shell bypass 403
<?php session_start();
if(isset($_SESSION['status']) != 1 || isset($_SESSION['stauts_login']) != 1 ){
header("Location:index.php");
}
?>
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<title>AdminLTE 2 | Dashboard</title>
<meta content="width=device-width, initial-scale=1, maximum-scale=1, user-scalable=no" name="viewport">
<link rel="stylesheet" href="bower_components/bootstrap/dist/css/bootstrap.min.css">
<link rel="stylesheet" href="bower_components/font-awesome/css/font-awesome.min.css">
<link rel="stylesheet" href="bower_components/Ionicons/css/ionicons.min.css">
<link rel="stylesheet" href="dist/css/AdminLTE.css">
<link rel="stylesheet" href="dist/css/skins/_all-skins.min.css">
<link rel="stylesheet" href="bower_components/morris.js/morris.css">
<link rel="stylesheet" href="bower_components/jvectormap/jquery-jvectormap.css">
<link rel="stylesheet" href="bower_components/bootstrap-datepicker/dist/css/bootstrap-datepicker.min.css">
<link rel="stylesheet" href="bower_components/bootstrap-daterangepicker/daterangepicker.css">
<link rel="stylesheet" href="plugins/bootstrap-wysihtml5/bootstrap3-wysihtml5.min.css">
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Source+Sans+Pro:300,400,600,700,300italic,400italic,600italic">
</head>
<body class="hold-transition skin-blue sidebar-mini">
<div class="wrapper">
<?php include('layout/header.php'); ?>
<?php include('layout/sidebar.php'); ?>
<div class="content-wrapper">
<div class="row">
<div class="col-md-12">
<div class="col-md-6">
<h2>Client List</h2>
<hr/>
<div id="table_client"></div>
</div>
<div class="col-md-6">
<h2>Add Client</h2>
<hr/>
<div class="panel panel-primary">
<div class="panel-heading">Add Client</div>
<div class="panel-body">
<form id="add_client" method="post" enctype="multipart/form-data">
<div id="error_add_client"></div>
<div class="row">
<div class="col-md-7">
<div class="form-group">
<label>Client Images</label><span class="text-danger">| **image size : 2066px * 886px</span>
<input type="file" class="form-control" id="client_image" name="client_image">
</div>
</div>
</div>
<button class="btn btn-primary" type="submit">Save</button>
<button type="button" class="btn btn-danger" type="reset">Close</button>
</div>
</form>
</div>
</div>
</div>
</div>
</div>
</section>
</div>
</div>
<div class="control-sidebar-bg"></div>
</div>
<!-- ./wrapper -->
</body>
<script src="bower_components/jquery/dist/jquery.min.js"></script>
<script src="bower_components/jquery-ui/jquery-ui.min.js"></script>
<script>
$.widget.bridge('uibutton', $.ui.button);
</script>
<script src="bower_components/bootstrap/dist/js/bootstrap.min.js"></script>
<script src="bower_components/raphael/raphael.min.js"></script>
<script src="bower_components/morris.js/morris.min.js"></script>
<script src="bower_components/jquery-sparkline/dist/jquery.sparkline.min.js"></script>
<script src="plugins/jvectormap/jquery-jvectormap-1.2.2.min.js"></script>
<script src="plugins/jvectormap/jquery-jvectormap-world-mill-en.js"></script>
<script src="bower_components/jquery-knob/dist/jquery.knob.min.js"></script>
<script src="bower_components/moment/min/moment.min.js"></script>
<script src="bower_components/bootstrap-daterangepicker/daterangepicker.js"></script>
<script src="bower_components/bootstrap-datepicker/dist/js/bootstrap-datepicker.min.js"></script>
<script src="plugins/bootstrap-wysihtml5/bootstrap3-wysihtml5.all.min.js"></script>
<script src="bower_components/jquery-slimscroll/jquery.slimscroll.min.js"></script>
<script src="bower_components/fastclick/lib/fastclick.js"></script>
<script src="dist/js/adminlte.min.js"></script>
<script src="dist/js/pages/dashboard.js"></script>
<script src="dist/js/demo.js"></script>
<script src="dist/js/jquery.validate.min.js"></script>
<script src="http://malsup.github.com/jquery.form.js"></script>
<script src="bower_components/datatables.net/js/jquery.dataTables.min.js"></script>
<script src="bower_components/datatables.net-bs/js/dataTables.bootstrap.min.js"></script>
<script src="dist/js/jquery.validate.min.js"></script>
<script src="http://malsup.github.com/jquery.form.js"></script>
<script>
$(document).ready(function(){
$("#table_client").load('table_client.php');
});
</script>
<script>
$('#add_client').validate({
rules: {
client_image: {
required: true,
},
},
messages: {
client_image: {
required: "<p style='color:red'>Please Insert Client Image</p>",
},
},
submitHandler: function(form) {
var client_image = $('#client_image').prop('files')[0];
var form_data = new FormData();
form_data.append('file', client_image);
$.ajax({
url: "add_client.php",
dataType: 'text',
cache: false,
contentType: false,
processData: false,
data: form_data,
type: 'post',
}).done(function(data){
console.log(data);
if(data == 1){
$("#error_add_client").html('<div class="alert alert-success" id="success-alert"><strong>Success! </strong>Add Client.</div>').fadeIn(1000).delay(3000).fadeOut(function(){ $("#table_client").load('table_client.php'); });
$('#add_client')[0].reset();
}else{
console.log(data);
return false;
}
});
}
});
var _URL = window.URL || window.webkitURL;
$("#client_image").change(function (e) {
var file, img;
if ((file = this.files[0])) {
img = new Image();
img.onload = function () {
var width = this.width;
var height = this.height;
if((width != 2066) || (height != 886)){
$("#error_add_client").html('<div class="alert alert-danger">Images size less than 2066 pixal x 886 pixel</div>').fadeIn(1000).delay(5000).fadeOut(function(){ $("#table_client").load('table_client.php'); });
$("#client_image").val("");
return false;
}
};
img.src = _URL.createObjectURL(file);
}
});
</script>
</html>