403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.155
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/news/csr/admin/report/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/news/csr/admin/report/schoolall.php
<?php  
if(!isset($_SESSION)) session_start();
if(isset($_SESSION['ugroup'])){ 
$user=$_SESSION["loguser"];
$ugroup=$_SESSION["ugroup"];
//ส่งออกรายชื่อนักเรียน 
error_reporting(E_ALL);
ini_set('display_errors', TRUE);
ini_set('display_startup_errors', TRUE);
date_default_timezone_set('Asia/Bangkok');
require_once "../../include/config.php";

$u="";
$output = '';
$sql= $mysqli->query("SELECT * FROM log_school ");
 if(mysqli_num_rows($sql) > 0)
 {

set_time_limit(0);
header('Content-Type: text/html; charset=utf-8');
header("Content-Type: application/vnd.ms-excel");
header('Content-Disposition: attachment; filename="filename.xls"');#กำหนดชื่อไฟล์

echo '<html xmlns:o="urn:schemas-microsoft-com:office:office"xmlns:x="urn:schemas-microsoft-com:office:excel"xmlns="http://www.w3.org/TR/REC-html40">';
 
$mysqli->set_charset("utf8");
 
$sql= $mysqli->query("SELECT * FROM log_school ");
$i = 0;
echo '<table style="boder:1px" border="1" x:str>';
echo '   <tr>  
                        <th>ที่</th>  
                        <th>รหัส</th>  
                        <th>ชื่อโรงเรียน</th>
						<th>เลขผู้เสียภาษี</th>
						<th>สังกัด</th>
        </tr>';
while($row=mysqli_fetch_array($sql)) {
	$i++;
$SQL1 = $mysqli->query("SELECT * FROM log_area WHERE `username` ='$row[areacode]'");
$Row1 = mysqli_fetch_array($SQL1);
	
    echo '<tr>
                <td>'.$i.'</td>
                <td>'.$row['username'].'</td>
                <td>'.$row['fullname'].'</td>
                <td>'.$row['idpayment'].'</td>
				<td>'.$Row1['fullname'].'</td>
            </tr>';
}
echo '</table>';

 }
} else {
header("Location: ../index.php?msg=error");
exit;
}
?>

Youez - 2016 - github.com/yon3zu
LinuXploit