS['DBNAME_EOFFICE'], $GLOBALS['DBUSER_EOFFICE'], $GLOBALS['DBPASS_EOFFICE']);

$oDP = new Department($oC);
$oDP2 = new Department($oC);
$oDP3 = new Department($oC);
$oDP4 = new Department($oC);
$oDP5 = new Department($oC);
$oPS = new person($oC);
$oPS2 = new person($oC);
$oPS3 = new person($oC);
$oDlc = new DocLineConfig($oC);
$oDlc2 = new DocLineConfig($oC);
$oDlc3 = new DocLineConfig($oC);
$oDlp = new docLinePosition($oC);
$oDlp1 = new docLinePosition($oC);
$oRSt = new receiveSendType($oC);
$oDt = new doctype($oC);
$oDsl = new DocSpeedLevel($oC);
$oDcl = new DocSecretLevel($oC);
$oDtmp = new DocattatchesTmp($oC);
$oDoc = new Documents($oC);
$oDoc2 = new Documents($oC);
$oDatt = new Docattatches($oC);
$oRs = new DocReceiveSend($oC);
$oRs1 = new DocReceiveSend($oC);
$oRs2 = new DocReceiveSend($oC);
$oRs3 = new DocReceiveSend($oC);
$oRs4 = new DocReceiveSend($oC);
$oRd = new runningdoc($oC);
$oDbx = new DocInbox($oC);
$oDbx1 = new DocInbox($oC);
$oDbx2 = new DocInbox($oC);

$MaxDocGroup=$oDP->SearchMaxDocGroup();
if(
$method=="setFlagread2"){ 
                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DrsflagRead="N";    
                    
$oRs->Save();    
        echo 
"<meta http-equiv='refresh' content='0; URL=regisDoc.php?RsID=$RsID&DtID=$DtID&flagshow=$flagshow'>";
    
}else if(
$method=="setFlagread3"){ 
                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DrsflagRead=" ";    
                    
$oRs->Save();    
        echo 
"<meta http-equiv='refresh' content='0; URL=regisDoc.php?RsID=$RsID&DtID=$DtID&flagshow=$flashowg'>";
}else if(
$method=="setFlagread4"){ 
                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DrsflagRead=" ";    
                    
$oRs->Save();    
        echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php?flagshow=$flagshow'>";
}else if(
$method=="updateDoc5"){ 
                    
$timesend=getNowDateTh()." ".date('H:i:s');
                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DsID=5;
    
                    
//----update DrsReadDoc
                    
if($DaSeq!=0){
                        
$count=strlen($DrsReadDoc);
                        if(
$count!=$DaSeq){
                            
$newDrsReadDoc substr_replace($DrsReadDoc"1"$DaSeq-1,-($count-1-($DaSeq-1)));
                        }else{
                            
$newDrsReadDoc substr_replace($DrsReadDoc"1"$count-1);
                        }
                        
$oRs->DrsReadDoc=$newDrsReadDoc
                    }
                    
//-----------------------
                        
                    
$oRs->Save();
                    
                    
        
?>
        <script>
        window.opener.location.href="showEntryDoc.php?DocID=<? echo $oRs->DocID?>&DrsID=<? echo $DrsID?>";
        </script>
        <?    
        
echo "<meta http-equiv='refresh' content='0; URL=$pathfile'>";
}else if(
$method=="updateDoc6"){ 
                    
$timesend=getNowDateTh()." ".date('H:i:s');
                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DsID=5;    
                    
$oRs->Save();
        
?>
        <script>
        window.opener.location.href="showDetailEntryDoc.php?DocID=<? echo $DocID?>&DrsID=<? echo $DrsID?>&flagshow=<? echo $flagshow?>&idInbox=<? echo $selectdo2?>&selectdo2=<? echo $selectdo2?>";
        </script>
        <?    
        
echo "<meta http-equiv='refresh' content='0; URL=$pathfile'>";
}else if(
$method=="acceptDoc"){ 
                    
$timesend=getNowDateTh()." ".date('H:i:s');
                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DsID=5;    
                    
$oRs->Save();
        
//echo "<meta http-equiv='refresh' content='0; URL=showEntryDoc.php?DocID=$DocID&DrsID=$DrsID'>";
        
echo "<meta http-equiv='refresh' content='0; URL=entryDoc.php'>";
}else if(
$method=="SendBack"){ 
                    
$timesend=getNowDateTh()." ".date('H:i:s');
                    
$oDoc2->SearchByKeyName($DocID,'DocID');
                    
$oDoc2->GetRecord();

