:: **Zploit** v1.0 | Current Path: **/var/softaculous/yourls/**
:: Editing File: _edit.php
<?php ////////////////////////////////////////////////////////////// //=========================================================== // edit.php(For individual softwares) //=========================================================== // SOFTACULOUS // Version : 1.0 // Inspired by the DESIRE to be the BEST OF ALL // ---------------------------------------------------------- // Started by: Alons // Date: 10th Jan 2009 // Time: 21:00 hrs // Site: http://www.softaculous.com/ (SOFTACULOUS) // ---------------------------------------------------------- // Please Read the Terms of use at http://www.softaculous.com // ---------------------------------------------------------- //=========================================================== // (c)Softaculous Inc. //=========================================================== ////////////////////////////////////////////////////////////// if(!defined('SOFTACULOUS')){ die('Hacking Attempt'); } ///////////////////////////////////////// // All functions in this PAGE must begin // with TWO UNDERSCORE '__' to avoid // clashes with SOFTACULOUS Functions // e.g. __funcname() ///////////////////////////////////////// ////////////////////////////////////////// // Note : The path of the upgrade package // is $software['path'].'/' . So to // access other files use // $software['path'].'/other_file.ext' ////////////////////////////////////////// //The Edit process function __edit($installation){ global $__settings, $globals, $setupcontinue, $software, $error, $replace_data; $__settings['admin_username'] = optPOST('admin_username'); $__settings['admin_pass'] = optPOST('admin_pass'); // Do we need to reset the password ? if(!empty($__settings['admin_pass'])){ // We need the username if(empty($__settings['admin_username'])){ $error[] = '{{err_no_username}}'; return false; } //We need the username and old password values $file = sfile($installation['softpath'].'/user/config.php'); if(empty($file)){ $error[] = '{{err_openconfig}}'; return false; } if(sversion_compare($__settings['ver'], '1.8', '<')){ soft_preg_replace('/\$yourls_user_passwords(\s*?)=(\s*?)array(.*?)("|\')(.*?)("|\')/is', $file, $user, 5); soft_preg_replace('/\$yourls_user_passwords(\s*?)=(\s*?)array(.*?)("|\')(.*?)("|\')(\s*?)=>(\s*?)("|\')(.*?)("|\')/is', $file, $pass, 10); } else{ soft_preg_replace('/\$yourls_user_passwords(\s*?)=(\s*?)\[(.*?)("|\')(.*?)("|\')/is', $file, $user, 5); soft_preg_replace('/\$yourls_user_passwords(\s*?)=(\s*?)\[(.*?)("|\')(.*?)("|\')(\s*?)=>(\s*?)("|\')(.*?)("|\')/is', $file, $pass, 10); } if($__settings['admin_username'] != $user){ $error[] = '{{err_no_such_user}}'; return false; }else{ if(sversion_compare($__settings['ver'], '1.8', '<')){ //This is for plain text passwords below 1.8 $replace_data["'".$user."' => '".$pass."'"] = "'".$user."' => '".$__settings['admin_pass']."'"; } else{ // This is to obtain password method from install.php sp_include_once($software['path'].'/install.php'); // creating password using install.php __admin_pass() function $__settings['admin_pass'] = __admin_pass($__settings['admin_pass']); $replace_data["'".$user."' => '".$pass."'"] = "'".$user."' => '".$__settings['admin_pass']."'"; } if(!empty($error)){ return false; } sclone_replace($replace_data, $installation['softpath'].'/user/config.php', true); } } } ?>