403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/gpa/pk/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/gpa/pk/printb.php
<?
require_once "../config/confiteacher.inc.php";
?>

<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=tis-620">

<title>ฝ่ายบริหารงานวิชาการ/งานปกครอง</title>

</head>

<body onload="window.print()">
<?
require_once "../config/connectdb.php";
$year=date(" Y ")+542; 
//*** Update Condition ***//
if($_GET["Action"] == "Save")
{
	for($i=1;$i<=$_POST["hdnLine"];$i++)
	{
		$strSQL = "UPDATE transcripsactivi SET ";
		$strSQL .="gradeac = '".$_POST["txtgradeac$i"]."' ";
		$strSQL .="WHERE idacti = '".$_POST["hdnid$i"]."' ";
		
		$objQuery = mysql_query($strSQL);
	}
	//header("location:$_SERVER[PHP_SELF]");
	//exit();
}

$sql2="SELECT years FROM config";
$result2 = mysql_query($sql2);
while (list($years) = mysql_fetch_row($result2)) {
$xsc_years = $years;
$strSQL = "SELECT * FROM pkklw join klw ON klw.Username=pkklw.idspk WHERE dpk = '$_GET[id]' and idspk='$_GET[idspk]' ";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
$i = 1;

}





?>
<table width="773" border="0" align="center" cellpadding="0" cellspacing="0">
                <tr> 
                  <td width="198"><a href="regis.php"><font color="#FF0000" size="2"></font></a>
				  
				  
				  </td>
                  <td width="575"><table width="100%" border="0" cellspacing="1" cellpadding="1">
                     
                    </table></td>
                </tr>
              </table>
			  <center><img src="images/logo2.gif" width="140" height="140"></center>
<form name="frmMain" method="post" action="totalsave.php?Action=Save">
<table  width="100%" border="0" bgcolor="#999999">
 <center><font size='3' color='red'>แบบขออนุญาตออกนอกสถานศึกษา โรงเรียนกันทรลักษ์วิทยา 
 
 <br></font></center>
  
  <tr bgcolor="#FFFFFF">
    
	

  </tr>
<?
$i =0;

while($objResult = mysql_fetch_array($objQuery))

{
if($bg == "#FFFFFF") { //ส่วนของการ สลับสี 
$bg = "#FFFFFF";
} else {
$bg = "#FFFFFF";
}

	$i = $i + 1;
	$timepk =$objResult["timepk"];
	$idspk =$objResult["idspk"];
	$becos =$objResult["becos"];
	$unit=$scor1+$scor2+$scor3;
	$mid =$objResult["mid"];
	$prefix =$objResult["prefix"];
	$room =$objResult['room'];
	$name =$objResult['Name'];
	$surname =$objResult['surname'];
	$bpk =$objResult['bpk'];

	$cllass =$objResult['cllass'];
?>
  <tr>
    <td><div align="center">

				<?
											
				$crsql="SELECT tpy FROM pkklwtyp
				WHERE idtpy = '$bpk'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$becos1=$dcrd[0];

				
				$crsql="SELECT count(idspk) FROM pkklw
				WHERE bpk =1 and dpk='$_GET[id]'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$b1=$dcrd[0];


				$crsql="SELECT count(idspk) FROM pkklw
				WHERE bpk =2 and dpk='$_GET[id]'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$b2=$dcrd[0];


				$crsql="SELECT count(idspk) FROM pkklw
				WHERE bpk =3 and dpk='$_GET[id]'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$b3=$dcrd[0];

				$crsql="SELECT count(idspk) FROM pkklw
				WHERE bpk =4 and dpk='$_GET[id]'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$b4=$dcrd[0];

				$totalall=$b1+$b2+$b3+$b4;					
	             ?>

	
   

	
	
                                        

	
    
	
	

   



  </tr>
<?
	  $i = $i;
  }
  ?>
</table>
<br>ชื่อ&nbsp;&nbsp; <? echo "$prefix"; ?><? echo "$name"; ?> &nbsp;&nbsp;<? echo "$surname"; ?>&nbsp;&nbsp;เลขประจำตัวนักเรียน <? echo "$idspk"; ?>
<br>ชั้น ม.&nbsp;&nbsp;<? echo "$cllass"; ?> &nbsp;&nbsp;ห้อง<? echo "$room"; ?>
<br>มีความประสงค์ขออนุญาตออกนอกสถานศึกษาเนื่องจาก &nbsp;&nbsp; <? echo "$becos1"; ?>
<br>หมายเหตุ: <? echo "$becos"; ?>
<br>
<br>
<br><center>ลงชื่อ...................</center>
<br><center>ผู้ยื่นคำขอ</center>
<br><center><? echo $_GET[id]; ?></center>
</form>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit