403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/admissions3/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/admissions3/scor4.php
<?
	session_start();
	if($_SESSION['idt'] == "")
	{
		echo "Please Login!";
		exit();
	}

	if($_SESSION['Status'] != "ADMIN")
	{
		echo "This page for Admin only!";
		exit();
	}	
	
	mysql_connect("localhost","root","gpaklw+3322");
	mysql_select_db("klw");
	mysql_query("SET character_set_results=tis620");//ตั้งค่าการดึงข้อมูลออกมาให้เป็น tis620
	mysql_query("SET character_set_client=tis620");//ตั้งค่าการส่งข้อมุลลงฐานข้อมูลออกมาให้ เป็น tis620
	mysql_query("SET character_set_connection=tis620");//ตั้งค่าการติดต่อฐานข้อมูลให้เป็น tis6
	
	$strSQL = "SELECT * FROM teacher WHERE idt = '".$_SESSION['idt']."' ";
	$objQuery = mysql_query($strSQL);
	$objResult = mysql_fetch_array($objQuery);
?>
<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=tis-620">

<title>ฝ่ายบริหารงานวิชาการ</title>

</head>

<body>
<?
$objConnect = mysql_connect("localhost","root","gpaklw+3322") or die("Error Connect to Database");
$objDB = mysql_select_db("jorjae_jorjaedb");
mysql_query("SET character_set_results=tis620");//ตั้งค่าการดึงข้อมูลออกมาให้เป็น tis620
mysql_query("SET character_set_client=tis620");//ตั้งค่าการส่งข้อมุลลงฐานข้อมูลออกมาให้ เป็น tis620
mysql_query("SET character_set_connection=tis620");//ตั้งค่าการติดต่อฐานข้อมูลให้เป็น tis




//*** Update Condition ***//
if($_GET["Action"] == "Save")
{
	for($i=1;$i<=$_POST["hdnLine"];$i++)
	{
		$strSQL = "UPDATE member4 SET ";
		$strSQL .="idtest = '".$_POST["txtscor1$i"]."' ";
		$strSQL .="WHERE id = '".$_POST["hdnid$i"]."' ";
		$objQuery = mysql_query($strSQL);
	}
	//header("location:$_SERVER[PHP_SELF]");
	//exit();
}

$strSQL = "SELECT * FROM member4 where idstudent='$_GET[id]' and room!='' group by room order by room+1 asc ";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
$i = 1;

?>



<table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                <tr> 
                  <td width="198"><a href="homeadmin.php"><font color="#FF0000" size="2">หน้าหลัก</font></a>
				  <a href="../teacher/excel.php"><font color="#FF0000" size="2">Excel</font></a>
				  
				  </td>
                  <td width="575"><table width="100%" border="0" cellspacing="1" cellpadding="1">
                    </table></td>
                </tr>
              </table>
<form name="frmMain" method="post" action="idtest.php?Action=Save">
<table  width="100%" border="0" bgcolor="#999999">
  <tr bgcolor="#FFFFFF">
    <th width="10"> <div align="center"></div></th>
	 <th width="10"> <div align="center">#</div></th>
    <th width="200"> <div align="center">ช่วงคะแนน</div></th>
	 <th width="200"> <div align="center">คะแนน1</div></th>
    <th width="200"> <div align="center">คะแนน2</div></th>
	 <th width="200"> <div align="center">คะแนน3</div></th>
	 <th width="200"> <div align="center">คะแนน4</div></th>
	 <th width="200"> <div align="center">คะแนน5</div></th>
	  <th width="200"> <div align="center">คะแนน6</div></th>
	   <th width="200"> <div align="center">คะแนน7</div></th>
	    <th width="200"> <div align="center">คะแนน8</div></th>
		 <th width="200"> <div align="center">คะแนน9</div></th>
		  <th width="200"> <div align="center">MA1/กีฬา</div></th>
		   
		    <th width="200"> <div align="center">MA2/จีน</div></th>
			<th width="200"> <div align="center">MA2/tep</div></th>
			
			<th width="200"> <div align="center">print1</div></th>
			<th width="200"> <div align="center">ประมวลผล</div></th>
			
