403Webshell
Server IP : 172.67.187.206  /  Your IP : 162.159.115.41
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  E:/Inetpub/www/myschool/prathan/modules/admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : E:/Inetpub/www/myschool/prathan/modules/admin/signature.php
<?
session_start();
?>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR/html4/frameset.dtd">
<HTML>
<HEAD>
<? if($name==''){
?>
<SCRIPT language="JavaScript">
	alert("กรุณา Login ก่อนเข้าใช้ระบบ");
location.href='index.php';
</SCRIPT>
<? } ?>
<?php
include 'connect.php';
?>
<? if($add == '1' ){
$sql = "insert into emonitorplan_user (username,passwords,fullname,status) values ('$username','$username','$fullname','school')"; 
//echo"$sql";
$dbquery = mysql_db_query($dbname, $sql);
} ?>
<? if($update == '1' ){
$sql= "update emonitorplan_user set username='$usernameedit',passwords='$passwordsedit',fullname='$fullnameedit' where id='$idedit'"; 
//echo"$sql";
$dbquery = mysql_db_query($dbname, $sql);
} ?>
<? if($del != '' ){
	$sql = "delete from emonitorplan_user where id='$del'"; 
	//echo"$sql";
	$dbquery = mysql_db_query($dbname, $sql); 
		

 } ?>


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-874">
<title></title>
<link href="stylesheet.css" rel="stylesheet" type="text/css">

<style type="text/css">
<!--
.style3 {color: #0000ff; font-weight: bold; }
.style4 {color: #FF0000; font-weight: bold; }
.style5 {color: #0000FF}
-->
</style>
</head>

<body leftmargin="0" topmargin="0">
<table width="100%"  border="0" cellspacing="0" cellpadding="1">
  <tr>
    <td bgcolor="#c2e1fd" class=" unnamed1"><strong>&nbsp;&nbsp;&nbsp;จัดการข้อมูลโรงเรียน</strong></td>
  </tr>
</table>
<form name="form3" method="post" action="user.php">
  <div align="left"><br>
  </div>
  <table width="342"  border="0" align="center" cellpadding="0" cellspacing="0">

    <tr class="unnamed1">
      <td width="11" class="unnamed2"><img src="images/search.jpg" alt="s" width="19" height="18"></td>
      <td width="70" class="unnamed2"><div align="left"><strong>ระบุเงื่อนไข</strong></div></td>
      <td width="151"><label>
      </label>
      <input name="search" type="text" id="search"></td>
      <td width="110">
        <div align="left">
          <input type="submit" name="Submit2" value="ค้นหา">
        </div></td>
    </tr>
  </table>
  <br>
  <div align="left"></div>
</form>
<table width="100%"  border="0" cellspacing="0" cellpadding="1">
  <tr>
    <td bgcolor="#c2e1fd" class=" unnamed1">&nbsp;</td>
  </tr>
</table>
<br>
<? if($showedit == '') {?>
<form name="form1" method="post" action="user.php">
  <table width="422"  border="0" align="center" cellpadding="0" cellspacing="0">
    <tr class="unnamed1">
      <td width="13" class="unnamed2">&nbsp;</td>
      <td width="192" class="unnamed2"><div align="center"><strong>user name</strong></div></td>
	  <td width="192" class="unnamed2"><div align="center"><strong>password</strong></div></td>
      <td width="192" class="unnamed2"><div align="center"><strong>ชื่อโรงเรียน</strong></div></td>
      <td width="101"><div align="center">
        <input name="add" type="hidden" id="add" value="1">
      </div></td>
    </tr>
    <tr class="unnamed1">
      <td class="unnamed2">&nbsp;</td>

      <td class="unnamed2"><div align="center">
        <input name="username" type="text" id="username" size="20">
      </div></td>

	  <td class="unnamed2"><div align="center">
        -
      </div></td>

      <td class="unnamed2"><div align="center">
        <input name="fullname" type="text" id="fullname" size="20">
      </div></td>

      <td><div align="center">
        <input type="button" name="Submit" value="  เพิ่ม  "onclick=chkaddsumit()>
      </div></td>
    </tr>
  </table>
  <br>
</form>
<? } ?>
<? if($showedit != '') { ?>
  <form name="form2" method="post" action="user.php">
    <table width="706"  border="0" align="center" cellpadding="0" cellspacing="0">
      <tr class="unnamed1">
        <td width="3" class="unnamed2">&nbsp;</td>
        <td width="192" class="unnamed2"><div align="center"><strong>แก้ไข user name</strong></div></td>
		<td width="192" class="unnamed2"><div align="center"><strong>แก้ไข password</strong></div></td>
		<td width="192" class="unnamed2"><div align="center"><strong>แก้ไขชื่อโรงเรียน</strong></div></td>
		<td width="147"><div align="center">
            <input name="update" type="hidden" id="update" value="1">
        </div></td>
        <td width="150">&nbsp;</td>
		<td width="150">&nbsp;</td>
      </tr>
      <tr class="unnamed1">
        <td class="unnamed2">&nbsp;</td>
		

<?
	
