403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.156
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/myoffice/2563/modules_backup301262/tkk1/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/myoffice/2563/modules_backup301262/tkk1/tabain.php
<?
CheckUser($_SESSION['user_user'], $_SESSION['user_pwd']);
?>
<script type="text/javascript">
function myoffice(val, group_num)
{
if(val==true)
{
	document.getElementById("group"+group_num+"").style.display="";
}
else
{
	document.getElementById("group"+group_num+"").style.display="none";
}

}
</script>
<script language="JavaScript">

//******************************************
function checkregis() {
  
if(document.myform.chk1.checked == false && document.myform.chk2.checked == false && document.myform.chk3.checked == false && document.myform.chk4.checked == false && document.myform.chk5.checked == false )   
{        
alert('คุณไม่ได้เลือกรายการ ');       
return false;    
}    

//********************************************
}
</script>
<script src="http://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js"></script>  
<script type="text/javascript">  
$(function(){        
	  
    $(".css_data_item").click(function(){  // เมื่อคลิก checkbox  ใดๆ  
        if($(this).prop("checked")==true){ // ตรวจสอบ property  การ ของ   
            var indexObj=$(this).index(".css_data_item"); //   
            $(".css_data_item").not(":eq("+indexObj+")").prop( "checked", false ); // ยกเลิกการคลิก รายการอื่น  
        }  
    });  

    $("#form_checkbox1").submit(function(){ // เมื่อมีการส่งข้อมูลฟอร์ม  
        if($(".css_data_item:checked").length==0){ // ถ้าไม่มีการเลือก checkbox ใดๆ เลย  
            alert("NO");  
            return false;     
        }  
    });  	
		  
});  
</script>  
	<TABLE cellSpacing=0 cellPadding=0 width=100% height=500 border=0>
      <TBODY>
        <TR>
          <TD  vAlign=top>
				<TABLE width="100%" align=center cellSpacing=0 cellPadding=0 border=0>
				<TR>
					<TD>
<?
	if($_GET[op] == "tkk1_edit" AND $_GET[action] == "edit"){
	//////////////////////////////////////////// กรณีแก้ไข Database Edit
	if(CheckLevelUser($_SESSION['user_user'],$_GET[op])){
		//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
		//ดึงค่า
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[tkk1] = $db->select_query("SELECT * FROM ".TB_TKK1." WHERE id='".$_GET[id]."' ");
		$arr[tkk1] = $db->fetch($res[tkk1]);
		$db->closedb ();

		if (!$_POST[CATEGORY] ){
			echo "<script language='javascript'>" ;
			echo "alert('กรุณากรอกข้อมูลต่างๆให้ครบถ้วน')" ;
			echo "</script>" ;
			echo "<script language='javascript'>javascript:history.back()</script>";
			exit();
}
		//ทำการแก้ไขข้อมูลลงดาต้าเบส
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$db->update_db(TB_TKK1,array(
			"category"=>"$_POST[CATEGORY]",
			"comment1"=>"".implode(",",$_POST[COMMENT1]).",",
			"comment2"=>"".htmlspecialchars($_POST[COMMENT2])."",
			"comment3"=>"".htmlspecialchars($_POST[COMMENT3])."",
			"comment_b"=>"".htmlspecialchars($_POST[COMMENT_B])."",
			"rabob"=>"$_POST[RABOB]",
			"enable_comment"=>"1"
		)," id=$_GET[id] ");
		$db->closedb ();

} else {
		//ทำการแก้ไขข้อมูลลงดาต้าเบส
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$db->update_db(TB_TKK1,array(
			"category"=>"$_POST[CATEGORY]",
			"comment1"=>"".implode(",",$_POST[COMMENT1]).",",
			"comment2"=>"".htmlspecialchars($_POST[COMMENT2])."",
			"comment3"=>"".htmlspecialchars($_POST[COMMENT3])."",
			"comment_b"=>"".htmlspecialchars($_POST[COMMENT_B])."",
			"rabob"=>"$_POST[RABOB]",
			"enable_comment"=>"1"
		)," id=$_GET[id] ");
		$db->closedb ();
}	
		$ProcessOutput .= "<BR><BR>";
		$ProcessOutput .= "<CENTER><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
		$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการจัดเก็บ เรียบร้อยแล้ว</B></FONT><BR><BR>";
		$ProcessOutput .= "<meta http-equiv=\"refresh\" content=\"0 ;url=?name=tkk1&op=tkk1_read&category=".$arr[user][id]."\">";
		$ProcessOutput .= "</CENTER>";
		$ProcessOutput .= "<BR><BR>";
	echo $ProcessOutput ;
}
else if($_GET[op] == "tkk1_edit"){
	//////////////////////////////////////////// กรณีแก้ไข Form
	if(CheckLevelUser($_SESSION['user_user'], $_GET[op])){
		//ดึงค่า
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[tkk1] = $db->select_query("SELECT * FROM ".TB_TKK1." WHERE id='".$_GET[id]."' ");
		$arr[tkk1] = $db->fetch($res[tkk1]);
		$db->closedb ();

