403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/gpa/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/gpa//reportuploadsente.php
<html>
<head>
<?
require_once "head.php";
include('confiteacher.inc.php');  //ไฟล์เชื่อมต่อกับ database ที่เราได้สร้างไว้ก่อนหน้าน
$teach=$objResult["teachcode"];
?>
<title>ThaiCreate.Com Tutorial</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf8">
</head>
<body>

<?php
	$objConnect = mysql_connect("localhost","root","klw3322") or die("Error Connect to Database");
	$objDB = mysql_select_db("klw");
	mysql_query("SET NAMES utf8");
	$strSQL = "SELECT * FROM uploadfile join teacher on teacher.teachcode=uploadfile.upteach  where reportup='$_GET[at]' and grupsara='$_GET[id1]'";
	$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
?>



<?

$crsql="SELECT uploadsent FROM uploadfileseting WHERE idset='$_GET[at]'";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$namereport=$dcrd[0];	

$crsql="SELECT linkmenu FROM menu WHERE idmenu=6";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$subject9=$dcrd[0];


$crsql="SELECT linkmenu FROM menu WHERE idmenu=2";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$subject2=$dcrd[0];


$crsql="SELECT linkmenu FROM menu WHERE idmenu=10";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$recode=$dcrd[0];

$crsql="SELECT linkmenu FROM menu WHERE idmenu=11";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$recod2=$dcrd[0];

$crsql="SELECT linkmenu FROM menu WHERE idmenu=12";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$file=$dcrd[0];

$crsql="SELECT linkmenu FROM menu WHERE idmenu=13";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$stat=$dcrd[0];

$crsql="SELECT linkmenu FROM menu WHERE idmenu=14";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$com=$dcrd[0];


$crsql="SELECT linkmenu FROM menu WHERE idmenu=15";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$com15=$dcrd[0];

$crsql="SELECT linkmenu FROM menu WHERE idmenu=16";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$com16=$dcrd[0];


$crsql="SELECT linkmenu FROM menu WHERE idmenu=17";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$com17=$dcrd[0];

$crsql="SELECT linkmenu FROM menu WHERE idmenu=18";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$com18=$dcrd[0];

$crsql="SELECT linkmenu FROM menu WHERE idmenu=19";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$com19=$dcrd[0];


$crsql="SELECT linkmenu FROM menu WHERE idmenu=20";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$com20=$dcrd[0];





?>


<tr> 
    <td bgcolor="#FFFFFF"><table width="100%" border="0" cellspacing="1" cellpadding="1">
        
        <tr> 
          <td><div align="right"><font color="#666666" size="2"><a href="main.php">index</a> 
              | <a href="logout.php">log out</a></font></div></td>
        </tr>
        <tr> 
          <td><div align="center">
              <table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                <tr> 
                  
                </tr>
              </table>
              <table width="76%" border="0" align="center" cellpadding="1" cellspacing="1">
                <tr> 
                  <td>&nbsp;</td>
                </tr>
                <tr>
                  <td><div align="center"> 


					
					
					
					
					
					</div>


</td>
  </tr><? echo "$namereport"; ?>
  <table>
M1/M2
  <table>
<table width="100%" border="0" bgcolor="#999999">
<tr bgcolor="EEEEEE">
<th width="50"> <div align="center">#</div></th>
<th width="50"> <div align="center"><? echo $recode?></div></th>
<th width="50"> <div align="center"><? echo $recod2?></div></th>
<th width="150"> <div align="center"><? echo $file?> </div></th>
<th width="150"> <div align="center"><? echo $com18?> </div></th>

<th width="150"> <div align="center">Files comment</div></th>
<th width="150"> <div align="center"><? echo $com?> </div></th>
<th width="150"> <div align="center"><? echo $stat?> </div></th>
<th width="150"> <div align="center">KPA</div></th>
<th width="150"> <div align="center"><? echo $com19?> </div></th>
<th width="150"> <div align="center"><? echo $com20?> </div></th>


