403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/hkosl.com/dashboard/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/hkosl.com/dashboard/webadmin/sys_cms_user_modifypwform.php
<?php
header('X-UA-Compatible: IE=edge,chrome=1');
include 'config.php';
// Check if the user is logged in

if ((!isSet($_SESSION['loginname'])) || ($loggin <> '1'))
{
	header("Location: login.php");
	exit;
}


// var_dump($_POST);

if(isset($_POST['cmsloginid']) && isset($_POST['originalpw']) && isset($_POST['cmsloginpw']) && isset($_POST['cmsloginpw_confirm'])){

	if( Sys_user::changePassword( (int)$_POST['cmsloginid'], $_POST['originalpw'], $_POST['cmsloginpw'], $_POST['cmsloginpw_confirm'] ) ){
		header('Location: mainpage.php');
		exit;
	}
	else{
		header('Location: sys_cms_user_modifypwform.php?msg=Failed+to+modify+password');
		exit;
	}

}
?>
<html>
<head>
<link rel="stylesheet" type="text/css" href="css/style.css" />
<!--<meta http-equiv="x-ua-compatible" content="ie=7"/>-->
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Content Management System (CMS) </title>
	<script src="js/jquery-1.11.1.min.js"></script>
	<script src="js/jquery-migrate-1.2.1.min.js"></script>
	<script src="js/jquery.validate.min.js"></script>

<script type="text/javascript">
$(document).ready(function(e) {
	$("#myform").validate({
		rules : {
            cmsloginpw_confirm : {
                equalTo : "#cmsloginpw"
            }
	    }
	});
});
</script>
</head>
<body>
<?php
$sql = "SELECT * FROM sys_cms_login WHERE cmsloginid=:cmsloginid";
$sql_param = array(	':cmsloginid' => (int)$_SESSION["cmsloginid"] );

	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
	}

	if (!$sth->execute($sql_param)) {
		throw new Exception('[' . $sth->errorCode() . ']: ' . print_r($sth->errorInfo()));
	}

if ( !$row = $sth->fetch() ) {
	header('Location: logout.php');
}

?>
<form method="post" name="modifyform" id="myform" enctype="multipart/form-data" autocomplete="off">
<input type="hidden" name="cmsloginid" value="<?=$row{'cmsloginid'};?>">
<input type="hidden" class="content" name="cmsloginname" value="<?=$row{'cmsloginname'}?>" id="cmsloginname" />
<table width="1000" border="0" cellpadding="0" cellspacing="0">
  <tr>
    <td height="70" align="right" valign="middle" class="icontxt"><table border="0" cellpadding="0" cellspacing="0">
      <tr>        
        <td width="50" align="center"><a href="#" onClick="$('#myform').submit()"><img src="images/iconSave.png" alt="Save" width="32" height="32" border="0"><br>
          &nbsp;Save&nbsp;&nbsp;</a></td>
        <td width="50" align="center"><a href="logout.php"><img src="images/iconCancel.png" alt="Cancel" width="32" height="32" border="0"><br>
          &nbsp;Cancel&nbsp;&nbsp;</a></td>
        <td>&nbsp;</td>
      </tr>
    </table></td>
  </tr>
  <tr>
    <td class="pagetitletxt">&nbsp;&nbsp;<b><img src="images/iconList.jpg" width="48" height="48" align="absmiddle" /> Please update your password </b></td>
  </tr>

	<tr>
		<td height="25" align="left" valign="middle" class="msg"><?php if (isset($_GET["msg"])) echo $_GET['msg']; ?></td>
	</tr>

  <tr>
    <td align="left" valign="middle"><!-- Content -->
	<table border="0" cellpadding="0" cellspacing="0">
		<tr>
			<td width="120" align="right" valign="top" class='content'>Current Password</td>
			<td class='content' valign="top">:&nbsp;</td>
			<td class='content'><input type="password" class="content required" id="originalpw" name="originalpw" size="50" maxlength="15" /></td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>New Password</td>
			<td class='content' valign="top">:&nbsp;</td>
			<td class='content'><input type="password" class="content required" id="cmsloginpw" name="cmsloginpw" size="50" maxlength="15" /><?=Password::ajax_validate('cmsloginpw', 'ajax_passwordChecker.php', 'cmsloginname')?> length:8-15</td>
		</tr>
		<tr>
			<td width="120" align="right" valign="top" class='content'>Confirm New Password</td>
			<td class='content' valign="top">:&nbsp;</td>
			<td class='content'><input type="password" class="content required" id="cmsloginpw_confirm" name="cmsloginpw_confirm" size="50" maxlength="15"  /></td>
		</tr>		
		</table>		
	<!-- End Content --></td>
  </tr>
  <tr>
    <td align="left" valign="middle">&nbsp;</td>
  </tr>
</table>
</form>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit