403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/hkosl.com/e-ims/file_manager/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/hkosl.com/e-ims/file_manager/delete_file.php
<?php
include 'config.php';

// Check if the user is logged in

if ((!isSet($_SESSION['loginname'])) || ($loggin <> '1'))
{
header("Location: login.php");
exit;
}
require("configure.php"); 

$index			= $_POST["index"];
$parentid		= $_POST["parentid"];
$companyid		= $_POST["companyid"];
$nowdate 		= date("Y-m-d H:i:s");
//print_r($_POST); 
//exit;

//Get Category function
function getAllfolderid($folderid){                
	$rtnString = "";
	$sql = "SELECT folderid FROM file_folder WHERE parentid=:parentid";
	$sth = Db::getDbh()->prepare($sql);
	$sth->execute(array(":parentid" => $folderid));
	if( $error = $sth->getError(array(":parentid" => $folderid)) ){
		var_dump($error);
	}
	$folder_count = $sth->rowCount();
	if ($folder_count > 0){                   
		while($row = $sth->fetch(PDO::FETCH_ASSOC)){
			$rtnString .= $row{'folderid'} .",".  getAllfolderid($row{'folderid'});				 
		}
	}
	return $rtnString;                                     
}

$folderid			= $_POST["folderid"];
if (is_array($folderid)){
	foreach ($folderid as $x => $v)	{
		$tfolderid = $folderid[$x];
		//Delete Folder File & DB
		$sql = "select * from file_content Where folderid=:folderid";
		$sth = Db::getDbh()->prepare($sql);
		$sth->execute(array(":folderid" => $tfolderid));
		if( $error = $sth->getError(array(":folderid" => $tfolderid)) ){
			var_dump($error);
		}
		while ($row = $sth->fetch(PDO::FETCH_ASSOC)){
			//Move File
			if($row{'filename'}){
				$source_path = "../file_manager/file/".$row{'filename'};
				$move_check = rename($source_path,"../file_manager/deleted_file/".date("Y-m-d_H-i-s")."_".$row{'filename'});
				if ($move_check === false){
					if (file_exists($source_path)) {
						die ("Could not Move the file to the path");
					}
				}
			}
			//Soft Delete File Content
			$sql = "update file_content set status='0', deleted='1', lastupby=:lastupby, lastupdate=:lastupdate where fileid=:fileid";
			$sth = Db::getDbh()->prepare($sql);
			$sql_param = array();
			$sql_param[':lastupby'] = $_SESSION['loginid'];
			$sql_param[':lastupdate'] = $nowdate;
			$sql_param[':fileid'] = $row{'fileid'};
			$sth->execute($sql_param);
			if( $error = $sth->getError($sql_param) ){
				var_dump($error);
			}
		}
	
		//Soft Delete File Content
		$sql = "update file_folder set status='0', deleted='1', lastupby=:lastupby, lastupdate=:lastupdate where folderid in (".substr($tfolderid.",".getAllfolderid($tfolderid),0, -1).")";
		$sth = Db::getDbh()->prepare($sql);
		$sql_param = array();
		$sql_param[':lastupby'] = $_SESSION['loginid'];
		$sql_param[':lastupdate'] = $nowdate;
		$sth->execute($sql_param);
		if( $error = $sth->getError($sql_param) ){
			var_dump($error);
		}
	}
}

$fileid			= $_POST["fileid"];
if (is_array($fileid)){
	foreach ($fileid as $x => $v)	{
		$tfileid = $fileid[$x];
		//Delete File & DB
		//Move File
		$sql = "select * from file_content Where fileid='$tfileid'";
		$sth = Db::getDbh()->prepare($sql);
		$sth->execute(array(":fileid" => $tfileid));
		if( $error = $sth->getError(array(":fileid" => $tfileid)) ){
			var_dump($error);
		}
		$row = $sth->fetch(PDO::FETCH_ASSOC);
		if($row{'filename'}){
			$source_path = "../file_manager/file/".$row{'filename'};
			$move_check = rename($source_path,"../file_manager/deleted_file/".date("Y-m-d_H-i-s")."_".$row{'filename'});
			if ($move_check === false){
				if (file_exists($source_path)) {
					//die ("Could not Move the file to the path");
				}
			}
		}
		//Soft Delete File Content
		$sql = "update file_content set status='0', deleted='1', lastupby=:lastupby, lastupdate=:lastupdate where fileid=:fileid";
		$sth = Db::getDbh()->prepare($sql);
		$sql_param = array();
		$sql_param[':lastupby'] = $_SESSION['loginid'];
		$sql_param[':lastupdate'] = $nowdate;
		$sql_param[':fileid'] = $row{'fileid'};
		$sth->execute($sql_param);
		if( $error = $sth->getError($sql_param) ){
			var_dump($error);
		}
	}
}

if(!is_array($fileid) && !is_array($folderid)){
	echo"<script language='javascript'>
		alert('Please Select A File.');
		history.back();
		</script>";
		exit;
}

header("Location: index.php?index=$index&companyid=$companyid&pid=$parentid");
?>

Youez - 2016 - github.com/yon3zu
LinuXploit