shell bypass 403
<div class="col-md-6">
<?php
$q = $_POST['q'];
include('../config/config.php');
$sql = "SELECT * FROM directors WHERE d_id = ".$q." ";
$res = $conn->query($sql);
$n = 0;
while($row = $res->fetch_assoc()){
?>
<form id="edit_direc" method="post" enctype="multipart/form-data">
<div id="error_edit_direc"></div>
<div class="row">
<div class="col-md-12">
<div class="form-group">
<label>Director Name</label>
<input type="text" class="form-control" id="direc_name" name="direc_name" placeholder="Director Name" value="<?php echo $row['d_name']; ?>">
<input type="hidden" class="form-control" id="direc_id" name="direc_id" value="<?php echo $row['d_id']; ?>">
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div class="form-group">
<label>Director Position</label>
<input type="text" class="form-control" id="direc_posi" name="direc_posi" placeholder="Director Position" value="<?php echo $row['d_postion']; ?>">
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div class="form-group">
<label>Director Images</label>
<input type="file" class="form-control" id="direc_image" name="direc_image">
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div class="form-group">
<button class="btn btn-primary update_direc" type="submit">Update</button>
</div>
</div>
</div>
</form>
</div>
<div class="col-md-6">
<img src="<?php echo "../".$row['d_image']; ?>" class="img-responsive" />
</div>
<?php
}
?>
<script>
$('#update_direc').validate({
rules: {
direc_name: {
required: true,
},
direc_posi: {
required: true,
},
direc_image: {
required: true,
},
},
messages: {
direc_name: {
required: "<p style='color:red'>Please Insert Director Name</p>",
},
direc_posi: {
required: "<p style='color:red'>Please Insert Director Position</p>",
},
direc_image: {
required: "<p style='color:red'>Please Insert Director Image</p>",
},
},
submitHandler: function(form) {
var direc_name = $('#direc_name').val();
var direc_posi = $('#direc_posi').val();
var direc_image = $('#direc_image').prop('files')[0];
var form_data = new FormData();
form_data.append('file', direc_image);
form_data.append('direc_posi', direc_posi);
form_data.append('direc_name', direc_name);
$.ajax({
url: "add_direc.php",
dataType: 'text',
cache: false,
contentType: false,
processData: false,
data: form_data,
type: 'post',
}).done(function(data){
console.log(data);
if(data == 1){
$("#table_director").load('table_director.php');
$('#add_direc')[0].reset();
}else{
console.log(data);
return false;
}
});
}
});
</script>