403Webshell
Server IP : 202.29.229.35  /  Your IP : 18.117.8.176
Web Server : Apache
System : Linux aapanel2 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User : www ( 1001)
PHP Version : 5.5.38
Disable Function : passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /www/wwwroot/www.ivecr2.ac.th/system_admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /www/wwwroot/www.ivecr2.ac.th/system_admin/pdNews.php
<?php 
	/*session_start();
	include('connect/connect.php');
	include('connect/function.php');
*/	
	
if($_SESSION['r_statuslogin'] != 1){
 echo '<script language="javascript">alert("สำหรับผู้ดูแลระบบเท่านั้น")</script>';
 echo'<meta http-equiv="refresh" content="0;url=../index.php">';
 exit();
}
	
					$adminid=$_SESSION['r_adID'];
					$wrokID=$_SESSION['r_workId'];
					echo "---++".$wrokID."**".$adminid;
					
					$queryperlogin = "select * from tbl_datatecher1 where tecNumber='$adminid' ";
					$resultperlogin=mysqli_query($connect1,$queryperlogin);
					$rsperteclogin=mysqli_fetch_assoc($resultperlogin);
					
					$tecPrefixThailogin=$rsperteclogin['tecPrefixThai'];//คำนำหน้าชื่อ
					$selectworklogin = $rsperteclogin['selectwork'];//กลุ่มงาน
					//คำนำหน้าชื่อ
					$sqlpflogin="select * from ref_prefix_name where PREFIX_NAME_ID=$tecPrefixThai";
					$resulpflogin=mysqli_query($connect1,$sqlpflogin);
					$rspflogin=mysqli_fetch_assoc($resulpflogin);
					$tecPrefixThaiorilogin=$rspflogin['FULLNAME'];
					
					//ชื่อกลุ่มงาน
						$sqlworklogin="select * from tbl_departmentall where daNodpt='$selectworklogin' ";
						$resqlworklogin=mysqli_query($connect1,$sqlworklogin);
						$rsworklogin=mysqli_fetch_assoc($resqlworklogin);
						$worknamelogin = $rsworklogin['daFname'];
						
   						$tecnamelogin=$tecPrefixThaiorilogin."&nbsp;".$rsperteclogin['tecFnameThai']."&nbsp;&nbsp;".$tecLnamelogin=$rsperteclogin['tecLnameThai']." (".$worknamelogin.")";
	?>
<html>
<head>
<title>ThaiCreate.Com Tutorial</title>
<!------------------text editor------------------------->
  <script type="text/javascript" src="ckeditor/ckeditor.js"></script>
  
<link rel="stylesheet" type="text/css" href="style.css" />
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css">
body {
	margin-left: 0px;
}
</style>
<script src="SpryAssets/SpryValidationTextField.js" type="text/javascript"></script>
<link href="SpryAssets/SpryValidationTextField.css" rel="stylesheet" type="text/css">
</head>

