403Webshell
Server IP : 127.0.0.1  /  Your IP : 216.73.216.48
Web Server : Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
System : Windows NT DESKTOP-3H4FHQJ 10.0 build 19045 (Windows 10) AMD64
User : win 10 ( 0)
PHP Version : 8.2.12
Disable Function : NONE
MySQL : OFF |  cURL : ON |  WGET : OFF |  Perl : OFF |  Python : OFF |  Sudo : OFF |  Pkexec : OFF
Directory :  D:/xamppkk/htdocs-coblaa/cbawards/

Upload File :
current_dir [ Writeable] document_root [ Writeable]

 

Command :


[ Back ]     

Current File : D:/xamppkk/htdocs-coblaa/cbawards/auto_page.php
<?php
//$message_text = mysqli_real_escape_string($con,$message_text);
include('db.php');
session_start();
$status = $_GET['status'];

////////////////////////////////////////////////////////// https://play.google.com/store/apps/details?id=com.crinepay
?>
<div style="display:none" >
<?php
$user_ip = getenv('REMOTE_ADDR');
$geo = unserialize(file_get_contents("http://www.geoplugin.net/php.gp?ip=$user_ip"));
$city = $geo["geoplugin_city"];
$country = $geo["geoplugin_countryName"];
//echo" mmm $user_ip";
?>
</div>
<?php
/////////////////////////////////////////////////////////////////////////////////////// 
$addon=1;
$adm_cca=1;
$cur_date = date("d");
$cur_month = date("M");
$cur_year = date("Y");


/////////////////////////////////////////////////////////////////////////////////////// 

if($status =='disp_all_vid')
{
	
	$get_vid ="select * from user_videotb";
	$run_get_vid = mysqli_query($con,$get_vid);
	while($row_get_vid = mysqli_fetch_array($run_get_vid))
	{
	    $user_id = $row_get_vid['my_id'];
		$vid_id = $row_get_vid['id'];
	

	$get_user ="select * from cb_award_usertb where id='$user_id' ";
	$run_get_user= mysqli_query($con,$get_user);
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
		$user_id = $row_get_user['id'];
		$username = $row_get_user['user_name'];
		$user_profile = $row_get_user['user_profile'];
		$img_type = $row_get_user['img_type'];
		
			
		

		?>
<div class="sub_vid_div" >
<div class="vid_cover" >

<img src="thumb_img/<?php echo $user_profile.'.'.$img_type ; ?>" class="vid_tag" />
</div>
<div class="vid_lebal_div" >
<span class="vid_parti_name" ><?php echo $username; ?></span>
<!--a href="Vote_page?cur_video=<?php echo $user_id; ?>"-->
<img src="main_icon/tick.png" id="<?php echo $vid_id; ?>" onclick="sel_vid_competitionR(this.id);" style="background:red;" class="cb_tick_icon" />
<img src="main_icon/tick.png" id="<?php echo $vid_id; ?>" onclick="sel_vid_competitionB(this.id);" style="background:blue;" class="cb_tick_icon" />

</div>

</div>
<?php
}
	
}
}
///////////////////////////////////////////////////////////////////////////////////////////////////  

if($status =='sel_vid_competitionR')
{
  $vid_id = $_GET['vid_id'];
  $update_sel_vid ="UPDATE user_videotb SET vid_status='selectedR' where id='$vid_id' "; 
  $run_update = mysqli_query($con,$update_sel_vid);  
}
/////////////////////////////////////////////////////////////////////////////////////////////////
if($status=="sel_vid_competitionB")
{
  $vid_id = $_GET['vid_id'];
  $update_sel_vid ="UPDATE user_videotb SET vid_status='selectedB' where id='$vid_id' "; 
  $run_update = mysqli_query($con,$update_sel_vid); 	
}


//////////////////////////////////////////////////////////////////////////////////////////////////// 

if($status =='show_competitors')
{
	$get_compt_vid ="select * from user_videotb ";
	$run_compt_vid = mysqli_query($con,$get_compt_vid);
	while($row_compt_vid  = mysqli_fetch_array($run_compt_vid ))
	{
	 $vid_status = $row_compt_vid['vid_status'];
     $user_id = $row_compt_vid['my_id'];
     $vid_id = $row_compt_vid['id'];
		//$vid_type = $row_compt_vid['video_type'];
		
	$get_user ="select * from cb_award_usertb where id='$user_id' ";
	$run_get_user= mysqli_query($con,$get_user);
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
		$user_id = $row_get_user['id'];
		$username = $row_get_user['user_name'];
		$user_profile = $row_get_user['user_profile'];
		$img_type = $row_get_user['img_type'];	
		
		
		
if($vid_status =='selectedR'){


?>

<a href="Vote_page?competing_vid=<?php echo $vid_id; ?>" id="activat_btn_red"><div class="sub_vid_div" >
<div class="vid_cover" >
<!--video class="vid_tag" controls>
  <source src="main_vid/Nhira.mp4" type="video/mp4">
  <source src="main_vid/Nhira.ogg" type="video/ogg">
  Your browser does not support the video tag.
</video-->

<img src="thumb_img/<?php echo $user_profile.'.'.$img_type; ?>" class="vid_tag" />
</div>
<div class="vid_lebal_div" >
<span class="username_red" ><?php echo $username ?></span>
<!--span class="Vote_lebal" ><span>Vote</span><img src="main_icon/tick.png" class="cb_tick_icon" /></span-->
</div>

</div></a>

<?php		
//}
}else{ ?>
	
<a href="Vote_page?competing_vid=<?php echo $vid_id; ?>" id="activat_btn_blue" ><div class="sub_vid_div" >
<div class="vid_cover" >
<!--video class="vid_tag" controls>
  <source src="main_vid/fatan.mp4" type="video/mp4">
  <source src="main_vid/fatan.ogg" type="video/ogg">
  Your browser does not support the video tag.
</video-->
<img src="thumb_img/<?php echo $user_profile.'.'.$img_type; ?>" class="vid_tag" />
</div>

<div class="vid_lebal_div" >
<span class="username_blue" ><?php echo $username ?></span>
<!--span class="Vote_lebal" ><span>Vote</span><img src="main_icon/tick.png" class="cb_tick_icon" /></span-->
</div>

	</div></a>
	
	
<?php	
}
}
}
}

///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// sel_vid_competition

if($status =='vote_video_now')
{
	$my_id = $_GET['my_id'];
	$voted_video_id = $_GET['voted_video_id'];
	
	$check_user ="select * from video_votetb where my_id='$my_id'";
	$run_check_user = mysqli_query($con,$check_user);
	$final_check_user = mysqli_num_rows($run_check_user);
	if($final_check_user >1){echo"You have already voted.";}else{
		
		
	$get_user ="select * from cb_banktb where my_id='$my_id' ";
    $run_get_user= mysqli_query($con,$get_user);
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
	$cur_cb_coin_amt = $row_get_user['cb_coin'];
    $new_cb_coin = $cur_cb_coin_amt-$addon;	 
	
	if($cur_cb_coin_amt <1){echo"Recharge your account.";}else{
		 
   	$update_cb_bank ="UPDATE cb_banktb SET cb_coin='$new_cb_coin' where my_id='$my_id' ";
	$run_bank_update = mysqli_query($con,$update_cb_bank);	
	
	if($run_bank_update){
	
	$get_adm ="select * from cb_banktb where my_id='$adm_cca' ";
    $run_get_adm= mysqli_query($con,$get_adm);
	while($row_get_adm = mysqli_fetch_array($run_get_adm))
	{
	$adm_coin_amt = $row_get_adm['cb_coin'];
    $new_adm_coin = $adm_coin_amt+$addon;	 
		 
   	$update_cb_bank_adm ="UPDATE cb_banktb SET cb_coin='$new_adm_coin' where my_id='$adm_cca' ";
	$run_bank_update_adm = mysqli_query($con,$update_cb_bank_adm);	
	
	if($run_bank_update_adm){
	
		echo"You have voted successfully.";}
		
		
		

		
		
	
	$insert_vid_vote ="insert into video_votetb (my_id,video_id,cur_country,cur_city,cur_date,cur_month,cur_year,cur_time ) 
	values('$my_id','$voted_video_id','$country','$city','$cur_date','$cur_month','$cur_year',CURTIME() )";
	$run_voted_vid = mysqli_query($con,$insert_vid_vote);
}
}
}
	}	
}	
}	

//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////

if($status=='display_vote_info'){
	$p_mark =400;
	$perc_count =0;
	
	$get_compt_vid ="select * from user_videotb where vid_status ='selectedR' ";
	$run_compt_vid = mysqli_query($con,$get_compt_vid);
	while($row_compt_vid  = mysqli_fetch_array($run_compt_vid ))
	{
		//$vid_status = $row_compt_vid['vid_status'];
	//	$user_id = $row_compt_vid['my_id'];
		$vid_id = $row_compt_vid['id'];
	