                    
$oRs3->SearchDlcIDByDocIDDsID3Docgroup($oDoc2->DocID,$MaxDocGroup);
                    
$oRs3->GetRecord();

                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DsID=7;
                    
$oRs->DrsDocReceiveDate=$timesend;
                    
$oRs->DrsSendBack=$DrsSendBack;
                    
$oRs->DrsSendBackDlcID=$oRs3->DlcID;     
                    
$oRs->Save();
        echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php'>";
}else if(
$method=="acceptDoc2"){ 
                    
$timesend=getNowDateTh()." ".date('H:i:s');
                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DsID=5;
                    
$oRs->DrsDocReceiveDate=$timesend;    
                    
$oRs->Save();
        echo 
"<meta http-equiv='refresh' content='0; URL=showDetailEntryDoc.php?DocID=$DocID&DrsID=$DrsID&flagshow=$flagshow&idInbox=$selectdo2&selectdo2=$selectdo2'>";
}else if(
$method=="setDelete"){ 
                    
$oRs->SearchByKey($DrsID);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DrsDelete="Y";    
                    
$oRs->Save();    
        echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php?flagshow=$flagshow'>";

}else if(
$method=="resetFlagreadAll"){
    for(
$k=0;$k<=$z;$k++){
        if(
$unread2[$k]!=""){
            
$oRs->SearchByKey($unread2[$k]);
            
$oRs->GetRecord();
            
$oRs->Edit();
            
$oRs->DrsflagRead=" ";    
            
$oRs->Save();
        }
    }
    echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php?flagshow=$flagshow&searchName=$searchName'>";
}else if(
$method=="setFlagreadAll2"){
    
$flagCommit true;
    
$checkflagCommittrue;
    
$oC->BeginTrans();
    for(
$k=0;$k<=$i;$k++){
        if(
$unread[$k]!=""){
            
//echo "--".$unread[$k]."<br>";
            
$oRs->SearchByKey($unread[$k]);
            
$oRs->GetRecord();
            
$oRs->Edit();
            
$oRs->DrsflagRead="N";    
            
$checkflagCommit $oRs->Save();
            if(!
$checkflagCommit){ $flagCommit=$checkflagCommit;   }    
        }
    }

    if(
$flagCommit)
        
$oC->CommitTrans();
    else
        
$oC->RollbackTrans();
    
        
    echo 
"<meta http-equiv='refresh' content='0; URL=regisDoc.php?flagshow=$flagshow&RsID=$RsID&DtID=$DtID&monthe=$monthe&searchYear=$searchYear'>";
}else if(
$method=="resetFlagreadAll2"){
    
$flagCommit true;
    
$checkflagCommittrue;
    
$oC->BeginTrans();
    for(
$k=0;$k<=$z;$k++){
        if(
$unread2[$k]!=""){
            
//echo "--".$unread2[$k]."<br>";
            
$oRs->SearchByKey($unread2[$k]);
            
$oRs->GetRecord();
            
$oRs->Edit();
            
$oRs->DrsflagRead=" ";    
            
$checkflagCommit $oRs->Save();
            if(!
$checkflagCommit){ $flagCommit=$checkflagCommit;   }    
        }
    }
    if(
$flagCommit)
        
$oC->CommitTrans();
    else
        
$oC->RollbackTrans();
        
    echo 
"<meta http-equiv='refresh' content='0; URL=regisDoc.php?flagshow=$flagshow&RsID=$RsID&DtID=$DtID&monthe=$monthe&searchYear=$searchYear'>";
}else if(
$method=="deldoc"){ 
    
$flagCommit true;
    
$checkflagCommittrue;
    
$oC->BeginTrans();
        for(
$k=0;$k<=$i;$k++){
            if(
$unread[$k]!=""){
                    
$oRs->SearchByKey($unread[$k]);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DrsDelete="Y";    
                    
$checkflagCommit $oRs->Save();
                    if(!
$checkflagCommit){ $flagCommit=$checkflagCommit;   }
        }
    }    
    if(
$flagCommit)
        
$oC->CommitTrans();
    else
        
$oC->RollbackTrans();
        
        echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php?flagshow=$flagshow'>";
}else if(
$method=="deldoc2"){ 
    
$flagCommit true;
    
$checkflagCommittrue;
    
$oC->BeginTrans();
        for(
$k=0;$k<=$z;$k++){
            if(
$unread2[$k]!=""){
                    
$oRs->SearchByKey($unread2[$k]);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DrsDelete="Y";    
                    
$checkflagCommit $oRs->Save();
                    if(!
$checkflagCommit){ $flagCommit=$checkflagCommit;   }
        }
    }    
    if(
$flagCommit)
        
