shell bypass 403

GrazzMean Shell

Uname: Linux webm016.cluster127.gra.hosting.ovh.net 5.15.167-ovh-vps-grsec-zfs-classid #1 SMP Tue Sep 17 08:14:20 UTC 2024 x86_64
Software: Apache
PHP version: 7.4.33 [ PHP INFO ] PHP os: Linux
Server Ip: 54.36.31.145
Your Ip: 216.73.216.182
User: homesquasz (91404) | Group: users (100)
Safe Mode: OFF
Disable Function:
_dyuweyrj4,_dyuweyrj4r,dl

name : index.php
<div class="row">
    <div class="col-md-12">
        <div class="box">
            <div class="box-header">
                <h3 class="box-title">Liste des utilisateurs</h3>
            	<div class="box-tools">
                    <?php if(in_array($add, $access["User"]->actions)){ ?>
                    <a href="<?php echo site_url('user/add'); ?>" class="btn btn-success btn-sm">Ajouter</a> 
                    <?php } ?>
                    <?php if(in_array($export, $access["User"]->actions)){ ?>
                    <a href="<?php echo site_url('user/pdf'); ?>" class="btn btn-info btn-sm" target="_blank">Exporter</a> 
                    <?php } ?>
                </div>
            </div>
            <div class="box-body">
                <table class="table table-striped" id="datausers">
                    <thead>
                        <tr>
                        <th>Nom</th>
                        <th>Prenom</th>
                        <th>Tel</th>
                        <th>Email</th>
                        <th>Responsable</th>
                        <th>Interim</th>
                        <th>Matricule</th>
                        <th>Login</th>
                        <th>Type</th>
                        <th>Etat</th>
                        <th>Actions</th>
                    </tr>

                    </thead>
                    <tbody>
                    <?php  foreach($users as $u){  ?>
                    <tr>
                        <td><?php echo $u['nom']; ?></td>
                        <td><?php echo $u['prenom']; ?></td>
						<td><?php echo $u['tel']; ?></td>
                        <td><?php echo $u['email']; ?></td>
						<td><?php echo $u['responsable']; ?></td>
						<td><?php echo $u['interim']; ?></td>
                        <td><?php echo $u['matricule']; ?></td>
                        <td><?php echo $u['login']; ?></td>
                        <td>
                            <?php 
                                if($u['type']=="0"){ 
                                    echo "Utilisateur";
                                }else if($u['type']=="1"){
                                    echo "Responsable";
                                }else{
                                    echo "Administrateur";
                                }
                            ?>
                        </td>
                        <td>
                           <?php if($u['active']=="1"){ ?>
                            <span class="badge badge-success">Actif</span>
                            <?php }else{ ?>
                            <span class="badge badge-danger">Inactif</span>
                            <?php }?></td>
                                
                        </td>
						<td>

                            <?php if(in_array($edit, $access["User"]->actions)){ ?>
                            <a href="<?php echo site_url('user/edit/'.$u['idUtilisateur']); ?>" class="btn btn-info btn-xs"><span class="fa fa-pencil"></span> Edition</a> 
                            <?php } ?>

                            <?php if(in_array($delete, $access["User"]->actions)){ ?>
                            <a href="<?php echo site_url('user/remove/'.$u['idUtilisateur']); ?>" class="btn btn-danger btn-xs"><span class="fa fa-trash"></span> Supprimer</a>
                            <?php } ?>
                            
                        </td>
                    </tr>
                    <?php } ?>
                </tbody>
                </table>
                <div class="pull-right">
                    <?php echo $this->pagination->create_links(); ?>                    
                </div>                
            </div>
        </div>
    </div>
</div>
© 2026 GrazzMean