shell bypass 403

Cubjrnet7 Shell


name : update-order-details.php
<?php 
include('login-status.php');
include("global.inc.php");
include("connection.inc.php");
global $db;

$target = isset($_GET['t'])?trim($_GET['t']):'';
$order_id = isset($_GET['o'])?trim($_GET['o']):'';
$element_value = isset($_GET['s'])?trim($_GET['s']):'';
$tableRow = isset($_GET['r'])?trim($_GET['r']):'';

if(!$order_id || strlen($element_value)==0)die('Wrong parameters!');
if($element_value == ORDER_COMPLETE_CODE || $element_value == CANCEL_ORDER_CODE)
	$openClose = ORDER_CLOSE;
else	
	$openClose = ORDER_OPEN;
	
if($target == 's')
{
  $VarQuery = "UPDATE customer_order SET order_status = '".$element_value."', ".
      							" order_is_order_open = ".$openClose." ".
        			" WHERE order_id = '".$order_id."'";
  $VarResult = mysqli_query($db, $VarQuery) or die(mysqli_error());
  showStatus($status_arr, $status_arr[$element_value], $element_value, $order_id, $tableRow,'');
}else
{
  $VarQuery = "UPDATE customer_order SET order_paid_amount = '".$element_value."' ".
  						"WHERE order_id = '".$order_id."'";
  $VarResult = mysqli_query($db, $VarQuery) or die(mysqli_error());
  showAmountPaid($element_value, $order_id, $tableRow);
}
?>

© 2025 Cubjrnet7