Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /var/www/html/manage/manage_depart/ drwxr-xr-x |
Viewing file: Select action/file-type: <?php session_start(); /** Define Validate Access */ define( '_VALID_ACCESS', 1 ); /** Check Session User Login */ if( !session_is_registered("valid_user") && !session_is_registered("Priority") ) { echo "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=windows-874\" />"; echo "<p style=padding-top:115px><p align=center><br /><font color=red><strong>กรุณาทำการ Login ก่อน</strong></font></p></p>"; echo "<meta http-equiv=\"refresh\" content=\"1; URL=../login.php\" />"; exit(); } else { /** Configuration */ require_once( "../configuration.php" ); require_once( $_Config_absolute_path . "/includes/framework.php" ); require_once( "../includes/Function.php" ); /** Chart */ include ("../includes/charts.php"); /** Create Database Object */ $dbObj = new DBConn; /** Config Table for This Page */ $myTable1 = "personal_tb"; $myTable2 = "research_tb"; $param = "&"; /** Query เพื่อหา Numrows ก่อน */ //$query = " SELECT * FROM $myTable2 GROUP BY Year_prop "; //$result = $dbObj->execQuery($query); //$numrows = $dbObj->_numrows } # else ?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-874" /> <link href="../css/default.css" rel="stylesheet" type="text/css" /> <script language="Javascript" src="../charts/charts.js"></script> <title><?=$_Config_sitename;?></title> </head> <body topmargin="0" rightmargin="0" bottommargin="0" leftmargin="0"> <?php include( "../templates/incHeaderDura.php" ); ?> <table width="1003" border="0" cellspacing="0" cellpadding="0"> <tr> <td width="203" align="left" valign="top" style="padding:10px 0px 0px 5px"><?php include("./_incMainMenu.php");?></td> <td width="800" height="440" align="left" valign="top" style="padding:10px 0px 5px 10px"><fieldset> <legend><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"><a href="index.php">หน้าหลัก</a></font><img src="../picture/ico3.gif" width="10" height="10" align="absmiddle" border="0" /><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"><a href="Menu_report.php">ข้อมูลรายงาน</a></font><img src="../picture/ico3.gif" width="10" height="10" align="absmiddle" border="0" /><span class="NOTE"><strong>กราฟแสดงข้อมูลครุภัณฑ์</strong></a></font></span></legend> <table width="780" border="0" cellspacing="0" cellpadding="0"> <tr> <td width="780" height="5" colspan="2"></td> </tr> <tr> <td colspan="2"> </td> </tr> <tr> <td colspan="2"><span class="PADDING-TOP-10"><img src="../images/icons/arrow-circle-225-left.png" width="16" height="16" border="0" align="absmiddle" /> <a href="javascript:;" onclick="window.history.back();"><strong>‹ ย้อนกลับ</strong></a></span></td> </tr> <tr> <td colspan="2"> </td> </tr> <tr> <td colspan="2"> </td> </tr> <tr> <td colspan="2" align="center"> <table width="95%" border="0" align="center" cellpadding="0" cellspacing="0"> <tr> <td width="100%" height="64" align="center" style="padding-bottom:5px;"><form id="form1" name="form1" method="post" action="<?=$PHP_SELF;?>"> <label for="setdata">มิติในการดูกราฟแสดงผล</label> <select name="setdata" id="setdata"> <option value="0"<?php if( $setdata == "0" ) echo 'selected'; ?