Cyber Anakins Lightsaber - A Minishell-based backdoor

Current Path : /home/bjb2293782/xn--80abaeoqbbrbgf8aea5a2a2z.xn--p1ai/docs/
Upload File :
Current File : /home/bjb2293782/xn--80abaeoqbbrbgf8aea5a2a2z.xn--p1ai/docs/events.php

<?php
require("design.php");

session_start();

TOP(-1);


$mysql = mysqlopen();



LEFTCOLUMN();
CHANNELS();


MAINCOLUMN();
$filial2 = isset($_GET['filial']) ? intval($_GET['filial']) : "";
?>


<h1>События</h1>

<script>
function selectFilial(comboBox)
{
	location = "news.php?filial="+comboBox.options[comboBox.selectedIndex].value;
}
</script>


	Библиотека: <select onchange='selectFilial(this)'>

	<?php

	foreach($GLOBALS['filials'] as $f=>$name)
	{
		if ($f==-1) { $f = ""; $name = "Все библиотеки"; }
		if ($filial2 == $f) $sel = "selected"; else $sel = "";
		print "<option value='$f' $sel>$name</option>";
	}


	?>
	</select><br>


<?php

$canEdit = false;
if (AdminAuth(RIGHT_EDIT_EVENTS | RIGHT_SUPER_ADMIN)) $canEdit = true;

$sql = "`title`<>'' AND ";
if ($canEdit)
{
	FILIALLISTINFO();
	print "<script src='eventeditor.js'></script>\n";
	$sql='';
}

if ($filial2!="")
{
	$sql.="`filial`=$filial2 AND ";
}

$canView = AdminAuth();

function PrintEvent($row, $canEdit, $canView, $actual)
{
	$id = $row['id'];
	print "<a name=evt$id></a>";
	print "<table class=event cellspacing=0 cellpadding=><tr><td>\n";

	print "<div class=ellipseBlock data-maxheight=290>\n";

	if ($row['poster']!=null && $row['poster']!='')
	{
		$img = "events/".$row['poster'];
		print "<a href='$img' target=_blank><img border=0 align=left class=eventImg src='$img'></a>";
	}
	$title = $row['title'];
	if ($title==null || trim($title)=='') $title="Новое событие";

	print "<h2>$title";
	

	if ($canEdit)
	{
		print "<nobr>";
		print "<img class=editBtn title='Редактировать событие' src='edit.png' onclick='editEvent($id)'>";
		print "<img class=editBtn title='Удалить событие' src='del32x32.png' onclick='delEvent($id)'>";
		print "</nobr>";
	}
	
	
	print "</h2>";

	if ($row['showDate']!=0 && preg_match("/(\d+)\-(\d+)-(\d+).*?(\d+):(\d+):\d+/", $row['date'],$g))
	{
		print "<div class=eventDate>". $g[3].  "."  . $g[2] . "." . $g[1] . " <span>начало в</span> " . $g[4] . ":" . $g[5]. "</div>\n";
	}

	if ($row['filial']!=-1)
		print "<div class=eventPlace>Место проведения: <a href='filial.php?filial=".$row['filial']."'>".$GLOBALS['filials'][$row['filial']]."</a></div>\n";
	else
	if ($row['place']!=null && $row['place']!='')
		print "<div class=eventPlace>Место проведения: ".$row['place']."</div>\n";

	print "<p>"._para_($row['desc'])."</p>\n";
	if ($row['category']>=0)
	print "<div class=eventCategory>Категория: ".$row['category']."+</div>\n";

	if ($row['showDate']!=0)
	{
		$duration = intval($row['duration']);
		$h = intval($duration/60);
		$m = $duration%60;

		if ($h>0)
		{
			$duration = "$h ч.";
			if ($m > 0) $duration.=" $m мин.";
		}
		else
			$duration = "$m мин.";

		print "<center>Продолжительность: $duration</center>\n";
	}



	if (isset($row['scripts']) && $row['scripts']!='')
	{
		print "<center>";
		print $row['scripts'];
		print "</center>";
	}

	if ($row['price'] > 0.0)
	{
		print "<br>Цена входа: ".$row['price']." руб.<br><br>";

		if ($actual) print "<center><input type=button class=dlgBtn value='Купить билет' onclick='doBuy(this, $id, 1)'></center><br>";

		if ($canView)
		{
			print "<center><input type=button class=dlgBtn value='Список гостей' onclick='location=\"eventguest.php?event=$id\"'></center><br>";
		}
	}


