C:\$Recycle.Bin\S-1-5-21-3967099092-2644009230-141905953-500\$R83TZYV\nucleus\index.php


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
<?php
/*
  * Nucleus: PHP/MySQL Weblog CMS (http://nucleuscms.org/)
  * Copyright (C) 2002-2005 The Nucleus Group
  *
  * This program is free software; you can redistribute it and/or
  * modify it under the terms of the GNU General Public License
  * as published by the Free Software Foundation; either version 2
  * of the License, or (at your option) any later version.
  * (see nucleus/documentation/index.html#license for more info)
 */
/**
 * @license http://nucleuscms.org/license.txt GNU General Public License
 * @copyright Copyright (C) 2002-2005 The Nucleus Group
 * @version $Id: index.php,v 1.16.2.1 2005/08/15 10:51:08 dekarma Exp $
  */
    // we are using admin stuff:
    
$CONF = array();
    
$CONF['UsingAdminArea'] = 1;

    
// include the admin code
    
include('../config.php');

    if (
$CONF['alertOnSecurityRisk'] == 1)
    {
        
// check if files exist and generate an error if so
        
$aFiles = array(
            
'../install.sql' => 'install.sql should be deleted',
            
'../install.php' => 'install.php should be deleted',
            
'upgrades' => 'nucleus/upgrades directory should be deleted',
            
'convert' => 'nucleus/convert directory should be deleted'
        
);
        
$aFound = array();
        foreach(
$aFiles as $fileName => $fileDesc)
        {
            if (@
file_exists($fileName))
                
array_push($aFound$fileDesc);
        }
        if (@
is_writable('../config.php')) {
            
array_push($aFound'config.php should be non-writable (chmod to 444)');
        }
        if (
sizeof($aFound) > 0)
        {
            
startUpError(
                
'<p>One or more of the Nucleus installation files are still present on the webserver, or are writable.</p><p>You should remove these files or change their permissions to ensure security. Here are the files that were found by Nucleus</p> <ul><li>'implode($aFound'</li><li>').'</li></ul><p>If you don\'t want to see this error message again, without solving the problem, set <code>$CONF[\'alertOnSecurityRisk\']</code> in <code>globalfunctions.php</code> to <code>0</code>, or do this at the end of <code>config.php</code>.</p>',
                
'Security Risk'
            
);
        }
    }

    
$bNeedsLogin false;
    
$bIsActivation in_array($action, array('activate''activatesetpwd'));
    
    if (
$action == 'logout'
        
$bNeedsLogin true;    
    
    if (!
$member->isLoggedIn() && !$bIsActivation)
        
$bNeedsLogin true;

    
// show error if member cannot login to admin
    
if ($member->isLoggedIn() && !$member->canLogin() && !$bIsActivation) {
        
$error _ERROR_LOGINDISALLOWED;
        
$bNeedsLogin true;
    }
    
    if (
$bNeedsLogin)
    {
        
setOldAction($action);    // see ADMIN::login() (sets old action in POST vars)
        
$action 'showlogin';
    }

    
sendContentType('application/xhtml+xml''admin-' $action);
    
    
$admin = new ADMIN();
    
$admin->action($action);
?>