>>เลือกมิติในการดูข้อมูล</option> <option value="A"<?php if( $setdata == "A" ) echo 'selected'; ?>>จำนวนครุภัณฑ์ที่ใช้งานอยู่จำแนกตามประเภท</option> <option value="B"<?php if( $setdata == "B" ) echo 'selected'; ?>>จำนวนการแจ้งซ่อมแยกตามประเภทครุภัณฑ์</option> <option value="C"<?php if( $setdata == "C" ) echo 'selected'; ?>>จำนวนประเภทการแจ้งซ่อมครุภัณฑ์</option> <option value="D"<?php if( $setdata == "D" ) echo 'selected'; ?>>จำนวนครุภัณฑ์ที่หมดอายุการใช้งานแยกตามประเภท</option> <option value="E"<?php if( $setdata == "E" ) echo 'selected'; ?>>จำนวนเงินครุภัณฑ์จำแนกตามปีงบประมาณ</option> <option value="F"<?php if( $setdata == "F" ) echo 'selected'; ?>>จำนวนเงินวัสดุจำแนกตามปีงบประมาณ</option> <option value="G"<?php if( $setdata == "G" ) echo 'selected'; ?>>จำนวนวัสดุที่ใช้งานอยู่จำแนกตามประเภท</option> </select> <input type="submit" name="multi" class="TEXT-GREEN10 WIDTH150" id="multi" value="เลือกมิติของการดูข้อมูล" /> </form> </td> </tr> <tr> <td align="center" style="padding-bottom:5px;"> </td> </tr> <tr> <td align="center" style="padding-bottom:5px;"> <? $setdata=$_POST[setdata]; $multi=$_POST[multi]; if($multi==TRUE){ if($setdata=="A"){ ?> <?php $animateChart = "1"; //$strXML will be used to store the entire XML document generated //Generate the chart element $strXML = "<chart caption='กราฟแสดงจำนวนครุภัณฑ์ที่ใช้งานอยู่จำแนกตามประเภท' subCaption='' pieSliceDepth='30' showBorder='1' formatNumberScale='0' numberSuffix=' รายการ' animation=' " . $animateChart . "'>"; // Fetch all factory records $strQuery = "SELECT * FROM accessories_type_tb "; $result1 = mysql_query($strQuery); //Iterate through each factory if ($result1) { while( $rs1 = mysql_fetch_array($result1) ) { $error_id = $rs1['id']; $strQuery = " SELECT * FROM accessories_tb at, accessories_type_tb att WHERE at.Dura='Y' and at.Status='Y' and at.Acc_type_code = att.Acc_type_code and at.Acc_type_code !='0' and at.Acc_type_code='$rs1[Acc_type_code]' "; $result2 = mysql_query($strQuery); $numAmt = mysql_num_rows($result2); $strXML .= "<set label=' " . $rs1['Acc_type'] . "' value='" . $numAmt . "' />"; } # while } # if //Finally, close <chart> element $strXML .= "</chart>"; //Create the chart - Pie 3D Chart with data from strXML echo renderChart("../charts/Pie3D.swf", "", $strXML, "", 750, 375, false, false); ?> <? } if($setdata=="B"){ ?> <?php $animateChart = "1"; //$strXML will be used to store the entire XML document generated //Generate the chart element $strXML = "<chart caption='กราฟแสดงการแจ้งซ่อมแยกตามประเภทครุภัณฑ์' subCaption='' pieSliceDepth='30' showBorder='1' formatNumberScale='0' numberSuffix=' รายการ' animation=' " . $animateChart . "'>"; // Fetch all factory records $strQuery = "SELECT * FROM durable_tb dt, accessories_type_tb att , accessories_tb at WHERE at.Dura='Y' and at.Acc_type_code = att.Acc_type_code and dt.AccId = at.AccId and at.Acc_type_code !='0' GROUP BY dt.Acc_type_code "; $result2= mysql_query($strQuery); //Iterate through each factory if ($result2) { while( $rs2 = mysql_fetch_array($result2) ) { $error_id = $rs2['id']; $strQuery = "SELECT * FROM durable_tb dt, accessories_type_tb att , accessories_tb at WHERE at.Dura='Y' and at.Acc_type_code = att.Acc_type_code and dt.AccId = at.AccId and at.Acc_type_code !='0' and at.Acc_type_code='$rs2[Acc_type_code]' "; $result3 = mysql_query($strQuery); $numAmt = mysql_num_rows($result3); $strXML .= "<set label=' " . $rs2['Acc_type'] . "' value='" . $numAmt . "' />"; } # while } # if //Finally, close <chart> element $strXML .= "</chart>"; //Create the chart - Pie 3D Chart with data from strXML echo renderChart("../charts/Pie3D.swf", "", $strXML, "", 750, 375, false, false); ?> <? } if($setdata=="C"){ ?> <?php $animateChart = "1"; //$strXML will be used to store the entire XML document generated //Generate the chart element $strXML = "<chart caption='กราฟแสดงจำนวนประเภทการแจ้งซ่อมครุภัณฑ' subCaption='' pieSliceDepth='30' showBorder='1' formatNumberScale='0' numberSuffix=' รายการ' animation=' " . $animateChart . "'>"; // Fetch all factory records $strQuery = " SELECT * FROM durable_type_tb "; $result1 = mysql_query($strQuery); //Iterate through each factory if ($result1) { while( $rs1 = mysql_fetch_array($result1) ) { $error_id = $rs1['id']; $strQuery = "Select * From durable_tb WHERE durableCode='$rs1[durableCode]' "; $result2 = mysql_query($strQuery); $numAmt = mysql_num_rows($result2); $strXML .= "<set label=' " . $rs1['durableName'] . "' value='" . $numAmt . "' />"; } # while } # if //Finally, close <chart> element $strXML .= "</chart>"; //Create the chart - Pie 3D Chart with data from strXML echo renderChart("../charts/Pie3D.swf", "", $strXML, "", 750, 375, false, false); ?> <? } if($setdata=="D"){ ?> <?php $animateChart = "1"; //$strXML will be used to store the entire XML document generated //Generate the chart element $strXML = "<chart caption='กราฟแสดงจำนวนเงินครุภัณฑ์ที่หมดอายุการใช้งานแยกตามประเภท' subCaption='' pieSliceDepth='30' showBorder='1' formatNumberScale='0' numberSuffix=' รายการ' animation=' " . $animateChart . "'>"; // Fetch all factory records $strQuery = " SELECT * FROM accessories_type_tb "; $result1 = mysql_query($strQuery); //Iterate through each factory if ($result1) { while( $rs1 = mysql_fetch_array($result1) ) { $error_id = $rs1['id']; $strQuery = " SELECT * FROM accessories_tb at, accessories_type_tb att WHERE Fund='หมดอายุการใช้งาน' and at.Acc_type_code = att.Acc_type_code and at.Acc_type_code !='0' and at.Acc_type_code='$rs1[Acc_type_code]' "; $result2 = mysql_query($strQuery); $numAmt = mysql_num_rows($result2); $strXML .= "<set label=' " . $rs1['Acc_type'] . "' value='" . $numAmt . "' />"; } # while } # if //Finally, close <chart> element $strXML .= "</chart>"; //Create the chart - Pie 3D Chart with data from strXML echo renderChart("../charts/Pie3D.swf", "", $strXML, "", 750, 375, false, false); ?> <? } if($setdata=="E"){ ?> <?php $animateChart = "1"; //$strXML will be used to store the entire XML document generated //Generate the chart element $strXML = "<chart caption='กราฟแสดงจำนวนเงินครุภัณฑ์จำแนกตามปีงบประมาณ' subCaption='' pieSliceDepth='30' showBorder='1' formatNumberScale='0' numberSuffix=' ' animation=' " . $animateChart . "'>"; // Fetch all factory records $strQuery = " SELECT * FROM accessories_tb WHERE Year !=' ' and Dura='Y' GROUP BY Year LIMIT 10,20"; $result1 = mysql_query($strQuery); //Iterate through each factory if ($result1) { while( $rs1 = mysql_fetch_array($result1) ) { $error_id = $rs1['id']; $strQuery = " SELECT SUM(Price) AS SumB1 FROM accessories_tb WHERE Year='$rs1[Year]' and Dura='Y' "; $result3 = $dbObj->execQuery($strQuery); $rs3 = $dbObj->fetchArray($result3); $strXML .