403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/gpa/homeroom/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/gpa/homeroom/cutgradex.php
<?
require_once "../config/confiteacher.inc.php";
require_once "../head.php";
$ttt=$objResult["teachcode"];

    $crsql="SELECT (years) FROM `config`" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $xyyyy=$dcrd[0];


	$crsql="SELECT (ku1) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $ku11=$dcrd[0];


	$crsql="SELECT (pu1) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $pu11=$dcrd[0];


	$crsql="SELECT (au1) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $au11=$dcrd[0];
    
	$unit1=$ku11+$pu11+$au11;
///////////////////////
	$crsql="SELECT (ku2) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $ku22=$dcrd[0];


	$crsql="SELECT (pu2) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $pu22=$dcrd[0];


	$crsql="SELECT (au2) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $au22=$dcrd[0];
 
	$unit2=$ku22+$pu22+$au22;
///////////////////////
	$crsql="SELECT (ku3) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $ku33=$dcrd[0];


	$crsql="SELECT (pu3) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $pu33=$dcrd[0];


	$crsql="SELECT (au3) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $au33=$dcrd[0];

	$unit3=$ku33+$pu33+$au33;

	///////////////////////
	$crsql="SELECT (ku4) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $ku44=$dcrd[0];


	$crsql="SELECT (pu4) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $pu44=$dcrd[0];


	$crsql="SELECT (au4) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $au44=$dcrd[0];
    
	$unit4=$ku44+$pu44+$au44;

///////////////////////
	$crsql="SELECT (ku5) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $ku55=$dcrd[0];


	$crsql="SELECT (pu5) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $pu55=$dcrd[0];


	$crsql="SELECT (au5) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $au55=$dcrd[0];

    $unit5=$ku55+$pu55+$au55;

	///////////////////////
	$crsql="SELECT (ku6) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $ku66=$dcrd[0];


	$crsql="SELECT (pu6) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $pu66=$dcrd[0];


	$crsql="SELECT (au6) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $au66=$dcrd[0];

    $unit6=$ku66+$pu66+$au66;

	///////////////////////
	$crsql="SELECT (midterm) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $midterm=$dcrd[0];


	$crsql="SELECT (final) FROM `registeacher`
	WHERE registeach = '$_GET[teachin]' and codeteach='$_GET[id]' and yearsxx='$xyyyy'" ;
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
    $final=$dcrd[0];


	$sumscore=$midterm+$final+$unit6+$unit5+$unit4+$unit3+$unit2+$unit1;
?>



<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=tis-620">

<title>ฝ่ายบริหารงานวิชาการ</title>

</head>

<body>
<?
require_once "../config/connectdb.php";
$year=date(" Y ")+542; 
//*** Update Condition ***//
if($_GET["Action"] == "Save")
{
	for($i=1;$i<=$_POST["hdnLine"];$i++)
	{
		$strSQL = "UPDATE transcripts SET ";
		$strSQL .="grad = '".$_POST["grade2$i"]."' ";
		$strSQL .=",k1 = '".$_POST["k2$i"]."' ";
		$strSQL .=",r1 = '".$_POST["r2$i"]."' ";
		$strSQL .="WHERE id = '".$_POST["hdnid$i"]."'";
		
		$objQuery = mysql_query($strSQL);
	}
	echo "รอสักครู Deleted.";
	echo "<script>window.alert(\"บันทึกข้อมูลเรียบแล้วครับ\");history.go (-1);</script>";
	//header("location:$_SERVER[PHP_SELF]");
	//exit();
}

$sql2="SELECT years FROM config";
$result2 = mysql_query($sql2);
while (list($years) = mysql_fetch_row($result2)) {
$xsc_years = $years;
$strSQL = "SELECT * FROM transcripts JOIN klw ON klw.Username=transcripts.IDstudent WHERE code = '$_GET[id]' and room = '$_GET[room]' and teach='$ttt' and xyy='$_GET[xyy]' order by room+1 asc,ordinal+1 asc";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
$i = 1;

}





?>
<table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                <tr> 
                  <td width="198"><a href="sentgpa.php"><font color="#FF0000" size="2">กลับ</font></a>
				  
				  
				  </td>
                  <td width="575"><table width="100%" border="0" cellspacing="1" cellpadding="1">
                     <form method="post" action="stat1.php"> <tr> 
                        <td><div align="center"><font color="#666666" size="2">ค้นหา 
                            : 
                            <input type=text name=txtsearch size=20 class=input>
                            <input name="searchtype" type="radio" value="room" checked>ห้อง
                              <input name="searchtype" type="radio" value="IDstudent" checked>รหัสนักเรียน
							<input name="Submit" type="submit" class="submitad" value="ค้นหา">
                            </font> </div></td>
                      </tr></form>
                    </table></td>
                </tr>
              </table>
<form name="frmMain" method="post" action="cutgradex.php?Action=Save">
<table  width="100%" border="0" bgcolor="#999999">
 <center><font size='3' color='red'>กด SAVE เท่านั้น</font></center>
  
  <tr bgcolor="#FFFFFF">
    <th width="10"> <div align="center"></div></th>
	 <th width="10"> <div align="center">#</div></th>
    <th width="10"> <div align="center">ID Student</div></th>
	<th width="10"> <div align="center">code</div></th>
	 <th width="100"> <div align="center">Name</div></th>
    <th width="10"> <div align="center">Unit 1 <br><? echo "$unit1"; ?></div></th>
	<th width="10"> <div align="center">Unit 2 <br><? echo "$unit2"; ?></div></th>
	<th width="10"> <div align="center">Unit 3 <br><? echo "$unit3"; ?></div></th>
	<th width="10"> <div align="center">กลางภาค <br><? echo "$midterm"; ?></div></th>
	<th width="10"> <div align="center">Unit 4 <br><? echo "$unit4"; ?></div></th>
	<th width="10"> <div align="center">Unit 5 <br><? echo "$unit5"; ?></div></th>
	<th width="10"> <div align="center">Unit 6 <br><? echo "$unit6"; ?></div></th>
	<th width="10"> <div align="center">ปลายภาค <br><? echo "$final"; ?></div></th>
	<th width="10"> <div align="center">รวมทั้งหมด  <br><? echo "$sumscore"; ?></div></th>
	<th width="10"> <div align="center">คำนวนเกรด</div></th>
	<th width="10"> <div align="center">ผลตัดสิน</div></th>
	<th width="10"> <div align="center">K</div></th>
	<th width="10"> <div align="center">R</div></th>
	
	

  </tr>
<?
$i =0;

while($objResult = mysql_fetch_array($objQuery))

{
if($bg == "#EEEEEE") { //ส่วนของการ สลับสี 
$bg = "#FFFFFF";
} else {
$bg = "#EEEEEE";
}

	$i = $i + 1;
	$scor1 =$objResult["scor1k"];
	$scor2 =$objResult["scor1p"];
	$scor3 =$objResult["scor1a"];
	$uni1 =$scor1+$scor2+$scor3;

	$scor4 =$objResult["scor2k"];
	$scor5 =$objResult["scor2p"];
	$scor6 =$objResult["scor2a"];
	$uni2 =$scor4+$scor5+$scor6;


	$scor7 =$objResult["scor3k"];
	$scor8 =$objResult["scor3p"];
	$scor9 =$objResult["scor3a"];
	$uni3 =$scor7+$scor8+$scor9;

	$mid =$objResult["mid"];

	$scor10 =$objResult["scor4k"];
	$scor11 =$objResult["scor4p"];
	$scor12 =$objResult["scor4a"];
	$uni4 =$scor10+$scor11+$scor12;


	$scor13 =$objResult["scor5k"];
	$scor14 =$objResult["scor5p"];
	$scor15 =$objResult["scor5a"];
	$uni5 =$scor13+$scor14+$scor15;


	$scor16 =$objResult["scor6k"];
	$scor17 =$objResult["scor6p"];
	$scor18 =$objResult["scor6a"];
	$uni6 =$scor16+$scor17+$scor18;


	$final=$objResult["final1"];

    $total=$uni1+$uni2+$uni3+$uni4+$uni5+$uni6+$mid+$final;
    $grade2=$objResult["grad"];
	$room =$objResult['room'];
	$ordinal =$objResult['ordinal'];

?>
  <tr bgcolor="<?=$bg?>">
    <td><div align="center">
	<input type="hidden" name="hdnid<?=$i;?>" size="5" value="<?=$objResult["id"];?>">
	 <td><?=$i?></td>
	<td><div align="right"><?=$objResult["Username"];?>
	</div></td>
	<td><div align="right"><?=$objResult["code"];?>
	</div></td>
   

	
	<td><div align="right"><?=$objResult["Name"];?>&nbsp;&nbsp;<?=$objResult["surname"];?>&nbsp;&nbsp;<? echo "$room"; ?></div></td>
                                        

	
	
	<td><? echo "$uni1"; ?></td>
	<td><? echo "$uni2"; ?></td>
	<td><? echo "$uni3"; ?></td>
	<td><? echo "$mid"; ?></td>
	<td><? echo "$uni4"; ?></td>
	<td><? echo "$uni5"; ?></td>
	<td><? echo "$uni6"; ?></td>
	<td><? echo "$final"; ?></td>
	<td><? echo "$total"; ?></td>
	
	<td><input type="text" name="grade2<?=$i;?>" size="3" maxlength="4" value="
<? 

if($total<50 and $grade2 != 'ร')
 {
   echo "0";
 }
 else if($total < 55 and $grade2!='ร')
 {
   echo "1";
 }
 else if($total < 60 and $grade2!='ร')
 {
   echo "1.5";
 }
  else if($total < 65 and $grade2!='ร')
 {
   echo "2";
 }
 else if($total < 70 and $grade2!='ร')
 {
   echo "2.5";
 }
  else if($total < 75 and $grade2!='ร')
 {
   echo "3";
 }
 else if($total < 80 and $grade2!='ร')
 {
   echo "3.5";
 }
 else if($total > 79 and $grade2!='ร')
 {
   echo "4";
 }
 else if($total>0 or $grade2=='ร')
 {
   echo "ร";
 }
?>
" >
</td>


<td><? echo "$grade2"; ?></td>

<td><input type="text" name="k2<?=$i;?>" size="3" maxlength="2" value="

<? if($total < 59)
 {
   echo "1";
 }
 else if($total < 69)
 {
   echo "2";
 }
 else
 {
   echo "3";
 }
?>
" >
</td>


<td><input type="text" name="r2<?=$i;?>" size="3" maxlength="2" value="

<? if($total < 59)
 {
   echo "1";
 }
 else if($total < 69)
 {
   echo "2";
 }
 else
 {
   echo "3";
 }
?>
" >
</td>






  </tr>
<?
	  $i = $i;
  }
  ?>
</table>
  <input type="submit" name="submit" value="SAVE">
  <input type="hidden" name="hdnLine" value="<?=$i;?>">
</form>
<?
?>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit