403Webshell
Server IP : 172.67.187.206  /  Your IP : 162.159.115.41
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  E:/Inetpub/www/myschool/triamudom/check/webadmin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : E:/Inetpub/www/myschool/triamudom/check/webadmin/display_student.php
<?php
session_start();
$path = "../";
include ($path.'include/config_db.php');
include ($path.'include/class_db.php'); 
include ($path.'include/class_display.php'); 
include ($path.'include/function.php'); 
include ($path.'include/permission_denied.php'); 
$CLASS['db']   = new db();
$CLASS['db']->connect(); 
$CLASS['disp']   = new display();
$db   = $CLASS['db']; 
$disp   = $CLASS['disp']; 

$link_value = $_REQUEST['link_value'];
$keyword = $_REQUEST['keyword'];
$link_value = "&keyword=".$keyword;

$del_id = $_REQUEST['del_id'];
$process = $_REQUEST['process'];
$tb_student_id = $_REQUEST['tb_student_id'];
$tb_student_degree = $_REQUEST['tb_student_degree'];
$tb_student_code = $_REQUEST['tb_student_code'];

if($process=="status0"){
	$db->query("update tb_students set tb_student_status='0' where tb_student_id='".$tb_student_id."' ");
}
if($process=="status1"){
	$db->query("update tb_students set tb_student_status='1' where tb_student_id='".$tb_student_id."' ");
}

if($process=="del"){
	$q=$db->query("select  tb_student_picture from tb_students where tb_student_id='".$del_id."'");
	$rec=$db->fetch_array($q);
	unlink("../file_student/".$rec['tb_student_picture']);

	$delete_time = $db->query("DELETE FROM tb_times WHERE tb_time_stucode = '".$tb_student_code."' ");
	
	$delete_rule = $db->query("DELETE FROM tb_rules WHERE tb_student_id = '".$tb_student_id."' ");
	
	$delete_sdq = $db->query("DELETE FROM tb_sdq WHERE tb_student_id = '".$tb_student_id."' ");
	$delete_sdqp = $db->query("DELETE FROM tb_sdq_parent WHERE tb_student_id = '".$tb_student_id."' ");
	
	$delete_act = $db->query("DELETE FROM tb_registers WHERE tb_student_id = '".$tb_student_id."' ");
	$delete_actlog = $db->query("DELETE FROM tb_act_logs WHERE tb_student_id = '".$tb_student_id."' ");
	
	$delete_know = $db->query("DELETE FROM tb_registers_knowledge WHERE tb_student_id = '".$tb_student_id."' ");
	$delete_knowlog = $db->query("DELETE FROM  tb_knowledge_logs WHERE tb_student_id = '".$tb_student_id."' ");

	$delete_vol = $db->query("DELETE FROM tb_volunteer WHERE tb_student_id = '".$tb_student_id."' ");
	$delete_vollog = $db->query("DELETE FROM  tb_volunteer_logs WHERE tb_student_id = '".$tb_student_id."' ");
	
	
	
	$db->query("delete from tb_students where tb_student_id='".$del_id."' ");
	print "
	<script language='javascript'>
	   alert('ลบข้อมูลเรียบร้อยแล้ว');
		window.location.href='".$_SERVER['PHP_SELF']."';
	</script>
	";
}

//----------------------------ค่าพื้นฐานระบบเว็บไซต์-----------------------------//
$fetch_public = $db->fetch_array($db->query("select * from tb_public"));
//----------------------------ค่าพื้นฐานระบบเว็บไซต์-----------------------------//

