shell bypass 403
<?xml version="1.0" encoding="utf-8"?> <form> <fieldset addfieldpath="/administrator/components/com_phocagallery/models/fields"> <field name="id" type="text" default="0" label="JGLOBAL_FIELD_ID_LABEL" required="true" readonly="true" class="readonly" /> <field name="title" type="text" class="form-control" size="40" label="COM_PHOCAGALLERY_FIELD_TITLE_LABEL" description="COM_PHOCAGALLERY_FIELD_TITLE_DESC" required="true" /> <field name="usertitle" type="phocainfotext" class="form-control" size="40" label="COM_PHOCAGALLERY_FIELD_USER_LABEL" description="COM_PHOCAGALLERY_FIELD_USER_DESC" /> <field name="alias" type="text" class="form-control" size="40" label="COM_PHOCAGALLERY_FIELD_ALIAS_LABEL" description="COM_PHOCAGALLERY_FIELD_ALIAS_DESC" /> <field name="cattitle" type="phocainfotext" label="COM_PHOCAGALLERY_FIELD_CATEGORY_LABEL" description="COM_PHOCAGALLERY_FIELD_CATEGORY_DESC" class="form-control" /> <field name="imagetitle" type="phocainfotext" label="COM_PHOCAGALLERY_FIELD_IMAGE_LABEL" description="COM_PHOCAGALLERY_FIELD_IMAGE_DESC" class="form-control" readonly="1" /> <field name="ordering" type="PhocaGalleryOrdering" table="commentimage" class="form-select" label="COM_PHOCAGALLERY_FIELD_ORDERING_LABEL" description="COM_PHOCAGALLERY_FIELD_ORDERING_DESC" /> <field name="imgid" type="hidden" filter="unset" /> <field name="comment" type="editor" buttons="true" hide="pagebreak,readmore" class="form-control" label="COM_PHOCAGALLERY_FIELD_COMMENT_LABEL" description="COM_PHOCAGALLERY_FIELD_COMMENT_DESC" filter="\Joomla\CMS\Component\ComponentHelper::filterText" /> </fieldset> <fieldset name="publish" label="COM_PHOCAGALLERY_GROUP_LABEL_PUBLISHING_DETAILS" > <field name="published" type="list" label="COM_PHOCAGALLERY_FIELD_PUBLISHED_LABEL" description="COM_PHOCAGALLERY_FIELD_PUBLISHED_DESC" class="form-select" size="1" default="1"> <option value="1">JPUBLISHED</option> <option value="0">JUNPUBLISHED</option> </field> <field name="date" type="Calendar" class="form-control" label="COM_PHOCAGALLERY_FIELD_DATE_LABEL" description="COM_PHOCAGALLERY_FIELD_DATE_DESC" filter="user_utc" translateformat="true" /> </fieldset> </form>