= "<set label=' " . $rs1['Year'] . "' value='".$rs3['SumB1'] . "' />"; } # while } # if //Finally, close <chart> element $strXML .= "</chart>"; //Create the chart - Pie 3D Chart with data from strXML echo renderChart("../charts/Line.swf", "", $strXML, "", 700, 375, false, false); ?> <? } if($setdata=="F"){ ?> <?php $animateChart = "1"; //$strXML will be used to store the entire XML document generated //Generate the chart element $strXML = "<chart caption='กราฟแสดงจำนวนเงินวัสดุจำแนกตามปีงบประมาณ' subCaption='' pieSliceDepth='30' showBorder='1' formatNumberScale='0' numberSuffix=' บาท' animation=' " . $animateChart . "'>"; // Fetch all factory records $strQuery = " SELECT * FROM accessories_tb WHERE Year !=' ' and Dura='N' GROUP BY Year LIMIT 0,20 "; $result1 = mysql_query($strQuery); //Iterate through each factory if ($result1) { while( $rs1 = mysql_fetch_array($result1) ) { $error_id = $rs1['id']; $strQuery = " SELECT SUM(Price) AS SumB1 FROM accessories_tb WHERE Year='$rs1[Year]' and Dura='N' "; $result2 = mysql_query($strQuery); $rs2 = $dbObj->fetchArray($result2); $strXML .= "<set label=' " . $rs1['Year'] . "' value='".$rs2['SumB1'] . "' />"; } # while } # if //Finally, close <chart> element $strXML .= "</chart>"; //Create the chart - Pie 3D Chart with data from strXML echo renderChart("../charts/Line.swf", "", $strXML, "", 750, 375, false, false); ?> <? } if($setdata=="G"){ ?> <?php $animateChart = "1"; //$strXML will be used to store the entire XML document generated //Generate the chart element $strXML = "<chart caption='กราฟแสดงจำนวนวัสดุที่ใช้งานอยู่จำแนกตามประเภท' subCaption='' pieSliceDepth='30' showBorder='1' formatNumberScale='0' numberSuffix=' รายการ' animation=' " . $animateChart . "'>"; // Fetch all factory records $strQuery = "SELECT * FROM accessories_type_tb "; $result1 = mysql_query($strQuery); //Iterate through each factory if ($result1) { while( $rs1 = mysql_fetch_array($result1) ) { $error_id = $rs1['id']; $strQuery = " SELECT * FROM accessories_tb at, accessories_type_tb att WHERE at.Dura='N' and at.Status='Y' and at.Acc_type_code = att.Acc_type_code and at.Acc_type_code !='0' and at.Acc_type_code='$rs1[Acc_type_code]' "; $result2 = mysql_query($strQuery); $numAmt = mysql_num_rows($result2); $strXML .= "<set label=' " . $rs1['Acc_Etype'] . "' value='" . $numAmt . "' />"; } # while } # if //Finally, close <chart> element $strXML .= "</chart>"; //Create the chart - Pie 3D Chart with data from strXML echo renderChart("../charts/Pie3D.swf", "", $strXML, "", 750, 375, false, false); ?> <? } } ?></td> </tr> <tr> <td align="center" style="padding-bottom:5px;"> </td> </tr> </table> <table width="750" border="0" cellspacing="0" cellpadding="0"> <tr> <td align="center"></td> </tr> </table></td> </tr> </table> </fieldset></td> </tr> </table> <?php include("../templates/incFooter.php"); ?> </body> </html> <?php /** Free Resource */ $dbObj->freeresult($result); /** Close the Database */ $dbObj->disconn(); /** Unset Class */ unset($dbObj); ?> |
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0058 ]-- |