shell bypass 403
<?php session_start();
if(isset($_SESSION['status']) != 1 || isset($_SESSION['stauts_login']) != 1 ){
header("Location:index.php");
}
?>
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<title>AdminLTE 2 | Dashboard</title>
<meta content="width=device-width, initial-scale=1, maximum-scale=1, user-scalable=no" name="viewport">
<link rel="stylesheet" href="bower_components/bootstrap/dist/css/bootstrap.min.css">
<link rel="stylesheet" href="bower_components/font-awesome/css/font-awesome.min.css">
<link rel="stylesheet" href="bower_components/Ionicons/css/ionicons.min.css">
<link rel="stylesheet" href="dist/css/AdminLTE.css">
<link rel="stylesheet" href="dist/css/skins/_all-skins.min.css">
<link rel="stylesheet" href="bower_components/morris.js/morris.css">
<link rel="stylesheet" href="bower_components/jvectormap/jquery-jvectormap.css">
<link rel="stylesheet" href="bower_components/bootstrap-datepicker/dist/css/bootstrap-datepicker.min.css">
<link rel="stylesheet" href="bower_components/bootstrap-daterangepicker/daterangepicker.css">
<link rel="stylesheet" href="plugins/bootstrap-wysihtml5/bootstrap3-wysihtml5.min.css">
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Source+Sans+Pro:300,400,600,700,300italic,400italic,600italic">
</head>
<body class="hold-transition skin-blue sidebar-mini">
<div class="wrapper">
<?php include('layout/header.php'); ?>
<?php include('layout/sidebar.php'); ?>
<div class="content-wrapper">
<div class="row" style="margin-left:20px;">
<div class="col-md-6">
<h2>Director List</h2>
<hr/>
<p class="text-right"><a href="director_setting.php" class="btn btn-info" >Add Director</a></p>
<hr/>
<div id="table_director"></div>
</div>
<div class="col-md-6">
<div class="show_add_direc">
<h2>Edit Director</h2>
<hr/>
<div class="panel panel-primary ">
<div class="panel-heading">Edit Director</div>
<div class="panel-body">
<div class="row">
<div class="col-md-7">
<?php
$q = $_GET['q'];
include('../config/config.php');
$sql = "SELECT * FROM directors WHERE d_id = ".$q." ";
$res= $conn->query($sql);
while($row = $res->fetch_assoc()){
?>
<form id="update_direc" method="post" enctype="multipart/form-data">
<div id="error_edit_direc"></div>
<div class="row">
<div class="col-md-12">
<div class="form-group">
<label>Director Name</label>
<input type="text" class="form-control" id="direc_name" name="direc_name" placeholder="Director Name" value="<?php echo $row['d_name']; ?>">
<input type="hidden" class="form-control" id="direc_id" name="direc_id" value="<?php echo $row['d_id']; ?>">
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div class="form-group">
<label>Director Position</label>
<input type="text" class="form-control" id="direc_posi" name="direc_posi" placeholder="Director Position" value="<?php echo $row['d_postion']; ?>">
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div class="form-group">
<label>Director Images</label><span class="text-danger">| **image size : 736px * 815px</span>
<input type="file" class="form-control" id="direc_image" name="direc_image">
</div>
</div>
</div>
<button class="btn btn-primary" type="submit">Update</button>
</form>
</div>
<div class="col-md-5">
<img src="<?php echo "../".$row['d_image']; ?>" class="img-responsive " />
</div>
<?php
}
?>
</div>
</div>
</div>
</div>
</div>
</div>
</section>
</div>
</div>
<div class="control-sidebar-bg"></div>
</div>
<!-- ./wrapper -->
</body>
<script src="bower_components/jquery/dist/jquery.min.js"></script>
<script src="bower_components/jquery-ui/jquery-ui.min.js"></script>
<script>
$.widget.bridge('uibutton', $.ui.button);
</script>
<script src="bower_components/bootstrap/dist/js/bootstrap.min.js"></script>
<script src="bower_components/raphael/raphael.min.js"></script>
<script src="bower_components/morris.js/morris.min.js"></script>
<script src="bower_components/jquery-sparkline/dist/jquery.sparkline.min.js"></script>
<script src="plugins/jvectormap/jquery-jvectormap-1.2.2.min.js"></script>
<script src="plugins/jvectormap/jquery-jvectormap-world-mill-en.js"></script>
<script src="bower_components/jquery-knob/dist/jquery.knob.min.js"></script>
<script src="bower_components/moment/min/moment.min.js"></script>
<script src="bower_components/bootstrap-daterangepicker/daterangepicker.js"></script>
<script src="bower_components/bootstrap-datepicker/dist/js/bootstrap-datepicker.min.js"></script>
<script src="plugins/bootstrap-wysihtml5/bootstrap3-wysihtml5.all.min.js"></script>
<script src="bower_components/jquery-slimscroll/jquery.slimscroll.min.js"></script>
<script src="bower_components/fastclick/lib/fastclick.js"></script>
<script src="dist/js/adminlte.min.js"></script>
<script src="dist/js/pages/dashboard.js"></script>
<script src="dist/js/demo.js"></script>
<script src="dist/js/jquery.validate.min.js"></script>
<script src="http://malsup.github.com/jquery.form.js"></script>
<script src="bower_components/datatables.net/js/jquery.dataTables.min.js"></script>
<script src="bower_components/datatables.net-bs/js/dataTables.bootstrap.min.js"></script>
<script src="dist/js/jquery.validate.min.js"></script>
<script src="http://malsup.github.com/jquery.form.js"></script>
<script>
$(document).ready(function(){
$("#table_director").load('table_director.php');
});
var _URL = window.URL || window.webkitURL;
$("#direc_image").change(function (e) {
var file, img;
if ((file = this.files[0])) {
img = new Image();
img.onload = function () {
var width = this.width;
var height = this.height;
if((width != 736) || (height != 815)){
$("#error_edit_direc").html('<div class="alert alert-danger">Images size less than 736 pixal x 815 pixel</div>').fadeIn(1000).delay(5000).fadeOut(function(){ $("#table_client2").load('table_client.php'); });
$("#direc_image").val("");
return false;
}
};
img.src = _URL.createObjectURL(file);
}
});
</script>
<script>
$('#update_direc').validate({
rules: {
direc_name: {
required: true,
},
direc_posi: {
required: true,
},
},
messages: {
direc_name: {
required: "<p style='color:red'>Please Insert Director Name</p>",
},
direc_posi: {
required: "<p style='color:red'>Please Insert Director Position</p>",
},
},
submitHandler: function(form) {
var direc_name = $('#direc_name').val();
var direc_posi = $('#direc_posi').val();
var direc_image = $('#direc_image').prop('files')[0];
var direc_id = $('#direc_id').val();
var form_data = new FormData();
form_data.append('file', direc_image);
form_data.append('direc_posi', direc_posi);
form_data.append('direc_name', direc_name);
form_data.append('q', direc_id);
$.ajax({
url: "update_direc.php",
dataType: 'text',
cache: false,
contentType: false,
processData: false,
data: form_data,
type: 'post',
}).done(function(data){
console.log(data);
if(data == 1){
console.log(data);
$("#error_edit_direc").html('<div class="alert alert-success"><strong>Success! </strong>Edit Director.</div>').fadeIn(1000).delay(3000).fadeOut(function(){ $("#table_director").load('table_director.php'); });
}else{
console.log(data);
return false;
}
});
}
});
</script>
</html>