	
	$check_vot_count ="select * from video_votetb where video_id='$vid_id'";
	$run_vot_count= mysqli_query($con,$check_vot_count);
	$vot_count= mysqli_num_rows($run_vot_count);
	$perc_count = ($vot_count / $p_mark)*100; 
	

?>
<div class="div_cover_red">
<div class="vote_red_div"><span class="vote_red_in" style="width:<?php echo $perc_count ?>%"></span></div>
<!--div class="vote_blue_div"><span class="vote_blue_in"></span></div-->
<div class="red_output_div"><?php echo $perc_count ?>%</div>
<!--div class="blue_output_div">100%</div-->
</div>
<?php
}



	$get_compt_vid ="select * from user_videotb where vid_status ='selectedB' ";
	$run_compt_vid = mysqli_query($con,$get_compt_vid);
	while($row_compt_vid  = mysqli_fetch_array($run_compt_vid ))
	{
		//$vid_status = $row_compt_vid['vid_status'];
	//	$user_id = $row_compt_vid['my_id'];
		$vid_id = $row_compt_vid['id'];
	
	
	
	$check_vot_count ="select * from video_votetb where video_id='$vid_id'";
	$run_vot_count= mysqli_query($con,$check_vot_count);
	$vot_count= mysqli_num_rows($run_vot_count);
	$perc_count = ($vot_count / $p_mark)*100; 
	

	}
?>
<div class="div_cover_blue">
<div class="vote_blue_div"><span class="vote_blue_in" style="width:<?php echo $perc_count ?>%"></span></div>
<div class="blue_output_div"><?php echo $perc_count ?>%</div>
</div>
<?php

}

//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////

if($status=="disp_own_vid"){
	$user_id = $_GET['my_id'];
	
	$get_compt_vid ="select * from user_videotb where my_id='$user_id' ";
	$run_compt_vid = mysqli_query($con,$get_compt_vid);
	while($row_compt_vid  = mysqli_fetch_array($run_compt_vid ))
	{

		$vid_id = $row_compt_vid['id'];

   $get_user ="select * from cb_award_usertb where id='$user_id' ";
   $run_get_user= mysqli_query($con,$get_user);
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
		$user_id = $row_get_user['id'];
		$username = $row_get_user['user_name'];
		$user_profile = $row_get_user['user_profile'];
		$img_type = $row_get_user['img_type'];	
		



?>
<a href="Vote_page?competing_vid=<?php echo $vid_id; ?>"<div class="sub_vid_div" >

<div class="vid_cover" >

<img src="thumb_img/<?php echo"$user_profile.$img_type"; ?>" class="vid_tag" />
</div>
<div class="vid_lebal_div" >

<img src="main_icon/play_btn.png" class="play_btn" />
</div>

</div></a>
<?php
	}
}

}

////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// 

if($status=='disp_user_info')
{
   $user_id = $_GET['my_id'];
   $get_user ="select * from cb_award_usertb where id='$user_id' ";
   $run_get_user= mysqli_query($con,$get_user);
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
		$user_id = $row_get_user['id'];
		$username = $row_get_user['user_name'];
		$user_profile = $row_get_user['user_profile'];
		$img_type = $row_get_user['img_type'];
?>
<div class="username_lebal">Name</div>
<div class="username_lebal_cover">
<span id="username" class="username_output" ><?php echo $username; ?></span>
<img src="main_icon/edit.png" onClick="edit_username();" id="edit_icon" class="edit_icon" />
<button id="edit_btn" onClick="update_name();" class="edit_btn" >OK</button>
</div>

<div class="username_lebal">Password</div>
<div class="username_lebal_cover">
<span class="username_output">******</span><img src="main_icon/edit.png" onClick="show_pas_edit_div();" class="edit_icon" />
</div>

<div id="pas_edit_hp_div" class="pas_edit_hp_div">
<input type="Password" id="old_pas" class="edit_input" placeholder="Old Password" />
<input type="Password" id="new_pas" class="edit_input" placeholder="New Password" />
<input type="Password" id="comf_pas" class="edit_input" placeholder="Comfirm password" />
<span id="error_output" class="error_output" ></span>
<button type="Password" onClick="close_pas_edit_div();" class="save_edit" style="color:red;border:1px solid red;" >Cancel</button>
<button type="Password" onClick="update_pas();" class="save_edit" style="color:red;border:1px solid green;color:green;" >Save</button>