//--------------------ส่วนบนใช้สำหรับประกาศตัวแปรและ Config เท่านั้น----------------------------//
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title><?php print $fetch_public['tb_public_title_admin'];?></title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<link href="css/style_admin.css" rel="stylesheet" type="text/css">
<SCRIPT type="text/javascript"  src="js/format.js"></SCRIPT>
<SCRIPT type="text/javascript"  src="js/global.js" ></SCRIPT>
<SCRIPT type="text/javascript"  src="js/dtree.js"  ></SCRIPT>
<SCRIPT type="text/javascript" src="../include/souc_java.js"></SCRIPT>
</HEAD>
<BODY>
<TABLE width=100% height="100%" border=0 cellPadding=0 cellSpacing=0>
	<tbODY>
		<TR>
			<TD width=100% height=100 align="left" vAlign=top ><?php include_once('header_admin.php'); ?></TD>
		</TR>
		<TR height="100%" >
		  <TD width="100%" height="100%" vAlign=top>
				<TABLE cellSpacing=0 cellPadding=0 width="100%" border=0 >
					<tbODY>
						<TR>
						<TD width=200 rowSpan=2 vAlign=top id=nav><?php include_once('left_nav.php'); ?></TD>
							<TD width=3 height=1 bgcolor="#f1f1f1"><img src="images/spacer.gif" width="3" height="1"></TD>
						  <TD width="100%" rowSpan=2 align="left" vAlign=top style="PADDING-LEFT: 3px; PADDING-RIGHT: 0px;">							
								<table cellspacing="0" cellpadding="0" width="100%" border="0">
								  <tbody>
									<tr>
									  <td rowspan="2"><img src="images/i_setup.gif" width="65" height="44" border="0"></td>
									  <td width="100%" height="24">&nbsp;</td>
									  <td>&nbsp;</td>
									</tr>
									<tr>
									  <td  align="left" width="100%" 
										  background="images/bg_part.gif"><B><font color="#000000">เข้าระบบโดย : <?php print $_SESSION['sessionadmin_name'];?>  <?php print $_SESSION['sessionadmin_sername'];?></font></B></td>
									  <td><img src="images/end_part.gif" width="25" height="20"></td>
									</tr>
								 </tbody>
								</table>
            				</br>
            				<table width="99%" border="0" align="center" cellpadding="3" cellspacing="1" bgcolor="#666666" class="km_bgtable">
                              <tr>
                                <td height="30" colspan="9" valign="middle" bgcolor="#FFFFFF" class="b-texthead">
                                  <table width="100%" border="0" cellspacing="0" cellpadding="3">
								  <form id="form1" name="form1" method="post" action="<?php $_SERVER['PHP_SELF'];?>">
                                    <input name="keyword" type="hidden" value="<?php print $keyword;?>" />
                                    <tr>
                                      <td nowrap="nowrap"><img src="images/add.gif" alt="เพิ่มข้อมูลนักเรียน" width="16" height="16" border="0" align="absmiddle" /> <a href="display_student_add.php"><strong>เพิ่มข้อมูลนักเรียน</strong></a></td>
                                      <td align="right" nowrap="nowrap">ค้นหาข้อมูลชื่อนักเรียน <span class="headtopic"> :
                                          <input name="keyword" type="text" class="textbox" id="keyword" value="<?php print $keyword;?>" />
                                          <strong>
                                          <select name="tb_student_degree" class="textbox" id="tb_student_degree">
                                            <option value="">= เลือกระดับชั้น =</option>
                                            <?php $query_room=$db->query("select * from tb_rooms where tb_room_status ='1' order by tb_room_id asc");
									while($fetch_room=$db->fetch_array($query_room)){
									?>
                                            <option value="<?php echo $fetch_room['tb_room_id'];?>" <?php if($tb_student_degree == $fetch_room['tb_room_id']){echo "selected";}?>><?php echo $fetch_room['tb_room_name'];?></option>
                                            <?php } ?>
                                          </select>
                                          </strong>                                      </span>
                                        <input name="send" type="submit" class="textbox"  id="send" style="cursor:hand" value="ค้นหา" />
&nbsp;</td>
                                    </tr>
									</form>
                                  </table>                                </td>
                              </tr>
                              <tr>
                                <td width="6%" height="30" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">ลำดับที่</td>
                                <td width="7%" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">รหัสประจำตัว</td>
                                <td width="11%" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">เลขประจำตัวประชาชน</td>
                                <td width="14%" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">ชื่อ - สกุล </td>
                                <td width="22%" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">ที่อยู่</td>
                                <td width="14%" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">เบอร์โทร</td>
                                <td width="8%" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">ระดับชั้น</td>
                                <td width="9%" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">สถานะ</td>
                                <td width="9%" align="center" valign="middle" nowrap="NOWRAP" bgcolor="#A2A2A2" class="headTable_mpt">การจัดการ</td>
                              </tr>
                              <?php
										  $page_size = 50;
										  if ($PAGE =="" || $PAGE =="0" ) { 
											 $PAGE=1; 
										  }
										$goto = ($PAGE-1)*$page_size;	
										$limit = "limit  $goto , $page_size";
										if($keyword){
											$sql_search .=" and tb_student_name like '%".$keyword."%' ";
										}
										if($keyword){
											$sql_search .=" or tb_student_sname like '%".$keyword."%' ";
										}
										if($tb_student_degree){
											
											$sql_search .=" and tb_student_degree = '".$tb_student_degree."' ";
										}
										$sql =  "select * from tb_students where 1=1 $sql_search order  by tb_student_degree asc,tb_student_tname asc,tb_student_code asc,tb_student_degree asc ".$limit;				  
										$sql_all="select * from tb_students where 1=1  $sql_search order by tb_student_degree asc,tb_student_tname asc,tb_student_code asc,tb_student_degree asc";
										$query_dis = $db->query($sql);
										$queryall = $db->query($sql_all);
										$numrows = $db->num_rows($queryall);
										if($numrows >0){
											$i=1;
											while($fetch_dis = $db->fetch_array($query_dis)){
														if($i%2=="1"){
															$bg="rowone";
														}else{
															$bg="rowtwo";
														}
										?>
                              <tr class="<?php echo $bg;?>">
                                <td height="25" align="center" valign="top" nowrap="NOWRAP"><?php print $i+$goto;?>.</td>
                                <td align="center" valign="top" nowrap="NOWRAP"><?php print $fetch_dis['tb_student_code'];?></td>
                                <td align="center" valign="top" nowrap="NOWRAP"><?php print $fetch_dis['tb_student_idcard'];?></td>
                                <td height="25" align="left" valign="top" nowrap="NOWRAP">&nbsp;<?php print display_nametype($fetch_dis['tb_student_tname']);?><?php print $fetch_dis['tb_student_name'];?> <?php print $fetch_dis['tb_student_sname'];?><a href="../file_student/<?php print $fetch_dis['tb_student_picture'];?>" target="_blank"><img src="images/admins.gif" border="0" align="absmiddle" /></a></td>
                                <td align="center" valign="top"><?php print $fetch_dis['tb_student_address'];?></td>
                                <td align="center" valign="top" nowrap="NOWRAP"><?php print $fetch_dis['tb_student_phone'];?></td>
                                <td align="center" valign="top" nowrap="NOWRAP"><?php print $disp->display_roomname($fetch_dis['tb_student_degree']);?></td>
                                <td align="center" valign="top" nowrap="NOWRAP"><?php 
								  		if($fetch_dis['tb_student_status']=='1'){
								  ?>
                                  <a href="<?php print $_SERVER['PHP_SELF'];?>?process=status0&&tb_student_id=<?php print $fetch_dis['tb_student_id']?>"><img src="images/check.gif" alt="ใช้งาน" width="16" height="16" border="0" align="absmiddle" /></a>
                                  <?php }else{?>
                                  <a href="<?php print $_SERVER['PHP_SELF'];?>?process=status1&&tb_student_id=<?php print $fetch_dis['tb_student_id']?>"><img src="images/check_gray.gif" alt="ไม่ใช้งาน" width="14" height="14" border="0" align="absmiddle" /></a>
                                  <?php }?></td>
                                <td align="center" valign="top" nowrap="NOWRAP"><a href="#" onClick="new_win_def_prot('display_student_edit_pop.php?tb_student_id=<?php print $fetch_dis['tb_student_id']?>','select',800,400,0,0)"><img src="images/document_edit.gif" alt="แก้ไขข้อมูล" border="0" align="absmiddle" /></a>  <a href="<?php print $_SERVER['PHP_SELF'];?>?process=del&del_id=<?php print $fetch_dis['tb_student_id']?>&&tb_student_code=<?php print $fetch_dis['tb_student_code']?>" onclick="return confirm('คุณต้องการที่จะลบข้อมูลนี้หรือไม่ ?');"><img src="images/document_delete.gif" alt="ลบข้อมูล" width="16" height="16" border="0" align="absmiddle" /></a></td>
                              </tr>
                              <?php
											$i++;
											}
										?>
                              <tr>
                                <td height="25" colspan="9" bgcolor="#FFFFFF"><table width="100%" border="0" cellspacing="0" cellpadding="3">
                                    <tr>
                                      <td width="50%">หน้า : <?php print $disp->ctrl_page_design_limit_show($sql_all ,10,$page_size,"red","blue","/",$link_value);?></td>
                                      <td width="50%" align="right" nowrap="nowrap">จำนวน <?php print number_format($numrows);?> รายการ</td>
                                    </tr>
                                </table></td>
                              </tr>
                              <?php
											}else{
										?>
                              <tr>
                                <td height="25" colspan="9" bgcolor="#FFFFFF"><div align="center" class="red_text"><strong>ไม่พบข้อมูล</strong></div></td>
                              </tr>
                              <?php 
												}
										  ?>
                            </table></TD>
						</TR>
        				<TR>
          					<TD height=100% vAlign=top background="images/vline.gif">
          						<IMG src="images/h1_.gif" width="8" height="100" id=ctrlMnu style="CURSOR: hand" onClick="ShowHidePanel('nav', 'ctrlMnu')" onMouseOver="this.style.filter='alpha(opacity=65);'" onMouseOut="this.style.filter='alpha(opacity=100);'"></TD>
						</TR>
					</tbODY>
				</TABLE>		  </TD>
		</TR>
		<TR height="100%" >
		  <TD height="30" vAlign=bottom><?php include_once('footer.php'); ?></TD>
	  </TR>
	</tbODY>
</TABLE>
</BODY>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit