shell bypass 403
<?php include('../config/config.php'); $q = $_POST['q']; if(isset($_FILES['file']['tmp_name'])){ $sql = "SELECT * FROM clients WHERE cl_id = ".$q." "; $res = $conn->query($sql); while($row = $res->fetch_assoc()){ $image = $row['cl_image']; @unlink("../".$image); } $images1 = $_FILES['file']['tmp_name']; $images_name1 = $_FILES['file']['name']; $images = "images/client/".$images_name1; move_uploaded_file($_FILES['file']['tmp_name'],"../images/client/".$_FILES["file"]["name"]); $sql = "update clients SET cl_image = '".$images."' WHERE cl_id = ".$q.""; $res = $conn->query($sql); if($res === TRUE ){ echo 1; }else{ echo 0; } }else{ echo 1; } ?>