KGRKJGETMRETU895U-589TY5MIGM5JGB5SDFESFREWTGR54TY
Server : Apache/2.4.62
System : FreeBSD fbsdweb2.web.rcn.net 14.1-RELEASE FreeBSD 14.1-RELEASE releng/14.1-n267679-10e31f0946d8 GENERIC amd64
User : www ( 80)
PHP Version : 8.3.8
Disable Function : NONE
Directory :  /domains/betterpi/Old Site/admin/includes/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : /domains/betterpi/Old Site/admin/includes/downloads_view.inc
<?php

echo "<h1>VEIW \ EDIT DOWNLOADS</h1>";

switch ($_GET['action']) {
  case "write":
function SaveFile ($ttl, $filen) {
	if ($_FILES[$filen]["name"] == "") {
		$filereturn = "no";
	} else {
		if(copy($_FILES[$filen]["tmp_name"], "../UserFiles/File/".$_FILES[$filen]["name"])) {
			$file_name = $_FILES[$filen]["name"];
			$read_extension = explode(".", $file_name);
			$ext = $read_extension[1];
			$temp_name = substr($ttl, 0, 24);
			$temp_name = preg_replace("/[^\w\x7F-\xFF\s]/", "", $temp_name);
			$filereturn = str_replace(" ", "", $temp_name).".".$ext;
			@rename("../UserFiles/File/".$file_name, "../UserFiles/File/".$filereturn);
		} else {
			die ("Error upload file-$filen<br>");
		}
	}
	return $filereturn;
}

  $title = stripslashes( $_POST['title'] );
  $body = stripslashes( $_POST['FCKeditor1'] );

  $title = str_replace("\r\n", " ", $title);
  $body = str_replace("\r\n", " ", $body);

  $title = str_replace("'", "''", $title);
  $body = str_replace("'", "''", $body);

  $file1 = SaveFile ($_POST['textlink1'], "file1");
  if ($file1 == "no") { $file1 = $_POST['fl1']; }

  $file2 = SaveFile ($_POST['textlink2'], "file2");
  if ($file2 == "no") { $file2 = $_POST['fl2']; }

  $file3 = SaveFile ($_POST['textlink3'], "file3");
  if ($file3 == "no") { $file3 = $_POST['fl3']; }

  $file4 = SaveFile ($_POST['textlink4'], "file4");
  if ($file4 == "no") { $file4 = $_POST['fl4']; }

  $file5 = SaveFile ($_POST['textlink5'], "file5");
  if ($file5 == "no") { $file5 = $_POST['fl5']; }

	$sql="UPDATE downloads SET title='$title', body='$body',
	textlink1='$_POST[textlink1]', file1='$file1',
	textlink2='$_POST[textlink2]', file2='$file2',
	textlink3='$_POST[textlink3]', file3='$file3',
	textlink4='$_POST[textlink4]', file4='$file4',
	textlink5='$_POST[textlink5]', file5='$file5'
	WHERE id_dl='$_POST[id]'";
	$query = new query ($sql);

	if ( $query->result == 1) {
		echo "<meta http-equiv=\"refresh\" content=\"0; url=index.php?option=downloads_view\">";
	} else {		echo "<h1><font color=#ff0000>Error</font></h1>
		<p align=\"center\"><a href=\"JavaScript:window.close();\">Close window</a>";
	}
    break;
  default:

	$sql = ("SELECT * FROM downloads WHERE id_dl=1;");
	$query = new query ($sql); 
	$data = mysql_fetch_array($query->result);

  echo "<table border=\"0\" width=\"100%\" cellspacing=\"6\">
  <form enctype=\"multipart/form-data\" method=\"post\" action=\"".$PHP_SELF."?action=write\">
  <input name=\"id\" type=\"hidden\" value=\"1\">";

echo "
<tr><td ><font class=table_header>Title</font>
<br/><input type=\"text\" name=\"title\" size=\"65\" value=\"".$data['title']."\" class=\"in3\"></td></tr>

<tr><td><font class=table_header>Body</font></td></tr>
<tr><td>";
include("../fckeditor/fckeditor.php");
$oFCKeditor = new FCKeditor('FCKeditor1') ;
$oFCKeditor->BasePath	= "/fckeditor/";
$oFCKeditor->Value		= $data['body'];
$oFCKeditor->Create() ;
echo "</td></tr>

<tr><td><font class=table_header>File #1</font>
<br/><input type=\"file\" size=\"40\" name=\"file1\"  class=\"in3\">
<br/>current file:".$data['file1']."<input name=\"fl1\" type=\"hidden\" value=\"".$data['file1']."\">
</td></tr>
<tr><td ><font class=table_header>Text to Link to File #1</font>
<br/><input type=\"text\" name=\"textlink1\" size=\"65\" value=\"".$data['textlink1']."\" class=\"in3\">
<hr size=1 width=420/ align=left>
</td></tr>

<tr><td><font class=table_header>File #2</font>
<br/><input type=\"file\" size=\"40\" name=\"file2\"  class=\"in3\">
<br/>current file:".$data['file2']."<input name=\"fl2\" type=\"hidden\" value=\"".$data['file2']."\">
</td></tr>
<tr><td ><font class=table_header>Text to Link to File #2</font>
<br/><input type=\"text\" name=\"textlink2\" size=\"65\" value=\"".$data['textlink2']."\" class=\"in3\">
<hr size=1 width=420/ align=left>
</td></tr>

<tr><td><font class=table_header>File #3</font>
<br/><input type=\"file\" size=\"40\" name=\"file3\"  class=\"in3\">
<br/>current file:".$data['file3']."<input name=\"fl3\" type=\"hidden\" value=\"".$data['file3']."\">
</td></tr>
<tr><td ><font class=table_header>Text to Link to File #3</font>
<br/><input type=\"text\" name=\"textlink3\" size=\"65\" value=\"".$data['textlink3']."\" class=\"in3\">
<hr size=1 width=420/ align=left>
</td></tr>

<tr><td><font class=table_header>File #4</font>
<br/><input type=\"file\" size=\"40\" name=\"file4\"  class=\"in3\">
<br/>current file:".$data['file4']."<input name=\"fl4\" type=\"hidden\" value=\"".$data['file4']."\">
</td></tr>
<tr><td ><font class=table_header>Text to Link to File #4</font>
<br/><input type=\"text\" name=\"textlink4\" size=\"65\" value=\"".$data['textlink4']."\" class=\"in3\">
<hr size=1 width=420/ align=left>
</td></tr>

<tr><td><font class=table_header>File #5</font>
<br/><input type=\"file\" size=\"40\" name=\"file5\"  class=\"in3\">
<br/>current file:".$data['file5']."<input name=\"fl5\" type=\"hidden\" value=\"".$data['file5']."\">
</td></tr>
<tr><td ><font class=table_header>Text to Link to File #5</font>
<br/><input type=\"text\" name=\"textlink5\" size=\"65\" value=\"".$data['textlink5']."\" class=\"in3\">
<hr size=1 width=420/ align=left> 


</td></tr>

</form></table>";

    break;
}

?>

Anon7 - 2021