		//อ่านค่าจากไฟล์ Text เพื่อแก้ไข
		$Filetkk1Topic = "tkk1data/".$arr[tkk1][post_date].".txt";
		$file_open = @fopen($Filetkk1Topic, "r");
		$TextContent = @fread ($file_open, @filesize($Filetkk1Topic));
		@fclose ($file_open);
		$TextContent = stripslashes($TextContent);
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
		?>

<FORM NAME="myform" METHOD=POST ACTION="?name=tkk1&file=tabain&op=tkk1_edit&action=edit&id=<?=$_GET[id];?>" enctype="multipart/form-data" onSubmit="return checkregis()">
<BR>
<table width="600" align="center" background="images/1234.jpg" border="0" cellspacing="0" cellpadding="0">
      <tr> 
      <td><div align="center"><p align="center"><BR><B>จัดการเอกสาร เลือกเพียงรายการเดียว</B><HR>
 <table width="600" align="center" border="0"  cellspacing="0" cellpadding="0">
<tr>
<td>
<INPUT TYPE="checkbox" NAME="RABOB" class="css_data_item" id="rabob" VALUE="30"  onclick="myoffice(this.checked, '2')" />
<font color=red><b>จัดเก็บเอกสาร (กรณีส่งด้วยตนเอง)</font>
<INPUT TYPE="checkbox" NAME="RABOB" class="css_data_item" id="rabob" VALUE="29"  onclick="myoffice(this.checked, '1')" />
<font color=blue>นำส่งธุรการกลุ่ม (กรณีให้ธุรการส่งหนังสือ)</B></font>
<BR>
<INPUT TYPE="checkbox" NAME="COMMENT1[]" id='chk1' VALUE="จัดเก็บ" >
จัดเก็บ
<INPUT TYPE="checkbox" NAME="COMMENT1[]" id='chk2' VALUE="ส่งโรงเรียน" >
 ส่งโรงเรียน
<INPUT TYPE="checkbox" NAME="COMMENT1[]" id='chk3' VALUE="ส่งหนังสือเวียนกลุ่ม" >
 ส่งหนังสือเวียนกลุ่ม
<INPUT TYPE="checkbox" NAME="COMMENT1[]" id='chk4' VALUE="ส่งหน่วยงานอื่นๆ" >
 ส่งหน่วยงานอื่นๆ
 <INPUT TYPE="checkbox" NAME="COMMENT1[]" id='chk5' VALUE="ส่ง สพฐ." >
 ส่ง สพฐ.<HR></font>
</td>
</tr>
</table>
<div id="group1" style="display:none;">
<table width="600" align="center" border="0" cellspacing="0" cellpadding="0">
<?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE turakan='7' and working='".$arr[user][working]."' and status='1' OR work='8' and working='".$arr[user][working]."' and status='1' ");
while ($arr[user] = $db->fetch($res[user])){
?>
<td width="50%"  valign="top">
<input type="radio" name="CATEGORY" value="<?=$arr[user][id];?>" ><font color=blue><?=$arr[user][category_name];?></font>
<?
if (($count%2) == 0) { echo "<TR><TD colspan=3 height=\"1\" class=\"dotline\"></TD></TR>"; $count=0; 
} else{
	echo "</TD>";
} 
}
$db->closedb ();
?>
</TD>
</TR>
</table>
</TD>
</TR>
</table>
</div>
<div id="group2" style="display:none;">
<table width="600" align="center" border="0" cellspacing="0" cellpadding="0">
<TR>
<TD><font color=red>
<input type="radio" name="CATEGORY" value="o" ><B>ทะเบียนหนังสือ</B>
</TD>
</TR>
</table>
</div>
</td>
</tr>
<tr>
<td align="center">
<INPUT TYPE="submit" value="บันทึกจัดเก็บ" name="submit"style="background-color:#FFFF99"> 
</td>
    </tr>
  </table>
</FORM>
<?
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
?>
					</TD>
				</TR>
			</TABLE>
			<!-- Admin -->
		  </TD>
        </TR>
      </TBODY>
    </TABLE>

Youez - 2016 - github.com/yon3zu
LinuXploit