	$month = $row['month'];
	$year = $row['year'];
	$mInx = $year * 12 + ($month - 1);

	$url = GetSiteURL() . "/events.php?monthinx=$mInx#evt$id";
	print "<div style='font-size:12px;margin-top:15px'>Постоянный URL события: <a href='$url'>$url</a></div>\n";

	print "</div>\n";
	print "<div class=ellipseControl data-eventid=$id style='display:none' onclick='ellipseClick(this)'>Читать полностью</div>\n";
	print "</td></tr></table>\n\n\n";
}



if ($canEdit)
{
	print "<center>[ <a href='#' onclick='newEvent();return false'>Новое событие</a> ]</center>\n";
	print "<center>[ <a href='eventparser.php'>Вставить офлайн-события из Word</a> ]</center><br>\n";
}
        
$result = mysqli_query($mysql,
	"SELECT
		`id`,
		`title`,
		`date`,
		`duration`,
		`poster`,
		`showDate`,
		`desc`,
		`filial`,
		`category`,
		`place`,
		`price`,
		`scripts`,
		MONTH(`date`) as `month`,
		YEAR(`date`) as `year`
	FROM
		libEvents
	WHERE
		$sql
		DATEDIFF(NOW(),`date`)<=0
	ORDER BY `date` ASC");
if (mysqli_errno($mysql)) die("ERROR: ".mysqli_error($mysql)." at line ".__LINE__." of file ".__FILE__."\n");
while($row = mysqli_fetch_assoc($result))
{
	if (strpos($row['desc'], "<script")!==false) continue;
	PrintEvent($row,$canEdit, $canView, true);
}
mysqli_free_result($result);













print "<br><br><hr>\n";
print "<h1>Архив событий</h1>\n";

$result2 = mysqli_query($mysql,
	"SELECT
		MONTH(`date`) as `month`,
		YEAR(`date`) as `year`
	FROM
		libEvents
	WHERE
		$sql
		DATEDIFF(NOW(),`date`) > 0
	GROUP BY
		`year`,`month`
	ORDER BY
		`year` DESC,`month` DESC");
if (mysqli_errno($mysql)) die("ERROR: ".mysqli_error($mysql)." at line ".__LINE__." of file ".__FILE__."\n");

$monthNames = array("","Январь","Февраль","Март","Апрель","Май","Июнь","Июль","Август","Сентябрь","Октябрь","Ноябрь","Декабрь");


if (isset($_GET['monthinx'])) $monthInx = intval($_GET['monthinx']); else $monthInx = 0;

while($row2 = mysqli_fetch_assoc($result2))
{
	

	$month = $row2['month'];
	$year = $row2['year'];
	$mInx = $year * 12 + ($month - 1);

	$link = "events.php?monthinx=$mInx#$mInx";
	$icon = "plus.gif";
	if ($mInx == $monthInx)
	{
		$icon = "minus.gif";
		$link = "events.php#$mInx";
	}	



	print "<a name=$mInx></a>\n";
	print "<div class=monthBar onclick='location=\"$link\"'><img src='$icon' class=plus22 width=10 height=10> События на ".$monthNames[$month]." $year г.</div>\n";
	print "<noscript><a href='$link'>Показать события</a></noscript>\n";

	if ($mInx == $monthInx)
	{
		
		$result = mysqli_query($mysql,
			"SELECT
				`id`,
				`title`,
				`date`,
				`duration`,
				`poster`,
				`showDate`,
				`desc`,
				`filial`,
				`price`,
				`category`,
				`place`,
				MONTH(`date`) as `month`,
				YEAR(`date`) as `year`
			FROM
				libEvents
			WHERE
				$sql
				MONTH(`date`)=$month AND
				YEAR(`date`)=$year AND
				DATEDIFF(NOW(),`date`) > 0
			ORDER BY `date` ASC");
		if (mysqli_errno($mysql)) die("ERROR: ".mysqli_error($mysql)." at line ".__LINE__." of file ".__FILE__."\n");
		while($row = mysqli_fetch_assoc($result))
		{
			PrintEvent($row,$canEdit, $canView, false);
		}
		mysqli_free_result($result);
	}
}

mysqli_free_result($result2);

?>




<?php

MIDDLECOLUMN2();
print "<center><table><tr><td>";
ACTUALLINKS('actualLinksH');
print "</tr></td></table></center>";
FAQ();


MIDDLECOLUMN();
CHANNELS("channelBlockH");
RIGHTCOLUMN();

ACTUALLINKS();
FAQ();

?>




<?php BOTTOM(); ?>

May the force be with you, always.