KGRKJGETMRETU895U-589TY5MIGM5JGB5SDFESFREWTGR54TY
Server : Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 PHP/5.2.17
System : Linux localhost 2.6.18-419.el5 #1 SMP Fri Feb 24 22:47:42 UTC 2017 x86_64
User : nobody ( 99)
PHP Version : 5.2.17
Disable Function : NONE
Directory :  /home/queenjbs/www/gallary/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : /home/queenjbs/www/gallary/write_proc.php
<?
$todayfull = date("YmdHis");
$contents = addslashes($contents); //특수문자db에 들어가게..

if ($addfile_name) {
	$savedir 	= "../files/board";
	$addfile_ext = strtolower(substr($addfile_name,-3)); // 확장자
	if($addfile_ext=="jpg" or $addfile_ext=="gif" or $addfile_ext=="png" or $addfile_ext=="bmp") { //소문자.. 대문자.. 구분가능.. 
		$vName = $tableName."_".$todayfull.".".$addfile_ext; //화명명 변경 예)20061212_6437210.jpg
		$realName = $addfile_name;
		$file_count = 1;
		if(!copy($addfile, "$savedir/$vName")) {
			echo("fail");
			exit;
		}
		unlink($addfile);
		
		include "./makesontop.php";
		
	}else{
?>
		<SCRIPT LANGUAGE="JavaScript">
		<!--
			alert("添付ファイルはイメージファイル(jpg,gif,bmp,png)のみアップロード可能です");
			document.history.back(-1);
		//-->
		</SCRIPT>
<? 
	exit;
	}
}
if($idx){
	if($mode == "proc"){
		$queryupok = "update photo_$tableName set subject='$subject',contents='$contents',modify_date=now() where no = '$idx'";
		$boardNo = get_db("select no from photo_$tableName where no = '$idx'");
		if($vName){
			
			//기존 파일 삭제
			$fileName = Get_db("select file_name from files where module_name='$tableName' and module_no = '$idx'");
				$del_file="../files/board/".$fileName;
				if($fileName && is_file($del_file)) unlink($del_file);
				$sontop_file="../files/board/sontop/".$fileName;
				if($fileName && is_file($sontop_file)) unlink($sontop_file);
				$resize_file="../files/board/resize/".$fileName;
				if($fileName && is_file($resize_file)) unlink($resize_file);
			if($fileName){
			$file_query = "update files set original_name='$realName',file_name='$vName',file_type='$addfile_ext',reg_date=now() where module_name='$tableName' and module_no = '$idx'";
			}else{
				$orderBy = mktime( 0, 0, 0, date("m"), date("d"), date("Y"));
				$file_query = "INSERT INTO files
										(module_no,module_name,original_name,file_name,file_type,order_by,reg_date)
									VALUES
										('$boardNo','$tableName', '$realName','$vName','$addfile_ext','$orderBy',now())";
			}
			
			//echo $file_query;
			$result = mysql_query($file_query,$db_con);
		}else if($delfile){
			$fileName = Get_db("select file_name from files where module_name='$tableName' and module_no = '$idx'");

			if($fileName){
				// 파일 삭제
				$del_file="../files/board/".$fileName;
				if($fileName && is_file($del_file)) unlink($del_file);
				$sontop_file="../files/board/sontop/".$fileName;
				if($fileName && is_file($sontop_file)) unlink($sontop_file);
				$resize_file="../files/board/resize/".$fileName;
				if($fileName && is_file($resize_file)) unlink($resize_file);

				$delqry =  mysql_query("DELETE FROM files where module_name='$tableName' and module_no = '$idx'",$db_con);
				$filesCnt =  mysql_query("update board_$tableName set files_count='0',modify_date=now() where no = '$idx'",$db_con);
			}
		}
	}else if($mode == "del"){
		$fileName = Get_db("select file_name from files where module_name='$tableName' and module_no = '$idx'");

		if($fileName){
			// 파일 삭제
			$del_file="../files/board/".$fileName;
			if($fileName && is_file($del_file)) unlink($del_file);
			$sontop_file="../files/board/sontop/".$fileName;
			if($fileName && is_file($sontop_file)) unlink($sontop_file);
			$resize_file="../files/board/resize/".$fileName;
			if($fileName && is_file($resize_file)) unlink($resize_file);
			$delqry =  mysql_query("DELETE FROM files where module_name='$tableName' and module_no = '$idx'",$db_con);
		}
		
		 $queryupok = "DELETE FROM photo_$tableName where no = '$idx'";
	}
	
	$queryupok_result = mysql_query($queryupok,$db_con);	
	$boardNo= $idx;
}else{
	$query = "INSERT INTO photo_$tableName
									(module_no,user_no,user_id,user_name,reg_date,modify_date,subject,contents,files_count,hit,ip)
								VALUES
									('$tableName', '$HTTP_SESSION_VARS[S_IDX]','$HTTP_SESSION_VARS[S_ID]','$HTTP_SESSION_VARS[S_NAME]',now(),now(),'$subject','$contents','$file_count','0','$REMOTE_ADDR')";
	
	//echo $query;
	$result = mysql_query($query,$db_con);

	if($vName){
		$boardNo = get_db("select max(no) from photo_$tableName");
		$orderBy = mktime( 0, 0, 0, date("m"), date("d"), date("Y"));
		$file_query = "INSERT INTO files
										(module_no,module_name,original_name,file_name,file_type,order_by,reg_date)
									VALUES
										('$boardNo','$tableName', '$realName','$vName','$addfile_ext','$orderBy',now())";

		//echo $file_query;
		$result = mysql_query($file_query,$db_con);
	}
	
}
if($mode == "del"){
	$modePath = "list";
	//$alertName = "削除";
}else{
	$modePath = "view";
	//$alertName = "保存";
}
mysql_close();
?>
<script>
//alert("<?=$alertName?> しました。");
formChange('<?=$boardNo?>','<?=$modePath?>');

</script>

Anon7 - 2021