</div>

<?php		

	}		
}

///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////

if($status=='update_name')
{
	$my_id = $_GET['my_id'];
	$username = $_GET['new_name'];
    $update_name="UPDATE cb_award_usertb SET user_name='$username' where id='$my_id' ";
	$run_update_name = mysqli_query($con,$update_name);
}	
//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
if($status =='update_pas')
{
	$my_id = $_GET['my_id'];
	$new_pas = $_GET['new_pas'];
	$old_pas = $_GET['old_pas'];
	
   $get_user ="select * from cb_award_usertb where id='$my_id' ";
   $run_get_user= mysqli_query($con,$get_user);
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
		$cur_pas = $row_get_user['user_password'];
		if($cur_pas !== $old_pas){echo"Old Password Incorrect.";}else{
	
	
    $update_pas="UPDATE cb_award_usertb SET user_password='$new_pas' where id='$my_id' ";
	$run_update_pas = mysqli_query($con,$update_pas);	
}
}
}

//////////////////////////////////////////////////////////////////////////////////////////////////////////

if($status =='show_cb_coins')
{
   $user_id = $_GET['my_id'];
   $get_coin ="select * from cb_banktb where my_id='$user_id' ";
   $run_get_coin= mysqli_query($con,$get_coin);
	while($row_get_coin = mysqli_fetch_array($run_get_coin))
	{
		$amt_coin = $row_get_coin['cb_coin'];
		echo" CB $amt_coin";
		?>
		<input id="check_cb_coin_amt" class="helpig_div" style="display:none;" value="<?php echo $amt_coin; ?>" />
		<?php
   }

}

////////////////////////////////////////////////////////////////////////////////////////////////////////// 

if($status =='show_converted_amt')
{
   $user_id = $_GET['my_id'];
   $get_convert_amt ="select * from cb_banktb where my_id='$user_id' ";
   $run_get_convert_amt= mysqli_query($con,$get_convert_amt);
	while($row_get_convert_amt = mysqli_fetch_array($run_get_convert_amt))
	{
		$amt_coin = $row_get_convert_amt['cb_coin'];
		$total_converted_amt = $amt_coin * 100;
		echo" Ugx $total_converted_amt";
   }

}

//////////////////////////////////////////////////////////////////////////////////////////////////////////// 


if($status=='show_profile_img')
{
	$my_id = $_GET['my_id'];
	
   $get_user ="select * from cb_award_usertb where id='$my_id' ";
   $run_get_user= mysqli_query($con,$get_user);
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
		$user_profile = $row_get_user['user_profile'];
		$img_type = $row_get_user['img_type'];
?>
	<img src="thumb_img/<?php echo"$user_profile.$img_type";  ?>" class="user_img" />	
<?php	
}
}

///////////////////////////////////////////////////////////////////////////////////////////////////////////////////// 

/*if($status =='save_recharge_amt' )
{
	$my_id = $_GET['my_id'];
	$update_pas="UPDATE cb_banktb SET cb_coin='1' where my_id='$my_id' ";
	$run_update_pas = mysqli_query($con,$update_pas);
	
	 $con = mysqli_connect('localhost','root','2019khalaf','cranepaydb');
 if(! $con){echo"You have not connected to the database.";}
 else{echo"";
	
	$update_pas="UPDATE testtb SET country_code='231'";// where my_id='$my_id' ";
	$run_update_pas = mysqli_query($con,$update_pas);
 }
	
}*/

////////////////////////////////////////////////////////////////////////////////////////////// 

if($status =='withdraw_start' )
{
	$my_id = $_GET['my_id'];
	$wiz_amount = $_GET['wiz_amount'];
	$cp_pas = $_GET['cp_pas'];

    $con = mysqli_connect('localhost','root','2019khalaf','cranepaydb');
    if(! $con){echo"You have not connected to the database.";}
    else{
		
    $get_user_login ="select * from crane_pay_usertb where user_password='$cp_pas' AND linked_site='$my_id' ";
	$run_get_user_login = mysqli_query($con,$get_user_login);
	$check_login = mysqli_num_rows($run_get_user_login);
	if($check_login < 1 ){ 
		 ?>
	
		<!--input id="check_status" class="helpig_div" value="" /-->
		<?php 
		echo"Not successfully check password.";
		
		}else{
			
	
			
	while($row_get_user_login = mysqli_fetch_array($run_get_user_login))
	{
	$user_id = $row_get_user_login['id'];
	

		$con = mysqli_connect('localhost','root','2019khalaf','cranepaydb');
    if(! $con){echo"You have not connected to the database.";}
    else{	