			<th width="200"> <div align="center">print2</div></th>
	
	 
  </tr>
<?
$i =0;
while($objResult = mysql_fetch_array($objQuery))
{
	$i = $i + 1;
	$idstudent = $objResult['idstudent'];
	$room = $objResult['room'];
?>
  <?
	$crsql="SELECT count(idstudent) FROM member4 where scor1>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score1=$dcrd[0];





	$crsql="SELECT count(idstudent) FROM member4 where scor2>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score2=$dcrd[0];


	$crsql="SELECT count(idstudent) FROM member4 where scor3>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score3=$dcrd[0];

	$crsql="SELECT count(idstudent) FROM member4 where scor4>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score4=$dcrd[0];


	$crsql="SELECT count(idstudent) FROM member4 where scor5>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score5=$dcrd[0];

	$crsql="SELECT count(idstudent) FROM member4 where scor6>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score6=$dcrd[0];


	$crsql="SELECT count(idstudent) FROM member4 where scor7>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score7=$dcrd[0];


	$crsql="SELECT count(idstudent) FROM member4 where scor8>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score8=$dcrd[0];

	$crsql="SELECT count(idstudent) FROM member4 where scor9>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score9=$dcrd[0];


	$crsql="SELECT count(idstudent) FROM member4 where scor10>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score10=$dcrd[0];

	$crsql="SELECT count(idstudent) FROM member4 where scor11>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score11=$dcrd[0];


	$crsql="SELECT count(idstudent) FROM member4 where scor12>0 and room='$room' and idstudent='$idstudent'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$score12=$dcrd[0];
 
?>
  
  <tr bgcolor="#FFFFFF"">
    <td><div align="center">
	<input type="hidden" name="hdnid<?=$i;?>" size="5" value="<?=$objResult["id"];?>">
	 <td><?=$i?></td>
	
	</div></td>
    <td><a href="scor445.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>">1</a>
	
	&nbsp;&nbsp;<a href="scor4x.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>">2</a>
	
	</td>
	<td><a href="scor41.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score1>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
	
	
	</td>
    <td><a href="scor42.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score2>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
	
	</td>
	<td><a href="scor43.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score3>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
	
	
	</td>
	<td><a href="scor44.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score4>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
	
	
	</td>
<td><a href="scor451.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score5>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
</td>



<td><a href="scor456.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score6>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
</td>

<td><a href="scor457.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score7>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
</td>

<td><a href="scor458.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score8>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
</td>


<td><a href="scor459.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score9>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
</td>


<td><a href="scor4510.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score10>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
</td>




<td><a href="scor4511.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score11>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
</td>

<td><a href="scor4512.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>"><? echo "$room"; ?></a>
	<? if($score12>0)
 {
  echo "ok";
 }
 else
 {
   echo "";
 }
?>
</td>

<td><a href="print.php?id=<? echo "$idstudent"; ?>&idr=<? echo "$room"; ?>">รวม</a></td>
	

<td>
<? if( $_GET[id]==5)
 {
  echo "<a href=psum4.php?id=$idstudent&idr=$room><span style=\"color: #0000FF;\">sum</span>";
 }
 else if($_GET[id]==6)
 {
   echo "<a href=psum4e.php?id=$idstudent&idr=$room><span style=\"color: #0000FF;\">sum</span>";
 }
 else
 {
   echo "<a href=psum4e.php?id=$idstudent&idr=$room><span style=\"color: #0000FF;\">sum</span>";
 }
?>


	
	
	</td>

<td>




<? if( $_GET[id]==5)
 {
  echo "<a href=psum4p.php?id=$idstudent&idr=$room><span style=\"color: #0000FF;\">print</span>";
 }
 else if($_GET[id]==6)
 {
   echo "<a href=psum4pe.php?id=$idstudent&idr=$room><span style=\"color: #0000FF;\">สรุปผล</span>";
 }
 else
 {
    echo "<a href=psum4pe.php?id=$idstudent&idr=$room><span style=\"color: #0000FF;\">สรุปผล</span>";
 }
?>





</td>

	

	 
	 
	 
<?
	  $i+1;
  }
  ?>
</table>
<?
mysql_close($objConnect);
?>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit