403Webshell
Server IP : 104.21.80.248  /  Your IP : 172.71.28.156
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/myschool/triamudom/check/activity/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/myschool/triamudom/check/activity/function_actadd.php
<?php
session_start();
$path = "../";
include ($path.'include/config_db.php');
include ($path.'include/class_db.php'); 
include ($path.'include/class_display.php'); 
include ($path.'include/class_application.php'); 

$CLASS['db']   = new db();
$CLASS['db']->connect (); 
$CLASS['disp']   = new display();
$db   = $CLASS['db']; 
$disp   = $CLASS['disp']; 

$action = $_REQUEST['action'];
$tb_act_id = $_REQUEST['tb_act_id'];
$tb_act_code = $_REQUEST['tb_act_code'];
$tb_act_name = $_REQUEST['tb_act_name'];
$tb_act_object = $_REQUEST['tb_act_object'];
$tb_act_detail = $_REQUEST['tb_act_detail'];
$tb_act_num = $_REQUEST['tb_act_num'];
$tb_act_room = $_REQUEST['tb_act_room'];
$tb_act_class = $_REQUEST['tb_act_class'];
$tb_act_year = $_REQUEST['tb_act_year'];
$tb_teacher_id = $_REQUEST['tb_teacher_id'];
$tb_act_comment = $_REQUEST['tb_act_comment'];

$fetch_numact = $db->fetch_array($db->query("SELECT COUNT(tb_act_id) AS numact FROM tb_acts"));
$tb_act_code = "ACT-".sprintf("%05d",$fetch_numact['numact']+1);

$fetch_disact = $db->fetch_array($db->query("select * from tb_act_setup"));
$tb_act_num  = $fetch_disact['tb_act_setup_num'];

 	$query_int = $db->query("INSERT INTO  tb_acts (tb_act_code, tb_act_name,tb_act_object, tb_act_detail, tb_act_num, tb_act_room, tb_act_year, tb_act_status, tb_teacher_id, tb_act_comment,tb_act_class) VALUES ('".$tb_act_code."', '".$tb_act_name."','".$tb_act_object."', '".$tb_act_detail."', '".$tb_act_num."', '".$tb_act_room."', '".$tb_act_year."', '1', '".$_SESSION['sessiontuser_id']."' ,'".$tb_act_comment."','".$tb_act_class."')");
	
		print "
	<script language='javascript'>
		window.location.href='display_teacher_act.php';
	</script>
	";

 ?>

Youez - 2016 - github.com/yon3zu
LinuXploit