</tr>


<?php
$i =0;
	while($objResult = mysql_fetch_array($objQuery))
	{
        $registestt=$objResult[registest];
		$registest=$objResult[check1];
		$registest9=$objResult[check9];
		$registime=$objResult[registime];
		$fileID=$objResult[fileID];
if($bg == "#EEEEEE") { //ส่วนของการ สลับสี 
$bg = "#FFFFFF";
} else {
$bg = "#EEEEEE";
}
$i = $i + 1;
?>
	
<?
$crsql="SELECT datcom1 FROM uploadfile WHERE fileID='$fileID'";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$datsign=$dcrd[0];


$crsql="SELECT name FROM teacher WHERE teachcode='$registestt'";
$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
$dcrd = mysql_fetch_array($slr);
$nametest=$dcrd[0];


?>
<tr bgcolor="<?=$bg?>">
<td><div align="center"><?=$i?> <a href=delupa.php?id=<?php echo $objResult["fileID"];?> onClick="return confirm ('you ')"><img src=images/delete.png width=22 height=22 border=0 alt=ลบข้อมูล></a></div></td>
<td><div align="center"><a href=print/indexup2.php?id=<?php echo $objResult["fileID"];?>><?php echo $objResult["teachcode"];?>&nbsp;&nbsp;<?php echo $objResult["name"];?>&nbsp;&nbsp;<?php echo $objResult["lastname"];?></a>
&nbsp;&nbsp;&nbsp;&nbsp;
<a href=print/indexup.php?id=<?php echo $objResult["fileID"];?>> &nbsp;&nbsp;signature&nbsp;&nbsp;<?php echo $objResult["teachcode"];?></a>


</div></td>
<td><center><a href="./uploadadmin/fileupload/<?php echo $objResult["fileuplaod3"];?>" target='_blank'><?php echo $objResult["fileuplaod3"];?></a>&nbsp;&nbsp;<a href=uploadadmin/index2.php?id=<?php echo $objResult["fileID"];?>>up</a></center></td>

<td><center><a href="upload/fileupload/<?php echo $objResult["fileupload"];?>" target='_blank'><?php echo $objResult["fileupload"];?></a></center>
<? if($registest9==1)
 {
   echo "<span style=\"color: #DD0000;\">$com15</span><br>"; 
 }
 else if($registest9==2)
 {
 echo "<span style=\"color: #DD0000;\">$com16</span><br>"; 
 }

  else if($registest9==3)
 {
 echo "<span style=\"color: #DD0000;\">$com17</span><br>"; 
 }
?>







</td>
<td><div align="center"><?php echo $objResult["unitup"];?></div></td>

<td><center><a href="./uploadadmin/fileupload/<?php echo $objResult["fileuplaod2"];?>" target='_blank'><?php echo $objResult["fileuplaod2"];?></a></center></td>
<td><center><a href=uploadadmin/index.php?id=<?php echo $objResult["fileID"];?>>upload</a></center></td>
<td><div align="center"> 


<?php echo $nametest;?>

<? if($registest>=1)
 {
   echo "<span style=\"color: #DD0000;\">check pass</span><br>"; 
 }
 else if($registest<1)
 {
   echo "";
 }
?>

<?php echo $objResult["registime"];?>


</div></td>

<td><div align="center"><a href=editcomment.php?id=<?php echo $objResult["fileID"];?>>KPA</a></div></td>
<td><center><a href=comment1/index.php?id=<?php echo $objResult["fileID"];?>>comment</a>



<? if($datsign>=1)
 {
   echo "<span style=\"color: #DD0000;\">check ok</span><br>"; 
 }
 else if($datsign<1)
 {
   echo "";
 }
?>




</center></td>
<td><center><a href=comment2/index.php?id=<?php echo $objResult["fileID"];?>>comment</a></center></td>


</tr>
<?
	  $i = $i;
  }
  ?>
</table>


</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit