403Webshell
Server IP : 172.67.187.206  /  Your IP : 162.159.115.41
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  E:/Inetpub/www/myoffice/2566/modules/tkk1/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : E:/Inetpub/www/myoffice/2566/modules/tkk1/readedit.php
<?
CheckUser($_SESSION['user_user'], $_SESSION['user_pwd']);
?>
<script language="JavaScript">
//******************************************
function checkregis() {

if(document.myform.KOM.value=="") {
alert("กรุณาเลือกกลุ่ม") ;
document.myform.KOM.select() ;
return false ;
}

if(document.myform.TOPIC.value=="") {
alert("กรุณากรอกเรื่อง") ;
document.myform.TOPIC.select() ;
return false ;
}

//********************************************
}
</script>
	<TABLE cellSpacing=0 cellPadding=0 width=100% height=500 border=0>
      <TBODY>
        <TR>
          <TD  vAlign=top>
				<TABLE width="800" background="images/1234.jpg" align=center cellSpacing=0 cellPadding=0 border=0>
				<TR>
					<TD vAlign=top>
 <?
 if($_GET[op] == "tkk1_edit" AND $_GET[action] == "edit"){
	//////////////////////////////////////////// กรณีแก้ไข Database Edit
	if(CheckLevelUser($_SESSION['user_user'],$_GET[op])){
		//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
		//ดึงค่า
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[tkk1] = $db->select_query("SELECT * FROM ".TB_TKK1." WHERE id='".$_GET[id]."' ");
		$arr[tkk1] = $db->fetch($res[tkk1]);
	
		if (!$_POST[CATEGORY]){
			echo "<script language='javascript'>" ;
			echo "alert('กรุณากรอกข้อมูลต่างๆให้ครบถ้วน')" ;
			echo "</script>" ;
			echo "<script language='javascript'>javascript:history.back()</script>";
			exit();
}

		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$db->update_db(TB_TKK1,array(
			"category"=>"$_POST[CATEGORY]",
			"topic"=>"$_POST[TOPIC]",
			"edit"=>"5",
			"comment3"=>"$_POST[COMMENT3]",
			"comment2"=>"$_POST[COMMENT2]",
			"comment1"=>"",
			"comment_b"=>"$_POST[COMMENT_B]",			
			"namecom"=>"$_POST[NAMECOM]",
			"update_date"=>"",
			"enable_comment"=>"1"
		)," id=$_GET[id] ");
		$db->closedb ();

} else {
		//ทำการแก้ไขข้อมูลลงดาต้าเบส
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$db->update_db(TB_TKK1,array(
			"category"=>"$_POST[CATEGORY]",
			"topic"=>"$_POST[TOPIC]",
			"edit"=>"5",
			"comment3"=>"$_POST[COMMENT3]",
			"comment2"=>"$_POST[COMMENT2]",
			"comment1"=>"",
			"comment_b"=>"$_POST[COMMENT_B]",			
			"namecom"=>"$_POST[NAMECOM]",
			"update_date"=>"",
			"enable_comment"=>"1"
		)," id=$_GET[id] ");
		$db->closedb ();
}

		
		$ProcessOutput .= "<BR><BR>";
		$ProcessOutput .= "<CENTER><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
		$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการแก้ไข เรียบร้อยแล้ว</B></FONT><BR><BR>";
		$ProcessOutput .= "<meta http-equiv=\"refresh\" content=\"2 ;url=?name=tkk1&op=tkk1_read&category=".$arr[user][id]."\">";
		$ProcessOutput .= "</CENTER>";
		$ProcessOutput .= "<BR><BR>";
	
	echo $ProcessOutput ;
}
else if($_GET[op] == "tkk1_edit"){
	//////////////////////////////////////////// กรณีแก้ไข Form
	if(CheckLevelUser($_SESSION['user_user'],$_GET[op])){
		//ดึงค่า
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[tkk1] = $db->select_query("SELECT * FROM ".TB_TKK1." WHERE id='".$_GET[id]."' ");
		$arr[tkk1] = $db->fetch($res[tkk1]);
		$db->closedb ();

		//อ่านค่าจากไฟล์ Text เพื่อแก้ไข
		$Filetkk1Topic = "data/tkk1text/".$arr[tkk1][post_date].".txt";
		$file_open = @fopen($Filetkk1Topic, "r");
		$TextContent = @fread ($file_open, @filesize($Filetkk1Topic));
		@fclose ($file_open);
		$TextContent = stripslashes($TextContent);
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
		?>

