403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/gpa/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/gpa//showinstall1.php
<?

require_once "config/connectdb.php";
require_once "head.php";
?>
						<?php
						  $sql_1="select * from  config";
						  $db_query=mysql_db_query($db,$sql_1);
						  $result1=mysql_fetch_array($db_query);
						  $idmember  =$result1['idsc'];
						  $namesc  =$result1['namesc'];
						   $tumbolsc  =$result1['tumbolsc'];
						    $amps =$result1['amps'];
							$dissc  =$result1['dissc'];
							$years  =$result1['years'];
							$termx  =$result1['termx'];


									
						  ?>


						  


<html>
<head>
<title>-:- ADMIN -:-</title>
<meta http-equiv="Content-Type" content="text/html; charset=tis-620">
<link href="style.css" rel="stylesheet" type="text/css">
</head>

<body bgcolor="#FFFFFF"  onLoad="javascript:document.getElementById('useradmin').focus();">
<table width="100%" border="0" align="center" cellpadding="0" cellspacing="0">
  
  <tr> 
    <td bgcolor="#FFFFFF"><table width="100%" border="0" cellspacing="1" cellpadding="1">
        <tr> 
          
        </tr>
        <tr> 
          <td><div align="right"><font color="#666666" size="2"><a href="index.php">หน้าหลักระบบ</a> 
           </font></div></td>
        </tr>
        <tr> 
          <td><div align="center">
              <table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                <tr> 
                  
                  <td width="575"><table width="100%" border="0" cellspacing="1" cellpadding="1">
                      <form method="post" action="searchstudent.php">
                        <tr> 
                          <td><div align="center"><font color="#666666" size="2">ค้นหา 
                              : 
                              <input type=text name=txtsearch size=20 class=input>
                              <input name="searchtype" type="radio" value="IDstudent" checked>เลขประจำตัว
                              
                           
                              <input name="Submit" type="submit" class="submitad" value="ค้นหา">
                              </font> </div></td>
                        </tr>
                      </form>
                    </table></td>
                </tr>
                <tr> 


                  
                </tr>
              </table>
              <table width="100%" border="0" align="center" cellpadding="1" cellspacing="1">
                <tr> 
                  <td><table width="100%" border="0" align="center" cellpadding="0" cellspacing="0">
                      <tr class="jobscss"> 
                        <td bgcolor="#FFFFFF"> <table width="100%" border="0" cellspacing="0" cellpadding="0">
                            <tr> 
                              <td bgcolor="#000000"><table width="100%" border="0" cellspacing="1" cellpadding="1">
                                  <tr bgcolor="#006666"> 
                                    <td width="10" height="24"> <div align="center"><font color="#FFFFFF" size="2">#</font></div></td>
                                    <td width="10"> <div align="center"><font color="#FFFFFF" size="2">เลขประจำตัว</font></div></td>
                                    <td width="100"><div align="center"><font color="#FFFFFF" size="2">ชื่อ </font></div></td>
									<td width="10"><div align="center"><font color="#FFFFFF" size="2">ช้ัน </font></div></td>
									<td width="20"><div align="center"><font color="#FFFFFF" size="2">ห้อง</font></div></td>
									<td width="55"><div align="center"><font color="#FFFFFF" size="2">1.</font></div></td>
									<td width="55"><div align="center"><font color="#FFFFFF" size="2">2.</font></div></td>
									<td width="55"><div align="center"><font color="#FFFFFF" size="2">3.</font></div></td>
									<td width="55"><div align="center"><font color="#FFFFFF" size="2">4</font></div></td>
									<td width="55"><div align="center"><font color="#FFFFFF" size="2">5.</font></div></td>
									<td width="55"><div align="center"><font color="#FFFFFF" size="2">6.</font></div></td>
									
									
									<td width="55"> <div align="center"><font color="#FFFFFF" size="2">วิชา ขาด/เกิน</font></div></td>
                                  </tr>
                                </table></td>
                            </tr>
                          </table>
                          <?
$page = $_GET['page'];
$num = 1;
$select_type="select cllass,Username ,room,sex from klw

where room >0 and cllass='$_GET[id]' order by cllass asc,sex asc,Username asc, cllass asc, room+1 asc ";
$query_select=mysql_query($select_type);
$num_rows=mysql_num_rows($query_select);
if($num_rows<1){
echo "<br><br><center><font color=#666666 face=tahoma size=2>ไม่พบข้อมูลทีี่ท่านค้นหาค่ะ</font></center>";
}else{
		$select="select cllass,Username,room,sex from klw where room >0 and cllass='$_GET[id]' order by cllass asc,sex asc,Username asc, cllass asc, room+1 asc";
		$q_ry = mysql_query($select);
	 	$num_rows=mysql_num_rows($q_ry);
  		$pagesize=900;
		$rt=$num_rows%$pagesize;
		if($rt!=0)
			{
				$totalpage=floor($num_rows/$pagesize)+1;
			}
		else
			{
				$totalpage=floor($num_rows/$pagesize);
				$toppic_id=1;
			}
		if(empty($page))
			{
				$page=1;
			}
		mysql_free_result($q_ry);
		$goto=($page-1)*$pagesize;
$sql_select_mem="Select * from klw JOIN configinstall ON
 klw.cllass=configinstall.configclass

where room >0 and room<18 and cllass='$_GET[id]'   order by cllass asc,room+1 asc,ordinal+1 asc limit $goto,$pagesize";
		$fect=mysql_query($sql_select_mem);
		if(!$fect)
		{
		("ติดต่อฐานข้อมูลไม่ได้".mysql_error());
		exit;
		}

	  $bgcount=0;
	while($rows=mysql_fetch_array($fect))
	{
$idmember =$rows['UserID'];
$Username  =$rows['Username'];
$prefix =$rows['prefix'];
$Name =$rows['Name'];
$surname =$rows['surname'];
$cllass =$rows['cllass'];
$room =$rows['room'];
$ordinal =$rows['ordinal'];
$codin =$rows['codin'];
$configclass =$rows['configclass'];
$configinstall =$rows['configinstall'];
	?>

<?
									$crsql="SELECT codin FROM `transcriptintall`
									WHERE idstin = '$Username' and yearsx='$years' and termx='$termx'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_0=$dcrd[0];


									$crsql="SELECT teachin FROM transcriptintall
									WHERE idstin = '$Username' and yearsx='$years' and termx='$termx' and codin='$slipnum_0'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$teach1=$dcrd[0];


									$crsql="SELECT name FROM teacher
									WHERE teachcode = '$teach1'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$nameteach1=$dcrd[0];
									


///////////////////////////////////////////////
									
									$crsql="SELECT codin FROM `transcriptintall`
									WHERE idstin = '$Username' and codin!='$slipnum_0' and yearsx='$years' and termx='$termx'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_2=$dcrd[0];


									$crsql="SELECT teachin FROM transcriptintall
									WHERE idstin = '$Username' and yearsx='$years' and termx='$termx' and  codin='$slipnum_2' ";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$teach2=$dcrd[0];


									$crsql="SELECT name FROM teacher
									WHERE teachcode = '$teach2'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$nameteach2=$dcrd[0];

									
									
	//////////////////////////////////////////////								
									$crsql="SELECT codin FROM `transcriptintall`
									WHERE idstin = '$Username' and codin!='$slipnum_0' and codin!='$slipnum_2' and yearsx='$years ' and termx='$termx'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_3=$dcrd[0];



									$crsql="SELECT teachin FROM transcriptintall
									WHERE idstin = '$Username' and yearsx='$years' and termx='$termx' and codin='$slipnum_3' ";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$teach3=$dcrd[0];


									$crsql="SELECT name FROM teacher
									WHERE teachcode = '$teach3'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$nameteach3=$dcrd[0];


									

//////////////////////////////////////////////////////////////
									$crsql="SELECT codin FROM `transcriptintall`
									WHERE idstin = '$Username' and codin!='$slipnum_0' and codin!='$slipnum_2' and codin!='$slipnum_3' and yearsx='$years' and termx='$termx'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_4=$dcrd[0];

									$crsql="SELECT teachin FROM transcriptintall
									WHERE idstin = '$Username' and yearsx='$years' and termx='$termx' and  codin='$slipnum_4'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$teach4=$dcrd[0];


									$crsql="SELECT name FROM teacher
									WHERE teachcode = '$teach4'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$nameteach4=$dcrd[0];


									
////////////////////////////////////////////////////

									$crsql="SELECT codin FROM `transcriptintall`
									WHERE idstin = '$Username' and codin!='$slipnum_0' and codin!='$slipnum_2' and codin!='$slipnum_3' and codin!='$slipnum_4' and yearsx='$years' and termx='$termx'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_5=$dcrd[0];


									$crsql="SELECT teachin FROM transcriptintall
									WHERE idstin = '$Username' and yearsx='$years' and termx='$termx' and codin='$slipnum_5'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$teach5=$dcrd[0];


									$crsql="SELECT name FROM teacher
									WHERE teachcode = '$teach5'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$nameteach5=$dcrd[0];


/////////////////////////////////////////////////
									$crsql="SELECT codin FROM `transcriptintall`
									WHERE idstin = '$Username' and codin!='$slipnum_0' and codin!='$slipnum_2' and codin!='$slipnum_3' and codin!='$slipnum_4' and codin!='$slipnum_5' and yearsx='$years' and termx='$termx'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_6=$dcrd[0];

									$crsql="SELECT teachin FROM transcriptintall
									WHERE idstin = '$Username' and yearsx='$years' and termx='$termx' and codin='$slipnum_6'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$teach6=$dcrd[0];


									$crsql="SELECT name FROM teacher
									WHERE teachcode = '$teach6'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$nameteach6=$dcrd[0];



									///////////////////////////
									


									$crsql="SELECT codin FROM `transcriptintall`
									WHERE idstin = '$Username' and codin!='$slipnum_0' and codin!='$slipnum_2' and codin!='$slipnum_3' and codin!='$slipnum_4' and codin!='$slipnum_5' and codin!='$slipnum_6' and yearsx='$years' and termx='$termx'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_7=$dcrd[0];


									$crsql="SELECT totals FROM `configregis`
									WHERE configri = '$cllass' and configro='$room'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$totalin=$dcrd[0];
									?>






<?
$sql3="SELECT configri,configro,totals FROM configregis where configri='$cllass' and configro='$room'";
$result3 = mysql_query($sql3);
while (list($configri,$configro,$totals) = mysql_fetch_row($result3)) {
$c1 = $configri;
$c2  = $configro;
$c3=$totals;
}

?>


									 


									


								


                          <table width="100%" border="0" cellspacing="0" cellpadding="0">
                            <tr> 
                              <td bgcolor="#000000"><table width="100%" border="0" cellspacing="1" cellpadding="1">
                                  <tr bgcolor="#FFFFFF"> 
                                    <td width="20" height="24"> <div align="center"><font color="#990000" size="2"><? echo "$num"; ?></font></div></td>
                                    <td width="10"><font color="#003366" size="2"><? echo "$Username"; ?></font><br> <div align="left"></div></td>
                                     
									 <td width="100"><font color="#003366" size="2"><? echo "$prefix"; ?><? echo "$Name"; ?>&nbsp;&nbsp;<? echo "$surname"; ?></font></td>
									<td width="10"><font color="#003366" size="2"><? echo "$cllass"; ?></font></td>
									<td width="10"><font color="#003366" size="2"><? echo "$room"; ?></font></td>
                              <td width="55"><font color="#003366" size="2">
									
									
									
						<? echo "$slipnum_0"; ?>&nbsp;&nbsp;<? echo "$nameteach1"; ?>				
					       </font>
</td>
									 <td width="55"><font color="#003366" size="2">
									 
									 
									
<? echo "$slipnum_2"; ?>	&nbsp;&nbsp;<? echo "$nameteach2"; ?>			
									 
									 
									 
									 
									 
									 </font></td>
									  <td width="55"><font color="#003366" size="2">
									  
									 
									
<? echo "$slipnum_3"; ?>	&nbsp;&nbsp;<? echo "$nameteach3"; ?>			
									  
									  
									  
									  
									  
									  </font></td>
									   <td width="55"><font color="#003366" size="2">
									   
									  
									
<? echo "$slipnum_4"; ?>	&nbsp;&nbsp;<? echo "$nameteach4"; ?>			
									   
									   
									   
									   
									   
									   
									   </font></td>
									    <td width="55"><font color="#003366" size="2">
										
										
									
<? echo "$slipnum_5"; ?>&nbsp;&nbsp;<? echo "$nameteach5"; ?>			
									   
										
										
										
										
										
										</font></td>
										<td width="55"><font color="#003366" size="2">
										
										
									
<? echo "$slipnum_6"; ?>		&nbsp;&nbsp;	<? echo "$nameteach6"; ?>	
									   
										
										
										
										
										
										</font></td>

										
										
									<td width="55"><font color="#003366" size="2">
									<?
									$crsql="SELECT count(idstin) FROM `transcriptintall`
									WHERE  idstin = '$Username' and yearsx='$years ' and termx='$termx' ";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_00=$dcrd[0];


									$crsql="SELECT count(configro) FROM `configregis`
									WHERE  configri = '$_GET[id]' and configro='$room' ";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$showroom=$dcrd[0];




									$install=$totalin-$slipnum_00;
									







									?>&nbsp;

<? if($showroom>=1)
 {
   echo "$install";
 }
 else if($showroom <1)
 {
   echo "";
 }
 else
 {
   echo "";
 }

 
?>




									
									
									
									</font></td>
                                  </tr>
                                </table></td>
                            </tr>

							
                          </table>
                          <?
$num = $num+1;
}
echo "<div align=center><br>
                    <font color=#999999 size=2><span class=cc> ";
	for($i=1;$i<$page;$i++)
	{
	echo"<a href='$PHP_SELF?page=$i'><font size=2 color='#000000' class=textborder>$i</font></a> ";
	}
	echo"<font size=2 color=#000000><b><font size=2 color='#FF00000' class=textborderok>$page</font></b></font> ";
	for($i=$page+1;$i<=$totalpage;$i++)
	{
	echo"<a href='$PHP_SELF?page=$i'><font size=2 color='#000000' class=textborder>$i</font></a> ";
	}
echo "</span></font> </div>";
}
?>
                        </td>
                      </tr>
                      <tr class="jobscss"> 
                        <td height="19">&nbsp;</td>
                      </tr>
                      <tr> 
                        <td><div align="center"></div></td>
                      </tr>
                    </table></td>
                </tr>
              </table>
            </div></td>
        </tr>
        <tr>
          <td>&nbsp;</td>
        </tr>
      </table></td>
  </tr>
  <tr>
    <td><div align="center"><? echo "<font size=2 color=#ffffff>$footerweb</font>"; ?></div></td>
  </tr>
</table>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit