C:\$Recycle.Bin\S-1-5-21-3967099092-2644009230-141905953-500\$RVSVKU0\setup\cpg1419\viewlog.php


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
<?php
/*************************
  Coppermine Photo Gallery
  ************************
  Copyright (c) 2003-2008 Dev Team
  v1.1 originally written by Gregory DEMAR

  This program is free software; you can redistribute it and/or modify
  it under the terms of the GNU General Public License version 3
  as published by the Free Software Foundation.

  ********************************************
  Coppermine version: 1.4.19
  $HeadURL: https://coppermine.svn.sourceforge.net/svnroot/coppermine/trunk/cpg1.4.x/viewlog.php $
  $Revision: 4392 $
  $Author: gaugau $
  $Date: 2008-04-16 09:25:35 +0200 (Mi, 16 Apr 2008) $
**********************************************/

define('IN_COPPERMINE',1);
define('VIEWLOG_PHP',1);

require(
'include/init.inc.php');

function 
display_log_list()
{
    global 
$lang_viewlog_php;

    
$log_list getloglist('logs/');
    if (
count($log_list)>0) {
            foreach (
$log_list as $log) {
                    echo <<<EOT
                                <tr>
                                        <td class="tableb">
                                                <img src="images/folder.gif" alt="" />&nbsp;<a href= "
{$_SERVER['PHP_SELF']}?log={$log['logname']}">{$log['logname']}</a>
                                                &nbsp;&nbsp;&nbsp; ( <i>
{$log['filesize']} KB</i> )
                                        </td>
                                </tr>
EOT;
            }
            echo <<<EOT
                                <tr>
                                        <td class="tableb" align="center">
                                                <input class="button" type="button" value="
{$lang_viewlog_php['delete_all']}" name="dall" id="dall" onclick="window.location='viewlog.php?action=dall';" />
                                        </td>
                                </tr>
EOT;
    } else {
            
cpg_die(INFORMATION,$lang_viewlog_php['no_logs'], __FILE__,1);
    }
}

function 
display_log($logname)
{
        global 
$lang_viewlog_php;

        echo <<<EOT
                <tr>
                        <td class="tableb" align="center">
                                <input class="button" type="button" value="
{$lang_viewlog_php['delete_all']}" name="dall1" id="dall1" onclick="window.location='viewlog.php?action=dall';" />
                                <input class="button" type="button" value="
{$lang_viewlog_php['view_logs']}" name="back1" id="back1" onclick="window.location='viewlog.php';" />
                                <input class="button" type="button" value="
{$lang_viewlog_php['delete_this']}" name="dthis1" id="dthis1" onclick="window.location='viewlog.php?action=dthis&amp;log=$logname';" />
                        </td>
                </tr>
                <tr>
                        <td class="tableb">
                                <pre>
EOT;
        
log_read($logname);
        echo <<<EOT
                                </pre>
                        </td>
                </tr>
                <tr>
                        <td class="tableb" align="center">
                                <input class="button" type="button" value="
{$lang_viewlog_php['delete_all']}" name="dall2" id="dall2" onclick="window.location='viewlog.php?action=dall';" />
                                <input class="button" type="button" value="
{$lang_viewlog_php['view_logs']}" name="back2" id="back2" onclick="window.location='viewlog.php';" />
                                <input class="button" type="button" value="
{$lang_viewlog_php['delete_this']}" name="dthis2" id="dthis2" onclick="window.location='viewlog.php?action=dthis&amp;log=$logname';" />
                        </td>
                </tr>

EOT;
}

$log = @$_GET['log'];
$action = @$_GET['action'];

pageheader('Logs :: '.$log);

if (!
$USER_DATA['has_admin_access']) {
        
// Write access attempt to 'security' log file
        
if ($CONFIG['log_mode']) {
                
log_write('Denied privileged access to viewlog.php from user '.$USER_DATA['user_name'].' at '.$_SERVER['REMOTE_HOST'].' on '.date("F j, Y, g:i a"),CPG_SECURITY_LOG);
        }
        
cpg_die(CRITICAL_ERROR,$lang_errors['access_denied'], __FILE__,1);
}

starttable("100%""Logs :: ".$log);


if (isset(
$action)) {
        if (
$action=='dthis' && isset($log)) {
                
log_delete($log);
                unset(
$log);
        } elseif (
$action=='dall') {
                unset(
$log);
                
log_delete();
        }
}

// If log variable not set or log file's directory is not current directory then display logs list else display log with given name stripping risky characters from it
if (!isset($log) || dirname($log) != '.') {
    
display_log_list();
} else {
    
display_log(ereg_replace('\.|/|%00'''$log));
}

endtable();
pagefooter();
?>