403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.155
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/myschool/benjama/modules/maintenance/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/myschool/benjama/modules/maintenance/roomedit.php
<?
require_once($MODPATH ."inc.php") ;
//print_r($_POST);
//print_r($_GET);
if(isset($_POST[submit])){
    $db->update_db(TB_room,array(
        "room"=>"$_POST[room]",
        "rname"=>"$_POST[rname]",
        "build"=>"$_POST[build]",
        "floor"=>"$_POST[floor]",
        "computer"=>"$_POST[computer]",
        "csn"=>"$_POST[csn]",
        "cnew"=>"$_POST[cnew]",
        "projector"=>"$_POST[projector]",
        "psn"=>"$_POST[psn]",
        "pnew"=>"$_POST[pnew]",			
        "visual"=>"$_POST[visual]",
        "amplifier"=>"$_POST[amplifier]",
        "result"=>"$_POST[result]",
        "ups"=>"$_POST[ups]",
        "old"=>"$_POST[old]",
        "remark"=>"$_POST[remark]"
    )," room=$_GET[id] "); 
    //echo $db->sql; 
    $ProcessOutput .= "<BR><BR>";
    $ProcessOutput .= "<CENTER><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
    $ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการแก้ไขห้อง เรียบร้อยแล้ว</B></FONT><BR><BR>";
    $ProcessOutput .= "<meta http-equiv=\"refresh\" content=\"1 ;url=?name=maintenance&file=roomedit&id=". $_POST[room] ."\">";
    $ProcessOutput .= "</CENTER>";
    $ProcessOutput .= "<BR><BR>";
    echo $ProcessOutput ;
    exit;
}
else if(isset($_POST[addnew])){
    $db->add_db(TB_room,array(
        "room"=>"$_POST[room]"
    ));
    $ProcessOutput .= "<BR><BR>";
    $ProcessOutput .= "<CENTER><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
    $ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการเพิ่มห้อง เรียบร้อยแล้ว</B></FONT><BR><BR>";
    $ProcessOutput .= "<meta http-equiv=\"refresh\" content=\"1 ;url=?name=maintenance&file=roomedit&id=". $_POST[room] ."\">";
    $ProcessOutput .= "</CENTER>";
    $ProcessOutput .= "<BR><BR>";
    echo $ProcessOutput ;
    exit;
}

echo "เลือกห้อง ";
echo room_list("id",$_GET[name],$_GET[file],$_GET[id],"");
//echo "<br>\n";

$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[room] = $db->select_query($sql="SELECT * FROM ".TB_room." WHERE room='" . $_GET[id] ."'" );
//echo $sql ;
$arr[room] = $db->fetch($res[room]);
//print_r ($arr[room]);

echo "<FORM METHOD=POST ACTION=\"?name=maintenance&file=roomedit&id=".$arr[room][room]."\">";
if($_GET[op]=='edit') {
    echo "room" . str_repeat('&nbsp;',7);
    echo "<input type=text name=room value=". $arr[room][room] .">";
}
echo "<table>";
$i=1;
foreach($arr[room] as $key => $val){
    if($key=='room')continue ;
    if($key=='remark'){echo "</tr>"; $i=1; }
    if($i==1)echo "<tr>";
    echo "<td>$key</td>";
    $txt = "<input type=textbox name=$key value='$val'>";
    if($_GET[op]!='edit') $txt= ":" . $val ;
    echo "<td>$txt</td>";
    if($i==3)echo "</tr>";
    $i++;
    if($i==4) $i=1;
}
//echo "<tr><td></td></tr>";
echo "</table>";
if($_GET[op]=='edit') echo "<input type=submit name=submit value=' submit ' > ";
if($_GET[op]=='edit') echo "<input type=submit name=addnew value=' add new ' > ";
echo "</form>";

echo "<br>\n";
echo "<table border=1 cellspacing=0>";
echo "<tr>";
echo "<td>หมายเลข</td>";
echo "<td>ห้อง</td>";
echo "<td>ชนิด</td>";
echo "<td>ยี่ห้อ</td>";
echo "<td>รุ่น</td>";
echo "<td>รีเรียล นัมเบอร์ (S/N)</td>";
echo "<td>หมายเลขพัสดุ</td>";
echo "<td>วันที่ซื้อ/ส่งมอบ</td>";
echo "<td>ซื้อจาก</td>";
echo "<td>detail</td>";
echo "<td>histrory</td>";
echo "<td>waranty</td>";
echo "<td>status</td>";
echo "</tr>";

$res[device] = $db->select_query($sql="SELECT * FROM ".TB_device." WHERE room='" . $_GET[id] ."' ORDER BY type" );
while ($arr[device] = $db->fetch($res[device])){
    echo "<tr>";
    foreach($arr[device] as $key => $val){
        echo "<td>";
        echo "<a href='?name=maintenance&file=device&id=" . $arr[device][id] ."'>";
        echo ($key =='type')? $atype[$val] : $val ;
        echo "</a>";
        echo "</td>";
    }
    echo "</tr>";

}
echo "</table>";

echo "<a href='?name=maintenance&file=device&room=" . $_GET[id] ."'>";
echo "เพิ่มอุปกรณ์" ;
echo "</a>";


?>

Youez - 2016 - github.com/yon3zu
LinuXploit