Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /var/www/html/manage/Car_depart/ drwxr-xr-x |
Viewing file: Select action/file-type: <?php session_start(); /** Define Validate Access */ define( '_VALID_ACCESS', 1 ); /** Check Session User Login */ if( !session_is_registered("valid_user") && !session_is_registered("Priority") ) { echo "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=windows-874\" />"; echo "<p style=padding-top:115px><p align=center><br /><font color=red><strong>กรุณาทำการ Login ก่อน</strong></font></p></p>"; echo "<meta http-equiv=\"refresh\" content=\"1; URL=../login.php\" />"; exit(); } else { /** Configuration */ require_once( "../configuration.php" ); require_once( $_Config_absolute_path . "/includes/framework.php" ); require_once( "../include/Function.php" ); require_once( "../include/FunctionDB.php" ); require_once( "../calendar/check.php" ); require_once( "../calendar/cal_func.php" ); /** Create Database Object */ $dbObj = new DBConn; //=== SESSION $Username = $valid_user; /** Config Table for This Page */ $myTable1 = "personal_tb"; $myTable2 = "formcaroffice"; $myTable3 = "project_tb"; $myTable4 = "training_tb"; $myTable5 = "autocar_tb"; /** Table --> personal_tb */ $query = " SELECT *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId WHERE Teacher_code='$Teacher_code' "; $result = $dbObj->execQuery($query); $rss = $dbObj->fetchArray($result); //$Teacher_code = $rss['Teacher_code']; /** Table --> tech_plan_tb */ $query1 = " SELECT * FROM $myTable2 WHERE carId='$carId' "; $result1 = $dbObj->execQuery($query1); $rs1 = $dbObj->fetchArray($result1); /** Table --> techplan_method_tb */ $query2 = " SELECT * FROM $myTable3 WHERE codeId='$codeId' "; $result2 = $dbObj->execQuery($query2); $rs2 = $dbObj->fetchArray($result2); /** Table --> tech_spec_tb */ $query5 = " SELECT * FROM $myTable5 WHERE carId='$carId' "; $result5 = $dbObj->execQuery($query5); $rs5 = $dbObj->fetchArray($result5); } # else ?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-874" /> <link href="../css/default.css" rel="stylesheet" type="text/css" /> <link href="../css/calendar.css" rel="stylesheet" type="text/css" /> <script language="javascript" src="../js/utilities.js"></script> <script type="text/javascript" src="../js/calendarDateInput2.js"></script> <title>MIS-การขอใช้รถยนต์</title> </head> <body topmargin="0" rightmargin="0" bottommargin="0" leftmargin="0"> <?php include("../templates/incHeaderCar.php"); ?> <table width="1003" border="0" cellspacing="0" cellpadding="0"> <tr> <td width="203" align="left" valign="top" style="padding:10px 0px 0px 5px"><?php include("./_incMainMenu.php");?></td> <td width="800" height="440" align="center" valign="top" style="padding:10px 0px 5px 10px"><fieldset> <table width="99%" border="0" cellspacing="0" cellpadding="0"> <form id="pc" name="pc" method="post" action="SaveEditCar.php"> <tr> <td width="783" height="5"></td> </tr> <tr> <td height="30" background="../images/background/bg-head-topic-w780.gif" class="PADDING-LEFT-10"><strong><a href="index.php">หน้าหลัก</a></strong> <strong>» <a href="PersonalFrom.php">แบบฟอร์ราชการ</a> » <span class="NOTE">ใบขออนญาตใช้รถยนต์ของทางราชการ</span></strong></td> </tr> <tr> <td> </td> </tr> <tr> <td><span class="PADDING-TOP-10"><img src="../images/icons/arrow-circle-225-left.png" width="16" height="16" border="0" align="absmiddle" /> <a href="javascript:;" onclick="window.history.back();"><strong>‹ ย้อนกลับ</strong></a></span></td> </tr> <tr> <td align="center"> <?php ?> <table width="758" border="0" align="center" cellpadding="0" cellspacing="3"> <tr height="31"> <td height="31" colspan="6" align="center" class="PATRON11">ใบขออนญาตใช้รถยนต์ของทางราชการ</td> </tr> <tr height="29"> <td height="18" colspan="6">เลขที่ <?=$rs1['CarNo'];?> <?php $collegeCode = $rss["collegeCode"]; $sql = "Select * From college Where collegeStatus ='1'"; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); ?> <input name="Teacher_code" type="hidden" id="Teacher_code" value="<? echo $rss["Teacher_code"]?>" /> </td> </tr> <tr height="29"> <td height="18" colspan="3" align="left">ส่วนราชการ <?=$rs2["collegeName"];?></td> <td height="18" colspan="3" align="center"> <?php echo dateThai($rs1['Date']); ?> </td> </tr> <tr height="29"> <td height="23" colspan="3" align="left">เรื่อง <input name="Da " type="text" id="Da " style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="ขอใช้รถยนต์ราชการ" size="20" readonly/> </td> <td width="92"></td> <td width="234"></td> <td width="76"></td> </tr> <tr height="29"> <td height="29" colspan="5" align="left">เรียน ผู้อำนวยการ <font size="2" face="Tahoma"> <?php $collegeCode = $rss["collegeCode"]; $sql = "Select * From college Where collegeStatus ='1'"; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); echo "$rs2[collegeName] "; ?> </font></td> <td> <? /** Table --> personal_tb */ //$query = " SELECT * FROM $myTable1 WHERE Teacher_code='$Teacher_code' "; //$result = $dbObj->execQuery($query); // $rss = $dbObj->fetchArray($result); $Teacher_code = $rss['Teacher_code']; ?> </td> </tr> <tr height="29"> <td width="172" height="25"></td> <td colspan="5" align="left">ข้าพเจ้า<font color="#0000FF" size="2" face="Tahoma"> <input name="Name" type="text" id="Name" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? echo $rss[First_name]?> <? echo $rss[Teacher_name]?> <? echo $rss[Teacher_lastname]?> " size="30" readonly="readonly" /> </font> ตำแหน่ง. <input name="Name2" type="text" id="Name2" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value=" <? $PositionId = $rss["PositionId"]; $sql = "Select * From position_tb Where PositionId ='$PositionId' "; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); echo "$rs2[Position_name] ";?> " size="20" readonly="readonly" /> </td> </tr> <tr height="29"> <td height="29" colspan="6" align="left"><label>ขออนุญาตใช้รถยนต์ไปราชการที่<font color="#0000FF" size="2" face="Tahoma"> <input name="makeWord" type="text" id="makeWord" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<?=$rs1["makeWord"]; ?>" size="60" readonly="readonly"/> </font><font color="#0000FF" size="2" face="Tahoma"> <input name="code" type="hidden" id="code" /> </font> <font face="Tahoma">จังหวัด</strong><font color="#003366" size="2" face="Tahoma"></font><font face="Tahoma"><font color="#003366" size="2" face="Tahoma"> <select name="provinceId" id="provinceId" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" > <?php $strSQL3 = " SELECT * FROM province "; $result3 = mysql_query($strSQL3); while( $rs3 = mysql_fetch_array($result3) ) { ?> <option value="<?=$rs3['provinceId'];?>" <?php if( $rs3['provinceId']==$rs1['provinceId'] ) echo 'selected'; ?>> <?=$rs3['provinceName'];?> </option> <?php } # while ?> </select> </font></font></font></label></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">เพื่อ<font color="#0000FF" size="2" face="Tahoma"> <input name="Training_name" type="text" id="Training_name" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? echo $rs1["Training_name"]; ?>" size="80" readonly="readonly"/> </font><font face="Tahoma"><span class="style14">ผู้ร่วมเดินทาง </span></font><font color="#0000FF" size="2" face="Tahoma"> <input name="Make" type="text" id="Make" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? echo $rs1["Make"]; ?>" size="2" readonly="readonly" /> </font><font face="Tahoma"><span class="style14">คน</span></font></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">หมายเหตุ<font color="#0000FF" size="2" face="Tahoma"> <input name="Detail" type="text" id="Detail" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? echo $rs1["Detail"]; ?>" size="100" readonly="readonly" /> </font></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">ประเภทในการขอใช้รถยนต์ <input type="radio" name="Training_type" value="1" <? if ($rs1["Training_type"] == 1) echo "checked"; ?> /> การอบรม <input type="radio" name="Training_type" value="2" <? if ($rs1["Training_type"] == 2) echo "checked"; ?> /> การศึกษาดูงาน <input type="radio" name="Training_type" value="3" <? if ($rs1["Training_type"] == 3) echo "checked"; ?> /> ประชุม <input type="radio" name="Training_type" value="4" <? if ($rs1["Training_type"] == 4) echo "checked"; ?> /> สัมมนา <input type="radio" name="Training_type" value="7" <? if ($rs1["Training_type"] == 7) echo "checked"; ?> /> วิทยากร <input type="radio" name="Training_type" value="6" <? if ($rs1["Training_type"] == 6) echo "checked"; ?> /> นิเทศงาน <input type="radio" name="Training_type" value="8" <? if ($rs1["Training_type"] == 8) echo "checked"; ?> /> อื่นๆ</td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">สถานะการเดินทาง <input name="object" type="radio" id="object" value="1" <? if ($rs1["object"] == 1) echo "checked"; ?> /> ค้างคืน <input name="object" type="radio" id="object" value="2" <? if ($rs1["object"] == 2) echo "checked"; ?> /> ไปกลับ <input name="object" type="radio" id="object" value="3" <? if ($rs1["object"] == 3) echo "checked"; ?> /> ส่งอย่างเดียว </a> <input name="object" type="radio" id="object" value="4" <? if ($rs1["object"] == 4) echo "checked"; ?> /> รับอย่างเดียว <input name="object" type="radio" id="object" value="5" <? if ($rs1["object"] ==5) echo "checked"; ?> /> รับส่ง ปีงบประมาณ</a>*</a> <input name="Budget_year" type="text" id="Budget_year" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? echo $rs1[Budget_year]; ?>" size="4" maxlength="4" /> </font></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">สถานะของพนักงานขับรถยนต์ <input type="radio" name="usecar" value="1" <? if ($rs1["usecar"] == 1) echo "checked"; ?> /> ใช้ พขร <input type="radio" name="usecar" value="0" <? if ($rs1["usecar"] == 0) echo "checked"; ?> /> ไม่ใช้ พขร </td> </tr> <tr height="29"> <td height="29" colspan="6" align="left"><table width="468"> <tr> <td width="126">อ้างการขอใช้ในวันที่</td> <td width="140"><?php echo dateThai($rs1['Date_start']); ?></td> <td width="186"> เวลา <input name="Time_start" type="text" id="Time_start" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" onkeypress="return checkNumeric();" value="<?=$rs1['Time_start'];?>" size="5" maxlength="5" readonly="readonly" /> น. </td> </tr> </table></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left"><table width="469"> <tr> <td width="126">สิ้นสุดการขอใช้วันที่</td> <td width="139"><?php echo dateThai($rs1['Date_finish']); ?></td> <td width="188"> เวลา <input name="Time_finish" type="text" id="Time_finish" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" onkeypress="return checkNumeric();" value="<?=$rs1['Time_finish'];?>" size="5" maxlength="5" readonly="readonly" /> น. </td> </tr> </table></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left"> <table width="471"> <tr> <td width="123">วันที่ ขอใช้</td> <td width="145"> <?php echo dateThai($rs1['DateCar']); ?> </td> <td width="187">(แสดงรายวันที่ขอใช้)</td> </tr> </table> </td> </tr> <tr height="29"> <td height="16" colspan="6" align="left"> </td> </tr> <tr height="29"> <td height="18" colspan="6" align="left">ความเห็นของผู้ควบคุมการใช้รถยนต์ วันที่ </a><a href="#" onClick="MM_openBrWindow('Carcalendar.php?now_stamp=<? echo $rs1['DateCar']; ?>','','scrollbars=yes,width=550,height=550')"><?php echo dateThai($rs1['DateCar']); ?></a></td> </tr> <tr height="29"> <td height="24" colspan="6" align="left">เห็นสมควรแจ้ง <select name="name1" id="name1"> <option value="">----- เลือก -----</option> <?php $sql4 = " SELECT *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId WHERE PositionId='6' and StatusId='1' "; $result4 = mysql_query($sql4); while( $rs4 = mysql_fetch_array($result4) ) { ?> <option value="<?=$rs4['Teacher_code'];?>" <?php if( $rs4['Teacher_code']==$rs1['name1'] ) echo 'selected';?>> <?=$rs4['First_name'];?> <?=$rs4['Teacher_name'];?> <?=$rs4['Teacher_lastname'];?> </option> <?php } # while mysql_free_result($result1); ?> </select> ให้ทราบ และให้ใช้รถยนต์ <select name="CarmoId" id="CarmoId"> <option value="">------- เลือก -------</option> <?php $strSQL3 = " SELECT * FROM automobile_tb "; $result3 = mysql_query($strSQL3); while( $rs3 = mysql_fetch_array($result3) ) { ?> <option value="<?=$rs3['CarmoId'];?>"<?php if( $rs3['CarmoId']==$rs1['CarmoId'] ) echo 'selected'; ?> > <?=$rs3['Acc_name'];?> <?=$rs3['Kind'];?> ทะเบียน <?=$rs3['CodeNo'];?> </option> <?php } # while mysql_free_result($result3); ?> </select> </td> </tr> <!-- <tr height="29"> <td height="29" colspan="6" align="center"><span class="PADDING-LEFT-10"><font size="2" face="Tahoma" ><a href="javascript:;" onclick="NewWindow('AddOil.php?carId=<?php echo $rs1['carId']; ?>','Detail','scrollbars=yes,width=600,height=300')"><img src="../picture/new.gif" alt="เพิ่มรายการเอกสาร" width="16" height="16" border="0" /></a></font><font color="#000000"> <span class="style22"> เพิ่มรายการใช้น้ำมันและเลขวัดระยะที่หน้าปัทม์ <font size="2" face="Tahoma" > <a href="javascript:;" onclick="NewWindow('FrmOil.php?carId=<?php echo $rs1['carId']; ?>','Detail','scrollbars=yes,width=600,height=300')"><img src="../picture/editnew.gif" alt="แก้ไขรายการเอกสาร" width="16" height="16" border="0" /></a></font><font color="#000000"> แก้ไขรายการใช้น้ำมันและเลขวัดระยะที่หน้าปัทม์</font></span></font></span></td> </tr> --> <tr height="29"> <td height="16" colspan="6" align="left"> </td> </tr> <tr height="31"> <td height="22" colspan="3" align="center"> </td> <td> </td> <td align="center">ลงชื่อ...................................</td> <td></td> </tr> <tr height="29"> <td height="24" colspan="3" align="center">ทราบ............................</td> <td></td> <td align="center">(<? echo $rss[First_name]?> <? echo $rss[Teacher_name]?> <? echo $rss[Teacher_lastname]?>)</td> <td></td> </tr> <tr height="29"> <td height="24" colspan="3" align="center">พนักงานขับรถยนต์</td> <td></td> <td align="center">ตำแหน่ง<font color="#0000FF" size="2" face="Tahoma"> <input name="Name3" type="text" id="Name3" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" size="20" value="<? //$PositionId = $rss["PositionId"]; $sql = "Select * From position_tb Where PositionId ='$rss[PositionId]' "; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); echo "$rs2[Position_name] ";?> " /> </font></td> <td></td> </tr> <tr height="31"> <td height="16" colspan="3" align="center">วันที่......./............./.......</td> <td colspan="3" align="left"> </td> </tr> <tr height="31"> <td height="16"> </td> <td width="3"> </td> <td width="160"> </td> <td colspan="3" align="left"><U><B>ความเห็นหัวหน้างาน</B></U></td> </tr> <tr height="29"> <td height="28" colspan="3"><U><B>ความเห็นของผู้ควบคุมการใช้รถยนต์</B></U></td> <td colspan="3"> <input name="Info_name" type="text" id="Info_name" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" size="40" /> </td> </tr> <tr height="29"> <td height="21" colspan="3" align="center"><label> <input name="Status" type="radio" id="Status" value="อนุมัติ" <?php if($rs1["Status"] == "อนุมัติ" ) echo 'checked'; ?> /> อนุมัติ <input name="Status" type="radio" id="Status" value="ไม่อนุมัติ" <?php if($rs1["Status"] == "ไม่อนุมัติ" ) echo 'checked'; ?> /> ไม่อนุมัติ <input name="Status" type="radio" id="Status" value="รออนุมัติ" <?php if($rs1["Status"] == "รออนุมัติ" ) echo 'checked'; ?> /> รออนุมัติ </label></td> <td></td> <td></td> <td></td> </tr> <tr height="29"> <td height="21" colspan="3" align="center">ลงชื่อ................................... ผู้จัดยานพาหนะ </td> <td></td> <td align="center">ลงชื่อ....................................</td> <td></td> </tr> <tr height="29"> <td height="18" colspan="3" align="center">(.....................................) </td> <td colspan="3" align="center"> ( <?php //$Teacher_code = $rss["TeacherId"]; $sql = "Select *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId Where Faculty_code ='$Faculty_code' and TeacherId='1' "; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); echo "$rs2[First_name]$rs2[Teacher_name] $rs2[Teacher_lastname]"; ?> ) <input name="TeacherId" type="hidden" id="TeacherId" value="<? echo $rs2["Teacher_code"]?>" /></td> </tr> <tr height="29"> <td height="23" colspan="3" align="left"> </td> <td colspan="3" align="center">ตำแหน่ง<input name="Name4" type="text" id="Name5" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" size="25" value=" <? $PositionId = $rs2["PositionId"]; $sql = "Select * From position_tb Where PositionId ='$PositionId' "; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); echo "$rs2[Position_name] ";?> " /> </td> </tr> <tr height="29"> <td height="29" colspan="3" align="center"> </td> <td colspan="3" align="center">วันที่......เดือน................พ.ศ......</td> </tr> <tr height="31"> <td height="17"></td> <td></td> <td></td> <td colspan="2" align="left"> คำสั่ง</td> <td></td> </tr> <tr height="29"> <td height="21"></td> <td></td> <td></td> <td align="left"> </td> <td colspan="2" align="left"><label> <input name="Status" type="checkbox" id="Status" value="อนุมัติ" <?php if($rs1["Status"] == "อนุมัติ" ) echo 'checked'; ?> disabled /> </label> อนุญาต <input name="Status" type="checkbox" id="Status" value="ไม่อนุมัติ" <?php if($rs1["Status"] == "ไม่อนุมัติ" ) echo 'checked'; ?> disabled /> ไม่อนุญาต</td> </tr> <tr height="29"> <td height="29"></td> <td></td> <td></td> <td colspan="3" align="center">ลงชื่อ.......................... .</td> </tr> <tr height="29"> <td height="27"></td> <td></td> <td></td> <td colspan="3" align="center">ตำแหน่ง.......................................</td> </tr> <tr height="29"> <td height="25"></td> <td></td> <td></td> <td colspan="3" align="center">วันที่........เดือน...............พ.ศ..... .</td> </tr> <tr height="31"> <td height="10" colspan="6" align="center"><hr /></td> </tr> </table></td> </tr> <tr> <td align="center"></td> </tr> <tr> <td align="center"> </td> </tr> <tr> <td align="center"><input name="carId" type="hidden" id="carId" value="<? echo $carId; ?>&Teacher_code<? echo $Teacher_code;?>" /> <input type="submit" name="Submit" value="บันทึก" class="WIDTH60 CURSOR-HAND" /> <input type="reset" name="Reset" value="รีเซ็ต" class="WIDTH60 CURSOR-HAND" /> <input type="button" name="Button" value="ยกเลิก" class="WIDTH60 CURSOR-HAND" onclick="location.href='FormCarList.php?Teacher_code=<?=$Teacher_code;?>'" /></td> </tr></form> </table> </fieldset></td> </tr> </table> <?php include("../templates/incFooter.php"); ?> </body> </html> <?php /** Free Resource */ $dbObj->freeresult($result1); /** Close the Database */ $dbObj->disconn(); /** Unset Class */ unset($dbObj); ?> |
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0067 ]-- |