<FORM NAME="myform" METHOD=POST ACTION="?name=tkk1&file=readback&op=tkk1_edit&action=edit&id=<?=$_GET[id];?>" enctype="multipart/form-data" onSubmit="return checkregis()">
<table width="100%" bgcolor=FFFFFF border="0" cellspacing="0" cellpadding="0">
 <tr> 	
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<B><FONT COLOR="#000000" size=4>บันทึกข้อความ</FONT></B></td>
  </tr>
  <tr> 
    <td >
<INPUT TYPE="hidden" NAME="KOM" size="40" VALUE="<?=$arr[tkk1][kom];?>" >
เรื่อง<INPUT TYPE="hidden" NAME="TOPIC" size="80" VALUE="<?=$arr[tkk1][topic];?>" ><?=$arr[tkk1][topic];?><hr />
<table width="750" border="0" cellspacing="0" cellpadding="0">
<tr> 
<td><div align="center"><?=$arr[tkk1][comment2];?><br>
 <?
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
$arr[user] = $db->fetch($res[user]);
?>
<INPUT TYPE="hidden" NAME="CATEGORY" VALUE="<?=$arr[user][id];?>" readonly style=\"color: #FF0000" >
</div>
</td>
</tr>
</tr>
  </table>
  <TABLE cellSpacing=0 cellPadding=0 width=400 border=0 align="center" >
<center><font color=red><b><u>ลบลายเซ็นและข้อคิดเห็นให้หมดก่อนบันทึกดึงกลับ</u></B></center>
<BR>
<?
if($arr[tkk1][enable_comment]){
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);

	
	//Check Comment
	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	$res[comment] = $db->select_query("SELECT * FROM ".TB_TKK1_COMMENT." WHERE tkk1_id='".$arr[tkk1][id]."' ORDER BY id ");
	$count=0;
	while($arr[comment] = $db->fetch($res[comment])){
		$count  ++;
	if(!$arr[comment][id]){
	echo "<BR><BR><BR><BR><CENTER><IMG SRC=\"images/icon/notview.gif\" BORDER=\"0\" ><BR><BR><B>ไม่มีเรื่อง</B></CENTER><BR><BR><BR><BR>";
	$Filetkk1Topic = "commentdata/".$arr[comment][post_date].".txt";
	$file_open = @fopen($Filetkk1Topic, "r");
	$content = @fread ($file_open, @filesize($Filetkk1Topic));
	$Detail = stripslashes(FixQuotes($content));
?>
<?
}
 { 	  
?>
<? } ?>			
			
			<TR>
			<TD align="center">
			<div align="center"><?if($_SESSION['user_user']){echo " <A HREF=\"?name=tkk1&file=delete_comment&id=".$_GET[id]."&comment=".$arr[comment][id]."\"><IMG SRC=\"images/admin/trash.gif\" WIDTH=\"20\" HEIGHT=\"20\" BORDER=\"0\" ALIGN=\"absmiddle\"></A>";};?>
			
			<?
					 if($arr[comment][comment_b]){ 	  
?>
<IMG SRC="myoffice/<?=($arr[comment][comment_b]);?>.png">
		  <? } else {
		 echo "";
	 }?>
<?
					 if($arr[comment][comment_c]){ 	  
?>
<IMG SRC="myoffice/<?=($arr[comment][comment_c]);?>.png">
		  <? } else {
		 echo "";
	 }?>
<BR>

				<?=($arr[comment][detail]);?><?echo thainumDigit($arr[comment][comment]);?></FONT></B>
			<B><div align="center"><B><FONT COLOR="#990000">
				<?
					 if($arr[comment][laysen1]){ 	  
?>
	<IMG SRC="laysen/<?=($arr[comment][laysen1]);?>.jpg">
		  <? } else {
		 echo "";
	 }?>		
				</div></TD>
			</TR>
			<TR>
				<TD height="1" class="dotline"></TD>
			</TR>
			
<?
}
?>
			</TABLE>
<CENTER><INPUT TYPE="submit" value="บันทึกดึงกลับ" name="submit"> <CENTER>
<?
	}
	$db->closedb ();
?>

</td>
  </tr>
</table>
</FORM>
</TD>
</TR>				
</TABLE>
	</td>
  </tr> 

<?
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
?>
		
					</TD>
				</TR>
			</TABLE>
		

Youez - 2016 - github.com/yon3zu
LinuXploit