$oC->CommitTrans();
    else
        
$oC->RollbackTrans();
        
        echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php?flagshow=$flagshow'>";
}else if(
$method=="showdoc"){      
        echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php?flagshow=$flagshow&idInbox=$selectdo2&selectdo2=$selectdo2'>";
}else if(
$method=="setDrsInboxID"){
    
$flagCommit true;
    
$checkflagCommittrue;
    
$oC->BeginTrans();
        for(
$k=0;$k<=$i;$k++){
            if(
$unread[$k]!=""){
                    
$oRs->SearchByKey($unread[$k]);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DrsflagRead="N";
                    
$oRs->DrsInboxID=$selectdo;    
                    
$checkflagCommit $oRs->Save();
                    if(!
$checkflagCommit){ $flagCommit=$checkflagCommit;   }
        }
    }
    if(
$flagCommit)
        
$oC->CommitTrans();
    else
        
$oC->RollbackTrans();
            
        echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php?flagshow=$flagshow'>";
}else if(
$method=="setDrsInboxID2"){
    
$flagCommit true;
    
$checkflagCommittrue;
    
$oC->BeginTrans(); 
        for(
$k=0;$k<=$z;$k++){
            if(
$unread2[$k]!=""){
                    
$oRs->SearchByKey($unread2[$k]);
                    
$oRs->GetRecord();
                    
$oRs->Edit();
                    
$oRs->DrsflagRead="N";
                    
$oRs->DrsInboxID=$selectdo2;    
                    
$checkflagCommit $oRs->Save();
                    if(!
$checkflagCommit){ $flagCommit=$checkflagCommit;   }
        }
    }
    if(
$flagCommit)
        
$oC->CommitTrans();
    else
        
$oC->RollbackTrans();
            
        echo 
"<meta http-equiv='refresh' content='0; URL=entryDoc.php?flagshow=$flagshow&idInbox=$idInbox&selectdo2=$idInbox'>";
}else if(
$method=="addfolder"){ 
        
$oDbx->SearchBypersonIdInboxNamenotdel($personId,$foldernew);
        if(
$oDbx->GetRecord()=="1"){
        
?>
            <script>window.alert("ª×èÍâ¿Åà´ÍÃì¹ÕéÁÕÍÂÙèáÅéÇ ¡ÃسÒãªéª×èÍâ¿Åà´ÍÃìãËÁè");</script>
            <form  METHOD="POST" action="manageFolder.php">
            <input type="hidden" name="foldernew" value="<? echo $foldernew?>">
            <input type="hidden" name="addline" value="<? echo $addline?>">
            </form>                
        <?
            
echo "<body onload=\"document.forms[0].submit();\">";
        }else{
            
$oDbx->AddNew();
            
$oDbx->DocInboxID=$oDbx->GetNextCode();
            
//echo "DocInboxID".$oDbx->DocInboxID."<br>";
            
$oDbx->personId=$personId;
            
//echo "personId".$oDbx->personId."<br>";
            
$oDbx->InboxName=$foldernew;
            
//echo "InboxName".$oDbx->InboxName."<br>";
            
$oDbx->InboxDel=0;
            
$oDbx->seqBox=$oDbx1->SearchseqNext($personId);
            
$oDbx->Save();
            echo 
"<meta http-equiv='refresh' content='0; URL=manageFolder.php'>";
        }
        
}else if(
$method=="renamefolder"){ 
        
$oDbx->SearchBypersonIdInboxNamenotdel($personId,$editfolder);
        if(
$oDbx->GetRecord()=="1"){
        
?>
            <script>window.alert("ª×èÍâ¿Åà´ÍÃì¹ÕéÁÕÍÂÙèáÅéÇ ¡ÃسÒãªéª×èÍâ¿Åà´ÍÃìãËÁè");</script>
            <form  METHOD="POST" action="manageFolder.php">
            <input type="hidden" name="DocInboxID" value="<? echo $iddoc?>">
            <input type="hidden" name="addname" value="<? echo $addname?>">
            </form>                
        <?
            
echo "<body onload=\"document.forms[0].submit();\">";
        }else{
            
$oDbx->SearchByKey($iddoc); 
            
$oDbx->GetRecord();
            
$oDbx->Edit();
            
$oDbx->DocInboxID=$oDbx->DocInboxID;
            
//echo "DocInboxID".$oDbx->DocInboxID."<br>";
            
$oDbx->personId=$oDbx->personId;
            
//echo "personId".$oDbx->personId."<br>";
            
