HEX
Server: LiteSpeed
System:
User: ()
PHP: 7.4.33
Disabled: sendmail,mail,exec,shell_exec,dl,system,passthru,pclose,proc_open,proc_nice,proc_terminate,proc_get_status,proc_close,leak,apache_child_terminate,posix_kill,posix_mkfifo,posix_setpgid,posix_setsid,posix_setuid,escapeshellcmd,escapeshellarg shell-exec,fpassthru,crack_check,crack_closedict,crack_getlastmessage,crack_opendict,psockopen,php_uname,symlink,ini_restore,posix_getpwuid,posix_getegid,posix_getcwd,posix_geteuid,posix_getgroups,posix_uname,posix_setuid,eval,show_source,passthru,popen,allow_url_fopen,get_current_user,getmyuid,getmygid,entre2v2,index_changer_wp,index_changer_joomla,exec_mode_1,exec_mode_2,exec_mode_3,wsoFooter,wsoEx,wsoViewSize,wsoPerms,wsoPermsColor,ukuran,tulis,ambil,tukar,entre2v2,rapih,magicboom,goaction,scookie,showstat,index_changer
Upload Files
File: /home/muratemr/theotto.tr/api/admin/profile.php
<?php
/**
 * api/admin/profile.php
 * Şifre değiştirme endpoint
 */

declare(strict_types=1);

require_once __DIR__ . '/../../includes/db.php';
require_once __DIR__ . '/../../includes/auth.php';
require_once __DIR__ . '/../../includes/csrf.php';
require_once __DIR__ . '/../../includes/functions.php';

require_login();
csrf_required();

if (post_str('action') !== 'change_password') json_response(false, 'Geçersiz işlem.');

$current = post_str('current_password');
$new     = post_str('new_password');

if (!$current) json_response(false, 'Mevcut şifre zorunlu.');
if (!$new)     json_response(false, 'Yeni şifre zorunlu.');
if (strlen($new) < 8) json_response(false, 'Yeni şifre en az 8 karakter olmalı.');

$me   = current_user();
$user = db_row("SELECT password_hash FROM users WHERE id = ?", [$me['id']]);

if (!$user || !password_verify($current, $user['password_hash'])) {
    json_response(false, 'Mevcut şifre hatalı.');
}

$hash = password_hash($new, PASSWORD_DEFAULT);
db_run("UPDATE users SET password_hash = ? WHERE id = ?", [$hash, $me['id']]);

json_response(true, 'Şifreniz başarıyla güncellendi.');