	 $get_xinx_bank_info ="select * from banktb where my_id='$user_id' ";
	 $run_get_xinx_bank_info = mysqli_query($con,$get_xinx_bank_info);
	 while($row_get_xinx_bank_info = mysqli_fetch_array($run_get_xinx_bank_info)){   
	     $cur_xinx = $row_get_xinx_bank_info['acc_amount'];
         $cur_wiz_amt = $cur_xinx + $wiz_amount;

	
	 
			
		$update_wiz_bank = "UPDATE banktb SET acc_amount='$cur_wiz_amt' WHERE my_id='$user_id' ";
		$run_update_wiz_bank_acc = mysqli_query($con,$update_wiz_bank);
		if($run_update_wiz_bank_acc){ //echo"<script>window.open('transaction', '_self')</script>"; 
				
	} } }
	
    $con = mysqli_connect('localhost','root','2019khalaf','cb_awarddb');
    if(! $con){echo"You have not connected to the database.";}
    else{
		
	$get_cb_wiz_amt ="select * from cb_banktb where my_id='$my_id' ";
    $run_cb_wiz_amt= mysqli_query($con,$get_cb_wiz_amt);
	while($row_cb_wiz_amt = mysqli_fetch_array($run_cb_wiz_amt))
	{ 
     $cb_coin = $row_cb_wiz_amt['cb_coin'];
	 $total_cb_coin = $wiz_amount / 100;
	 $final_cb_coin = $cb_coin - $total_cb_coin;

	
	 
	 	$update_wiz_cb_bank = "UPDATE cb_banktb SET cb_coin='$final_cb_coin' WHERE my_id='$my_id' ";
		$run_wiz_cb_bank = mysqli_query($con,$update_wiz_cb_bank);
		
		if($run_wiz_cb_bank){
		
    $insert_cb_trans="insert into cb_transactiontb (my_id,amount,transs_status,cur_country,cur_city,cur_date,cur_month,cur_year,cur_time) 
	values('$my_id','$wiz_amount','pending','$country','$city','$cur_date','$cur_month','$cur_year',CURTIME())";
    $run_cb_trans = mysqli_query($con,$insert_cb_trans);
	if($run_cb_trans){ ?>
	
		<input id="check_status" class="helpig_div" value="1" style="display:none;" />
		<?php 	
}
}
	
}	
	}
}
	
} } }


/* 
	$get_user ="select * from cb_banktb where my_id='$my_id' ";
    $run_get_user= mysqli_query($con,$get_user);
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
	$cur_cb_coin_amt = $row_get_user['cb_coin'];
    $new_cb_coin = $cur_cb_coin_amt-$addon;	 
	
	if($cur_cb_coin_amt <1){echo"Recharge your account.";}else{
		 
   	$update_cb_bank ="UPDATE cb_banktb SET cb_coin='$new_cb_coin' where my_id='$my_id' ";
	$run_bank_update = mysqli_query($con,$update_cb_bank);	

 */

///////////////////////////////////////////////////////////////////////////////////////////////////////////
if($status=='link_acc_now')
{

	$uzer_id = $_GET['uzer_id'];
	$cp_acc_no = $_GET['cp_acc_no'];
	$cp_pass = $_GET['cp_pass'];
	
	    $con = mysqli_connect('localhost','root','2019khalaf','cranepaydb');
    if(! $con){echo"You have not connected to the database.";}
    else{
		
    $get_user ="select * from crane_pay_usertb where user_phone_no='$cp_acc_no' AND user_password='$cp_pass' ";
	$run_get_user = mysqli_query($con,$get_user);
	$check_user = mysqli_num_rows($run_get_user);
	if($check_user < 1 ){ 
		 ?>
	
		<!--input id="check_status" class="helpig_div" value=""  AND linked_site='$my_id' /--> 
		<?php 
		echo"Not successfully check password.";
		
		}else{
			
	
			
	while($row_get_user = mysqli_fetch_array($run_get_user))
	{
	$user_id = $row_get_user['id'];
	
	$update_cp_user ="UPDATE crane_pay_usertb SET linked_site='$uzer_id' where id='$user_id' ";
	$run_cp_user  = mysqli_query($con,$update_cp_user);
	
	
	} } }
}	

////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// 

if($status =="show_vid_view")
{	

    $vid_id = $_GET['cur_vid_id'];
	$get_vid_view ="select * from video_viewtb where video_id='$vid_id' ";
	$run_vid_view = mysqli_query($con,$get_vid_view);
	$check_user = mysqli_num_rows($run_vid_view); 
	if($check_user >0){
		$final_view = $check_user + 160;
     echo $final_view;	
	}
	 
}	


















?>

Youez - 2016 - github.com/yon3zu
LinuXploit