	$sql="select * from emonitorplan_user where id=$showedit and status='school' order by username  ";
	//echo"$sql";
	$dbquery = mysql_db_query($dbname, $sql);
	$num_rows = mysql_num_rows($dbquery);
	$i=0;
	while ($i < $num_rows)
	{
		$result = mysql_fetch_array($dbquery);
		$idedit = $result[0];
		$usernameedit = $result[1];
		$passwordsedit = $result[2];
		$fullnameedit = $result[3];
		$i++;
	}
?>
			<td class="unnamed2"><div align="center">
				<input name="usernameedit" type="text" id="usernameedit" size="20" value="<? echo"$usernameedit"; ?>">&nbsp;&nbsp;
				
			</div></td>

			<td class="unnamed2"><div align="center">
				
				<input name="passwordsedit" type="text" id="passwordsedit" size="20" value="<? echo"$passwordsedit"; ?>">&nbsp;&nbsp;
				
			</div></td>

			<td class="unnamed2"><div align="center">
				
				<input name="fullnameedit" type="text" id="fullnameedit" size="20" value="<? echo"$fullnameedit"; ?>">&nbsp;&nbsp;
				<input name="idedit" type="hidden" id="idedit" value="<? echo"$idedit"; ?>">
			</div></td>
			
        
        <td><div align="center">
            <input type="submit" name="Submit" value="  บันทึกการแก้ไข    ">
        </div></td>
        <td><label>
          <input type="button" name="Button" id="button" value="ยกเลิก"  onClick="DoCancel()">
        </label></td>
      </tr>

    </table>
    <br>
</form>
  <? } ?>
<table width="400"  border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="#999999" bordercolordark="#FFFFFF">
<?

	if($search=='') {
		$sql="select  * from emonitorplan_user where  status='school' order by username";
	} else {
		$sql="select  * from emonitorplan_user where status='school' and username like '%$search%' or fullname like '%$search%' order by username ";
	}
	
//echo"$sql";
$i=0;
	$dbquery = mysql_db_query($dbname, $sql);
	$num_rows = mysql_num_rows($dbquery);
?>
  <tr class="unnamed1">
    <td colspan="6" class="unnamed2"><div align="right">มีข้อมูลจำนวน <b><? echo"$num_rows"; ?></b> รายการ </div></td>
  </tr>
  
 <tr bgcolor="c2e1fd" class="unnamed2">
	<td class="unnamed2"><div align="center" class="style3">แก้ไข</div></td>
	<td class="unnamed2"><div align="center" class="style4 style5">ลบ</div></td>
    <td class="unnamed1"><div align="center" class="style3">ลำดับ</div></td>
    <td class="unnamed1"><div align="center" class="style3">user name</div></td>
	<td class="unnamed1"><div align="center" class="style3">password</div></td>
	<td class="unnamed1"><div align="center" class="style3">ชื่อโรงเรียน</div></td>
  </tr>
<?	
	
	//echo"$sql";
	while ($i < $num_rows)
	{
		$result = mysql_fetch_array($dbquery);
		$id = $result[0];
		$username = $result[1];
		$passwords = $result[2];
		$fullname = $result[3];
		$i++;

 
  
if ($i%2==0) 
{
	?><tr bgcolor="d6dff7" class="unnamed1"><?
} else {
	?><tr bgcolor="ffffff" class="unnamed1"><?
} ?>
  <td><div align="center"><? echo"<A HREF='user.php?showedit=$id'>"; ?> <img src="images/b_edit.png" alt="edit" width="16" height="16" border="0"></a></div></td>
  <td><div align="center"><? echo"<A HREF='user.php?del=$id'>"; ?><img src="images/b_drop.png" alt="delete" width="16" height="16" border="0"></a></div></td>
    <td class="unnamed2"><div align="center"><? echo"$i"; ?></div></td>
    <td class="unnamed2"><div align="left">&nbsp;<? echo"$username"; ?></div></td>
	<td class="unnamed2"><div align="left">&nbsp;<? echo"$passwords"; ?></div></td>
	<td class="unnamed2"><div align="left">&nbsp;<? echo"$fullname"; ?></div></td>

  </tr>
<?

}
?>
  <tr class="unnamed1">
    <td colspan="6" class="unnamed2"><div align="right">มีข้อมูลจำนวน <b><? echo"$num_rows"; ?></b> รายการ </div></td>
  </tr>
</table>
<br>
<?


mysql_close();
?>

<br>
</body>
</html>
<script language="javascript">


function DoEdit(id)
{
			var sConfirm;
			sConfirm=confirm("             คุณต้องการแก้ไขข้อมูล ใช่หรือไม่ ?")
			if (sConfirm){
				 location.href("user.php?showedit="+id);
			}else{
				return false;
			}
}
function DoConfirm(id)
{
			var sConfirm;
			sConfirm=confirm("คุณต้องการลบข้อมูลนี้ ใช่หรือไม่?")
			if (sConfirm){
				 location.href("user.php?del="+id);
			}else{
				return false;
			}
}
function chkaddsumit()
{
	
		if(document.form1.username.value=="")
		{	alert("กรุณากรอก user name");
			document.form1.username.focus();
		} else if(document.form1.fullname.value=="")
		{
			alert("กรุณากรอก ชื่อโรงเรียน");
			document.form1.fullname.focus();	
		}else
		{
			document.form1.submit();
		}
}
function DoCancel()
{
	location.href("user.php");
}
</script>

Youez - 2016 - github.com/yon3zu
LinuXploit