$oDbx->InboxName=$editfolder;
            
//echo "InboxName".$oDbx->InboxName."<br>";
            
$oDbx->InboxDel=$oDbx->InboxDel;
            
$oDbx->seqBox=$oDbx->seqBox;
            
$oDbx->Save();
            echo 
"<meta http-equiv='refresh' content='0; URL=manageFolder.php'>";
        }
}else if(
$method=="delfolder"){ 
            
$flagCommit true;
            
$checkflagCommittrue;
            
$oC->BeginTrans(); 
            
            
$oDbx->SearchByKey($iddoc); 
            
$oDbx->GetRecord();
            
$oDbx->Edit();
            
$oDbx->DocInboxID=$oDbx->DocInboxID;
            
//echo "DocInboxID".$oDbx->DocInboxID."<br>";
            
$oDbx->personId=$oDbx->personId;
            
//echo "personId".$oDbx->personId."<br>";
            
$oDbx->InboxName=$oDbx->InboxName;
            
//echo "InboxName".$oDbx->InboxName."<br>";
            
$oDbx->InboxDel="Y";
            
//echo "InboxDel".$oDbx->InboxDel."<br>";
            
$oDbx->seqBox=$oDbx->seqBox;
            
$checkflagCommit $oDbx->Save();
            if(!
$checkflagCommit){ $flagCommit=$checkflagCommit;   }
            
            if(
$countdocfolder>0){
                    
$oRs->SearchByPersonIdDrsDeleteDrsflagReadDrsInboxID($personId,$iddoc);
                    while(
$oRs->GetRecord()){
                        
$oRs->Edit();
                        
$oRs->DrsDelete="Y";    
                        
$checkflagCommit $oRs->Save();
                        if(!
$checkflagCommit){ $flagCommit=$checkflagCommit;   }
                    }
                    
            }
    if(
$flagCommit)
        
$oC->CommitTrans();
    else
        
$oC->RollbackTrans();
                
            echo 
"<meta http-equiv='refresh' content='0; URL=manageFolder.php'>";
}else if(
$method=="changeSeq"){ 
    
$flagCommit true;
    
$oC->BeginTrans();
    
    if(
$typeb=="Top"){
        
$oDbx->SearchBypersonIdNoDelFolderlimitPreSeq($ps,$seqBox); 
        
$oDbx->GetRecord();
        
        
$preboxID=$oDbx->DocInboxID;
        
$preseqBox=$oDbx->seqBox;
        
        
$thisboxID=$DocInboxID;
        
$thisseqBox=$seqBox;
        
            
$oDbx1->SearchByKey($preboxID); 
            
$oDbx1->GetRecord();
            
$oDbx1->Edit();
            
$oDbx1->seqBox=$thisseqBox;
            
//echo "seqBox1=".$oDbx1->seqBox."<br>";
            
$flagCommit $oDbx1->Save();
            
            
$oDbx2->SearchByKey($thisboxID); 
            
$oDbx2->GetRecord();
            
$oDbx2->Edit();
            
$oDbx2->seqBox=$preseqBox;
            
//echo "seqBox2=".$oDbx2->seqBox."<br>";
            
$flagCommit $oDbx2->Save();
            
            if(
$flagCommit)
                
$oC->CommitTrans();
            else
                
$oC->RollbackTrans();
        
        
    }else if(
$typeb=="Bottom"){
        
$oDbx->SearchBypersonIdNoDelFolderlimitNextSeq($ps,$seqBox); 
        
$oDbx->GetRecord();

        
$nextboxID=$oDbx->DocInboxID;
        
$nextseqBox=$oDbx->seqBox;
        
        
$thisboxID=$DocInboxID;
        
$thisseqBox=$seqBox;
        
            
$oDbx1->SearchByKey($nextboxID); 
            
$oDbx1->GetRecord();
            
$oDbx1->Edit();
            
$oDbx1->seqBox=$thisseqBox;
            
//echo "seqBox1=".$oDbx1->seqBox."<br>";
            
$flagCommit $oDbx1->Save();
            
            
$oDbx2->SearchByKey($thisboxID); 
            
$oDbx2->GetRecord();
            
$oDbx2->Edit();
            
$oDbx2->seqBox=$nextseqBox;
            
//echo "seqBox2=".$oDbx2->seqBox."<br>";
            
$flagCommit $oDbx2->Save();
            
            if(
$flagCommit)
                
$oC->CommitTrans();
            else
                
$oC->RollbackTrans();        
        
    }
    echo 
"<meta http-equiv='refresh' content='0; URL=manageFolder.php'>";
    
}
?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0185 ]--