<body>

      <form action="?i=pdNews_insert" method="post" enctype="multipart/form-data" name="form1" id="form1">
        <table width="800" border="0" align="center" cellpadding="5" cellspacing="5">
          <tr>
            <td colspan="3" align="center" valign="top"><h1>.:: เขียนข่าวประชาสัมพันธ์ ::.</h1></td>
          </tr>
          <tr>
            <td align="right" valign="top">หัวข่าวประกาศ :</td>
            <td width="296" colspan="2" align="left" valign="top"><label for="title"></label>
              <span id="sprytextfield1">
              <input name="title" type="text" id="title" size="60" maxlength="100">
            <span class="textfieldRequiredMsg">*ใส่หัวข้อข่าว...</span></span><font color="#FF0000">*</font></td>
          </tr>
          <tr>
            <td colspan="3" align="center" valign="top">&nbsp;</td>
          </tr>
          <tr>
            <td colspan="3" align="center" valign="top"><table width="800" border="0" cellspacing="0" cellpadding="5">
              <tr>
                <td width="100" align="right" valign="top">ชื่อไฟล์1:</td>
                <td width="300" align="left" valign="top"><input name="Titlefile1" type="text" id="Titlefile1" size="45" maxlength="90"></td>
                <td width="100" align="right" valign="top">แนบไฟล์ 1:</td>
                <td width="300"><input name="filUpload1" type="file" id="filUpload1" />
                  <font color="#FF0000">*.pdf </font></td>
              </tr>
              <tr>
                <td width="100" align="right" valign="top">ชื่อไฟล์2:</td>
                <td width="300" align="left" valign="top"><input name="Titlefile2" type="text" id="Titlefile2" size="45" maxlength="90"></td>
                <td width="100" align="right" valign="top">แนบไฟล์ 2:</td>
                <td width="300"><input name="filUpload2" type="file" id="filUpload2">
                  <font color="#FF0000">*.pdf </font></td>
              </tr>
              <tr>
                <td width="100" align="right" valign="top">ชื่อไฟล์:3</td>
                <td width="300" align="left" valign="top"><input name="Titlefile3" type="text" id="Titlefile3" size="45" maxlength="90"></td>
                <td width="100" align="right" valign="top">แนบไฟล์ 3:</td>
                <td width="300"><input name="filUpload3" type="file" id="filUpload3">
                  <font color="#FF0000">*.pdf </font></td>
              </tr>
              <tr>
                <td width="100" align="right" valign="top">ชื่อไฟล์4:</td>
                <td width="300" align="left" valign="top"><input name="Titlefile4" type="text" id="Titlefile4" size="45" maxlength="90"></td>
                <td width="100" align="right" valign="top">แนบไฟล์ 4:</td>
                <td width="300"><input name="filUpload4" type="file" id="filUpload4">
                  <font color="#FF0000">*.pdf</font></td>
              </tr>
              <tr>
                <td width="100" align="right" valign="top">ชื่อไฟล์5:</td>
                <td width="300" align="left" valign="top"><input name="Titlefile5" type="text" id="Titlefile5" size="45" maxlength="90"></td>
                <td width="100" align="right" valign="top">แนบไฟล์ 5:</td>
                <td width="300"><input name="filUpload5" type="file" id="filUpload5">
                  <font color="#FF0000">*.pdf</font></td>
              </tr>
            </table></td>
          </tr>
          <tr>
            <td colspan="3" align="center" valign="top">&nbsp;</td>
          </tr>
          <tr>
            <td colspan="3" align="left" valign="top"><font color="#FF0000">** หมายเหตุ ถ้าแนบไฟล์จะต้องตั้งชื่อให้กับไฟล์ด้วยทุกครั้ง**</font></td>
          </tr>
          <tr>
            <td colspan="3" align="center" valign="top"><strong>.:: รายละเอียดข่าว 
(โดยสังเขป) ::.</strong></td>
          </tr>
          <tr>
            <td colspan="3" align="center" valign="top"><textarea class="ckeditor" cols="80" id="detail" name="detail" rows="10"></textarea>
            <font color="#FF0000">*</font></td>
          </tr>
          <tr>
            <td align="right" valign="top">เขียนโดย :</td>
            <td colspan="2" align="left" valign="top"><?php echo $tecnamelogin;?></td>
          </tr>
          <tr>
            <td align="right" valign="top">&nbsp;</td>
            <td colspan="2" align="left" valign="top">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;
              <input type="submit" name="Submit" value="Submit" />
              &nbsp;&nbsp;
              <input type="reset" name="Submit2" value="Reset" /></td>
          </tr>
        </table>
</form>
      <p>&nbsp;</p>
      <p>&nbsp; </p>
      <?php 
					if($wrokID == 1 || $wrokID == 5){
					$sql="select * from tbl_dpnews order by dpN_ID desc";
					}else{
					$sql="select * from tbl_dpnews where dp_ID='$adminid' order by dpN_ID desc";
					}
					$result=mysqli_query($connect1,$sql);
					$num_cd=mysql_num_rows($result);
					
?>
      <table width="700" border="0" align="center" cellpadding="5" cellspacing="0">
        <tr>
          <td height="28" colspan="4" align="center" valign="middle"><B>ข่าวประชาสัมพันธ์ ทั้งหมด&nbsp;&nbsp;
            <?php  echo $num_cd;?>
            &nbsp;&nbsp;ข่าว</B></td>
        </tr>
        <tr>
          <td width="20" height="28" align="center" valign="middle" bgcolor="#EBEBEB">&nbsp;</td>
          <td colspan="2" align="center" valign="middle" bgcolor="#EBEBEB">ข่าวประชาสัมพันธ์</td>
          <td width="227" align="center" valign="middle" bgcolor="#EBEBEB">วันที่อัพไฟล์</td>
        </tr>
        <?php
					while($rs=mysqli_fetch_assoc($result)){
					$dp_ID=$rs['dp_ID'];
						
					$queryper = "select * from tbl_datatecher1 where tecNumber='$dp_ID' ";
					//echo $queryper;
					$resultper=mysqli_query($connect1,$queryper);
					$rspertec=mysqli_fetch_assoc($resultper);
					
					$tecPrefixThai=$rspertec['tecPrefixThai'];//คำนำหน้าชื่อ
					$selectwork = $rspertec['selectwork'];//กลุ่มงาน
					//คำนำหน้าชื่อ
					$sqlpf="select * from ref_prefix_name where PREFIX_NAME_ID=$tecPrefixThai";
					$resulpf=mysqli_query($connect1,$sqlpf);
					$rspf=mysqli_fetch_assoc($resulpf);
					$tecPrefixThaiori=$rspf['FULLNAME'];
					
						//ชื่อกลุ่มงาน
						$sqlwork="select * from tbl_departmentall where daNodpt='$selectwork' ";
						$resqlwork=mysqli_query($connect1,$sqlwork);
						$rswork=mysqli_fetch_assoc($resqlwork);
						$workname = $rswork['daFname'];
						
   						$tecname=$tecPrefixThaiori."&nbsp;".$rspertec['tecFnameThai']."&nbsp;&nbsp;".$tecLname=$rspertec['tecLnameThai']." (".$workname.")";
			
					
							
					if($bg == "#F5F5F5") {
						$bg = "#FDFDFD";
					} else {
						$bg = "#F5F5F5";
					}
					
		  ?>
        <tr bgcolor="<?php echo $bg?>"  >
          <td width="20" align="center" valign="middle" bgcolor="<?php echo $bg?>"><img src="images/icon07.png" width="20" height="12" /></td>
          <td width="530" align="left" valign="middle" bgcolor="<?php echo $bg?>"><a href="?i=pdNews_Showdetail&dpN_ID=<?php echo $rs['dpN_ID'];?>"><?php echo $rs['dpN_Title'];?> <font color="#0099FF" size="-2"><br><i>โดย : <?php echo $tecname;?></i></font></a></td>
          <td width="18" align="center" valign="top" bgcolor="<?php echo $bg?>"><a href="index.php?i=pdNews_delete&dpN_ID=<?php echo $rs['dpN_ID'];?>"><img src="images/33333.jpg" width="18" height="16" border="0" /></a></td>
          <td width="227" align="left" valign="top" bgcolor="<?php echo $bg?>">เมื่อ :: <?php echo displaydate($rs['dpN_Date'])//."  ".$rs['dpN_Time'];?></td>
        </tr>
        <?php
								$num--;
				}
				
		  ?>
      </table>
      <p>&nbsp;</p>
<script type="text/javascript">
var sprytextfield1 = new Spry.Widget.ValidationTextField("sprytextfield1");
</script>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit