Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /var/www/html/manage/State/ drwxr-xr-x |
Viewing file: EditFrmState.php (3.46 KB) -rw-r--r-- Select action/file-type: (+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) | <?php session_start(); if (session_is_registered("valid_user")) { include("../include/FunctionDB.php"); include("../source/myFunc.php"); ConnectDB(); //===============================================// // Select ข้อมูลขึ้นมาเพื่อ คำนวณหายอดรวมของ record ก่อนหน้า record นี้ //===============================================// $sql2 = "select * from state_tb where stateId = '$stateId' "; $result2= mysql_query($sql2) or die("Select State Error $sql2".mysql_error()); $rss = mysql_fetch_array($result2); $costTmp = $rss['Cost1'] + $rss['Cost5']; $costTmp2 = $rss['CostSum'] + $rss['Cost2'] + $rss['Cost3'] + $rss['Cost4']; if($costTmp > $costTmp2) $costSumTmp = ($rss['Cost1']+$rss['Cost5']) - ($rss['CostSum']+$rss['Cost2']+$rss['Cost3']+$rss['Cost4']); else $costSumTmp = ($rss['CostSum']+$rss['Cost2']+$rss['Cost3']+$rss['Cost4']) - ($rss['Cost1']+$rss['Cost5']); /***************************************************************************************************************/ // =================== update ข้อมูลของ record นี้ ============================= $costSumTmp2 = ($Cost1+$Cost5+$costSumTmp)-($Cost2+$Cost3+$Cost4); $dateNote = dmyE2ymdT($date); $sql = " UPDATE state_tb SET Year_State='$Year_State',Date_note='$dateNote',No='$No',Disciption='$Disciption',Cost1='$Cost1',Cost2='$Cost2',Cost3='$Cost3',Cost4='$Cost4',Cost5='$Cost5',CostSum='$costSumTmp2' WHERE stateId ='$stateId' "; $result = mysql_query($sql) or die("Update Error $sql".mysql_error()); //=================================================== //////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// //select ข้อมูล ที่อยู่ต่อจาก record นี้ทั้งหมด เพื่อทำการ update ยอดรวมทั้งหมดอีกครั้ง $sql3 = "select * from state_tb where stateId > '$stateId' AND State = '$rss[State]' "; $result3= mysql_query($sql3) or die("Select State Error $sql2".mysql_error()); if($result3){ $i = 0; $costSumTmp4; while($rss2 = mysql_fetch_array($result3)){ if($i == 0) $costSumTmp3 = ($rss2['Cost1']+$rss2['Cost5']+$costSumTmp2) - ($rss2['Cost2']+$rss2['Cost3']+$rss2['Cost4']); else { //$costTmp3 = $rss2['Cost1'] + $rss2['Cost5']; //$costTmp4 = $rss2['CostSum'] + $rss2['Cost2'] + $rss2['Cost3'] + $rss2['Cost4']; //if($costTmp3 > $costTmp4) $costSumTmp4 = ($rss2['Cost1']+$rss2['Cost5']) - ($rss2['CostSum']+$rss2['Cost2']+$rss2['Cost3']+$rss2['Cost4']); //else $costSumTmp4= ($rss2['CostSum']+$rss2['Cost2']+$rss2['Cost3']+$rss2['Cost4']) - ($rss2['Cost1']+$rss2['Cost5']); $costSumTmp3 = ($rss2['Cost1']+$rss2['Cost5']+$costSumTmp4) - ($rss2['Cost2']+$rss2['Cost3']+$rss2['Cost4']); } $costSumTmp4 = $costSumTmp3; $sql4 = "UPDATE state_tb SET CostSum='$costSumTmp3' WHERE stateId ='$rss2[stateId]'"; $result4 = mysql_query($sql4) or die("Update Error $sql4".mysql_error()); $i++; } } //======================================================= if ($result || $result3){ //header("Location:EditStateList.php?State=$State"); echo"<meta http-equiv=\"refresh\" content=\"2;URL=EditStateList.php?State=$State\">"; echo"<br><br><center><font face=\"Ms San serif\"size=\"5\" color=\"#FF0000\">แก้ไขข้อมูลเรียบร้อยแล้ว</font></center>"; } CloseDB(); ?> <?php } else { echo"<meta http-equiv=\"refresh\" content=\"3;URL=../Login.php\">\n"; echo"Please Login "; } ?> |
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0054 ]-- |