403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/admissions3/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/admissions3/psum4pe.php
<?
	session_start();
	if($_SESSION['idt'] == "")
	{
		echo "Please Login!";
		exit();
	}

	if($_SESSION['Status'] != "ADMIN")
	{
		echo "This page for Admin only!";
		exit();
	}	
	
	mysql_connect("localhost","root","klw3322");
	mysql_select_db("klw");
	mysql_query("SET character_set_results=tis620");//ตั้งค่าการดึงข้อมูลออกมาให้เป็น tis620
	mysql_query("SET character_set_client=tis620");//ตั้งค่าการส่งข้อมุลลงฐานข้อมูลออกมาให้ เป็น tis620
	mysql_query("SET character_set_connection=tis620");//ตั้งค่าการติดต่อฐานข้อมูลให้เป็น tis6
	
	$strSQL = "SELECT * FROM teacher WHERE idt = '".$_SESSION['idt']."' ";
	$objQuery = mysql_query($strSQL);
	$objResult = mysql_fetch_array($objQuery);
?>
<html>
<head>

<meta http-equiv=Content-Type content="homeadmin.php; charset=tis-620">

<title>ฝ่ายบริหารงานวิชาการ</title>

</head>

<body>
<?
$objConnect = mysql_connect("localhost","root","klw3322") or die("Error Connect to Database");
$objDB = mysql_select_db("jorjae_jorjaedb");
mysql_query("SET character_set_results=tis620");//ตั้งค่าการดึงข้อมูลออกมาให้เป็น tis620
mysql_query("SET character_set_client=tis620");//ตั้งค่าการส่งข้อมุลลงฐานข้อมูลออกมาให้ เป็น tis620
mysql_query("SET character_set_connection=tis620");//ตั้งค่าการติดต่อฐานข้อมูลให้เป็น tis




//*** Update Condition ***//
if($_GET["Action"] == "Save")
{
	for($i=1;$i<=$_POST["hdnLine"];$i++)
	{
		$strSQL = "UPDATE member4 SET ";
		$strSQL .="totalsum = '".$_POST["txtscor1$i"]."' ";
		$strSQL .="WHERE id = '".$_POST["hdnid$i"]."' ";
		$objQuery = mysql_query($strSQL);
	}

	echo "รอสักครู .";
	echo "<script>window.alert(\"บันทึกข้อมูลเรียบแล้วครับ\");history.go (-2);</script>";
	//header("location:$_SERVER[PHP_SELF]");
	//exit();
}

$strSQL = "SELECT * FROM member4 where idstudent='$_GET[id]' and room>0 order by totalsum+1 desc ";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
$i = 1;
?>
<table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                <tr> 
                  <td width="198"><font color="#FF0000" size="2">ประเภท&nbsp;&nbsp;<?echo "$_GET[id]"; ?>&nbsp;&nbsp;ห้อง&nbsp;&nbsp;<?echo "$_GET[idr]"; ?></font>
				  
				  
				  </td>
                  <td width="575"><table width="100%" border="0" cellspacing="1" cellpadding="1">
                    </table></td>
                </tr>
              </table>
<form name="frmMain" method="post" action="psum4e.php?Action=Save">
<table  width="100%" border="0" bgcolor="#999999">
  <tr bgcolor="#FFFFFF">
    <th width="10"> <div align="center"></div></th>
	 <th width="10"> <div align="center">#</div></th>
    <th width="10"> <div align="center">ID klw</div></th>
	<th width="10"> <div align="center">ID Student</div></th>
	 <th width="50"> <div align="center">Name </div></th>
	 <th width="10"> <div align="center">Room</div></th>
    <th width="10"> <div align="center">1</div></th>
	<th width="10"> <div align="center">2</div></th>
	<th width="10"> <div align="center">3</div></th>
	<th width="10"> <div align="center">4</div></th>
	<th width="10"> <div align="center">5</div></th>
	<th width="10"> <div align="center">6</div></th>
	<th width="10"> <div align="center">7</div></th>
	<th width="10"> <div align="center">8</div></th>
	<th width="10"> <div align="center">9</div></th>
	<th width="10"> <div align="center">10</div></th>
	<th width="10"> <div align="center">รวม</div></th>
	<th width="10"> <div align="center">M1</div></th>
	<th width="10"> <div align="center">M2</div></th>
	<th width="10"> <div align="center">รวม M</div></th>
	<th width="10"> <div align="center">ผล</div></th>
	<th width="10"> <div align="center">ร.ร.</div></th>
	<th width="10"> <div align="center">แผน</div></th>
	<th width="10"> <div align="center">pin</div></th>
	<th width="10"> <div align="center">เพศ</div></th>
	
	
  </tr>
<?
$i =0;
while($objResult = mysql_fetch_array($objQuery))
{
	$i = $i + 1;
	////////////////////////
	$thai=$objResult["thaio"];
	$math=$objResult["matno"];
	$sci=$objResult["scio"];
	$eng=$objResult["eng0"];
	$pan=$objResult["pan"];
	$idstudents=$objResult["idstudents"];
   ///////////////////////////////
	$scoronet=$thai+$math+$sci+$eng;
	@$onet=$scoronet/400*100;
	@$onet30=(30/100)*$onet;
     
	$gpa=$objResult["gpa"];
	$gpam=$objResult["gpam"];
	$gpasi=$objResult["gpasi"];
	$gpae=$objResult["gpae"];
	$schoolout=$objResult["schoolout"];
	$pin=$objResult["pin"];
	$sex=$objResult["sex"];
	$teachid=$objResult["teachid"];



	$totalsum=$objResult["totalsum"];


    
   

	$sc1=$objResult["scor1"];
	$ss1=@$sc1/1;
		
	$sc2=$objResult["scor2"];
	$ss2=@$sc2/1;

	$sc3=$objResult["scor3"];
	$ss3=@$sc3/1;

	$sc4=$objResult["scor4"];
	$ss4=@$sc4/1;


	$sc5=$objResult["scor5"];
	$ss5=@$sc5/1;

	$sc6=$objResult["scor6"];
	$sc7=$objResult["scor7"];
	$sc8=$objResult["scor8"];
	$sc9=$objResult["scor9"];
	$sc10=$objResult["scor10"];
	$sc11=$objResult["scor11"];
	$sc12=$objResult["scor12"];

	$total=$ss1+$ss2+$ss3+$ss4+$ss5+$sc6+$sc7+$sc8+$sc9+$sc10;

	$totalmat=$sc11+$sc12;

	$totalall=$total+$totalmat;


	$crsql="SELECT (idtest1) FROM student where pinid='$pin'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$idtest1=$dcrd[0];

?>
  <tr bgcolor="#FFFFFF"">
    <td><div align="center">
	<input type="hidden" name="hdnid<?=$i;?>" size="5" value="<?=$objResult["id"];?>">
	 <td><?=$i?></td>
	
	</div></td>
	 <td><?echo "$idtest1"; ?></td>
    <td><?=$objResult["idtest"];?></td>
	<td align="right"><?=$objResult["prefix"];?><?=$objResult["name"];?> <?=$objResult["surname"];?></td>
	<td><?=$objResult["room"];?></td>
<td><?echo "$ss1"; ?></td>
<td><?echo "$ss2"; ?></td>
<td><?echo "$ss3"; ?></td>
<td><?echo "$ss4"; ?></td>
<td><?echo "$ss5"; ?></td>
<td><?=$objResult["scor6"];?></td>
<td><?=$objResult["scor7"];?></td>
<td><?=$objResult["scor8"];?></td>
<td><?=$objResult["scor9"];?></td>

<td><?=$objResult["scor10"];?></td>
<td><?echo "$total"; ?></td>
<td><?=$objResult["scor11"];?></td>
<td><?=$objResult["scor12"];?></td>
<td><?echo "$totalmat"; ?></td>
<td> <?echo "$totalsum"; ?></td>
<td> <?echo "$schoolout"; ?> </td>
<td> <?echo "$pan"; ?> </td>
<td> <?echo "$pin"; ?> </td>
<td> <?echo "$teachid"; ?> </td>


	  
<?
	  $i+1;
  }
  ?>
</table>
  
</form>
<?
mysql_close($objConnect);

?>
</body>
</html>


Youez - 2016 - github.com/yon3zu
LinuXploit