!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage_22222/teacher/   drwxr-xr-x
Free 52.41 GB of 127.8 GB (41.01%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     CommitteeMe.php (22.59 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php

	session_start();
	
	/**  Define Validate Access  */
	define( '_VALID_ACCESS', 1 );

	/**  Check Session User Login  */
	if( !session_is_registered("valid_user") && !session_is_registered("Priority") ) {
		echo "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=windows-874\" />";
		echo "<p style=padding-top:115px><p align=center><br /><font color=red><strong>กรุณาทำการ Login ก่อน</strong></font></p></p>";
		echo "<meta http-equiv=\"refresh\" content=\"1; URL=../login.php\" />";
		exit();
	} 
	else {
		/**  Configuration  */
		require_once( "../configuration.php" );
		require_once( $_Config_absolute_path . "/includes/framework.php" );
		require_once( "../include/Function.php" );
	
		/**  Create Database Object  */
		$dbObj = new DBConn;

		//=== SESSION
		$Username = $valid_user; 
		
		//###  Persional
		$sql = " SELECT *  FROM personal_tb  WHERE Teacher_code='$Teacher_code' ";
		$result = $dbObj->execQuery($sql);
		$row = $dbObj->fetchArray($result);
			$Teacher_code = $row['Teacher_code'];
		
		//###  Committee
		$sql2 = " SELECT *  FROM committee_tb  WHERE Teacher_code='$Teacher_code'  ORDER BY Year_com ";
		$result2 = $dbObj->execQuery($sql2);
		$num = $dbObj->_numrows;
		
	} # else
 ?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-874" />
<link href="../css/default.css" rel="stylesheet" type="text/css" />
<script language="javascript" src="../js/utilities.js"></script>
<title>MIS -- Teacher</title>
</head>

<body topmargin="0" rightmargin="0" bottommargin="0" leftmargin="0">
<?php
	include("../templates/incHeader.php");
?>
<table width="1003" border="0" cellspacing="0" cellpadding="0">
  <tr>
    <td width="203" align="left" valign="top" style="padding:10px 0px 0px 5px"><?php include("./_incMainMenu.php");?></td>
    <td width="800" height="440" align="center" valign="top" style="padding:10px 0px 5px 10px">
    <fieldset>
     <table width="780" border="0" cellspacing="0" cellpadding="0">
      <form id="myForm" name="myForm" method="post" action="<?=$PHP_SELF;?>?Teacher_code=<?=$Teacher_code;?>&amp;page=<?=$page;?>">
      <tr>
        <td height="5"></td>
      </tr>
      <tr>
        <td height="30" background="../images/background/bg-head-topic-w780.gif" class="PADDING-LEFT-10"><strong><a href="index.php">หน้าหลัก</a></strong> <strong>&raquo; <a href="Menu_Teach.php">ข้อมูลทั่วไปบุคลากร</a> &raquo; <span class="NOTE">ข้อมูลการพัฒนาบุคลากร</span></strong></td>
      </tr>
      <tr>
        <td>&nbsp;</td>
      </tr>
      <tr>
        <td align="center"><table width="760" border="0" align="center" cellpadding="1" cellspacing="1" bordercolor="#CCCCCC" bgcolor="#FFFFFF" style="border:1px solid #CCCCCC">
<tr bgcolor="#DFEBF9">
                        <td height="22" colspan="5" align="center" bgcolor="#FFFFFF"><font color="#003366" face="Tahoma">ข้อมูลการเป็นกรรมการบริการวิชาการ</font> <font face="Tahoma">อ.<font color="#993333"><? echo $row['Teacher_name']; ?> &nbsp;<font face="Tahoma"><? echo $row['Teacher_lastname']; ?></font></font></font></td>
                </tr>
                      <tr bgcolor="#CCE6FF">
                        <td colspan="3" align="center" bordercolor="#0066CC" bgcolor="#CCE6FF" style="border:1px solid gray">&nbsp;</td>
                        <td width="152" align="center" bordercolor="#0066CC" bgcolor="#CCE6FF" style="border:1px solid gray"><span class="style15"><font face="Tahoma">แยกประเภทตาม 
                          สมศ.3.2</font></span></td>
                        <td width="318" align="center" bordercolor="#0066CC" style="border:1px solid gray"><span class="style15"><font face="Tahoma">แยกประเภทตามการเป็นกรรมการ</font> <font face="Tahoma">ให้บริการวิชาการอื่นฯ</font></span></td>
                </tr>
                      <tr bgcolor="#CCE6FF">
                        <td width="35" height="26" align="center" bordercolor="#0066CC" bgcolor="#DFEBF9" style="border:1px solid gray"><span class="style15 style16"><font color="#000000" face="Tahoma">ลำดับ</font></span></td>
                        <td width="37" align="center" bordercolor="#0066CC" bgcolor="#DFEBF9" style="border:1px solid gray"><span class="style16"><font face="Tahoma">ปี 
                          พ.ศ</font></span> </td>
                        <td width="202" align="center" bordercolor="#0066CC" bgcolor="#DFEBF9" style="border:1px solid gray"><span class="style15"><font color="#000000" face="Tahoma">ชื่อเรื่อง</font></span></td>
<td align="center" style="border:1px solid gray"><table width="100%" height="30" border="0" align="center" cellpadding="0" cellspacing="1">
                <tr bgcolor="#DFEBF9">
                              <td width="30%" height="20" align="center" style="border:1px solid gray"><font size="1" face="Tahoma">วิชาการ</font></td>
                              <td width="30%" align="center" style="border:1px solid gray"><font size="1" face="Tahoma">วิชาชีพ</font></td>
                              <td width="40%" align="center" style="border:1px solid gray"><font size="1" face="Tahoma">วิทยานิพนธ์</font></td>
                      </tr>
                        </table></td>
                        <td align="center" style="border:1px solid gray"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr bgcolor="#DFEBF9">
                              <td width="20%" align="center" style="border:1px solid gray"><font size="1" face="Tahoma">ตรวจเครื่องมือ</font></td>
                          <td width="20%" align="center" style="border:1px solid gray"><font size="1" face="Tahoma">คปสข.4-5</font></td>
                          <td width="20%" align="center" style="border:1px solid gray"><font size="1" face="Tahoma">ครือข่าย ภาคกลาง</font>1</td>
                          <td width="20%" align="center" bgcolor="#DFEBF9" style="border:1px solid gray"><font size="1" face="Tahoma">การเป็นวิทยากร</font></td>
                          <td width="20%" align="center" style="border:1px solid gray"><font size="1" face="Tahoma">กรรมการ อื่นๆ</font></td>
                          </tr>
                        </table></td>
                      </tr>
                      <?php
						$i = 1;
						while( $rs2 =mysql_fetch_array($result2) ) {
						
							$bgColor = ( $bgColor == "#FFFFFF" ) ? "#F9FBFB" : "#FFFFFF";
					?>
                      <tr bgcolor="<?=$bgColor;?>">
                        <td align="center" valign="top" bordercolor="#EBFAFE"><? echo $i; ?></td>
                        <td align="center" valign="top" bordercolor="#EBFAFE"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[Year_com]; ?></font></td>
                        <td valign="top" bordercolor="#EBFAFE"><font color="#000000" size="2" face="Tahoma"><? echo $rs2[Title]; ?></font></td>
                  <td valign="top" bordercolor="#EBFAFE"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                            <tr>
                              <td width="30%" height="18"><div align="center"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[Edu]; ?></font></div></td>
                              <td width="30%"><div align="center"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[Edu_job]; ?></font></div></td>
                              <td width="40%"><div align="center"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[Tsis]; ?></font></div></td>
                      </tr>
                        </table></td>
                        <td valign="top" bordercolor="#EBFAFE"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1" bgcolor="#FFFFFF">
                      <tr>
                              <td width="20%" height="18"><div align="center"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[Check_tool]; ?></font></div></td>
                              <td width="20%"><div align="center"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[Scp10]; ?></font></div></td>
                              <td width="20%"><div align="center"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[Club_bcnlp]; ?></font></div></td>
                              <td width="20%"><div align="center"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[North_network]; ?></font></div></td>
                        <td width="20%"><div align="center"><font color="#993333" size="2" face="Tahoma"><? echo $rs2[Else_commit]; ?></font></div></td>
                          </tr>
                        </table></td>
                      </tr>
                      <?php
							$i++;
						 }	
					?>
                    </table>
           	  <br />
           	  <table width="760" border="0" align="center" cellpadding="1" cellspacing="1" style="border:1px solid #CCCCCC">
      			<tr>
                    <td width="47%" align="left" bgcolor="#FDFCEC"><font color="#003366" size="2" face="Tahoma">จำนวนการเป็นกรรมการ 
                  (แยกตามประเภท)</font></td>
                    <td width="20%"><table width="99%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr>
                          <td width="33%" bgcolor="#FDFCEC"><div align="center"><font color="#993333" size="2" face="Tahoma">
                          <?php 
							$Teacher_code = $row[Teacher_code];
							$sql1 = "Select * From committee_tb Where Edu='Yes' AND Teacher_code='$Teacher_code' AND Year_com='$Year_com'";
							$result1 = mysql_query($sql1);
							$Srs1 = mysql_num_rows($result1);
								echo $Srs1;
						  ?>
                          </font></div></td>
                          <td width="34%" bgcolor="#FDFCEC"><div align="center"><font color="#993333" size="2" face="Tahoma">
                          <?php 
							$Teacher_code = $row[Teacher_code];
							$sql5 = "Select * From committee_tb Where Edu_job='Yes' AND Teacher_code='$Teacher_code' ";
							$result5 = mysql_query($sql5);
							$Srs5 = mysql_num_rows($result5);
								echo $Srs5;
						  ?>
                          </font></div></td>
                          <td width="33%" bgcolor="#FDFCEC"><div align="center"><font color="#993333" size="2" face="Tahoma">
                          <?php 
							$Teacher_code = $row[Teacher_code];
							$sql8 = "Select * From committee_tb Where Tsis='Yes' AND Teacher_code='$Teacher_code' ";
							$result8 = mysql_query($sql8);
							$Srs8 = mysql_num_rows($result8);
								echo $Srs8;
					  ?>
                          </font></div></td>
                      </tr>
                  </table></td>
                      <td width="33%" colspan="2"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr>
                          <td width="20%" bgcolor="#FDFCEC"><div align="center"><font color="#993333" size="2" face="Tahoma">
                          <?php 
							$Teacher_code = $row[Teacher_code];
							$sql1 = "Select * From committee_tb Where Check_tool='Yes' AND Teacher_code='$Teacher_code' ";
							$result1 = mysql_query($sql1);
							$rs10 = mysql_num_rows($result1);
								echo $rs10;
							?>
                          </font></div></td>
                          <td width="20%" bgcolor="#FDFCEC"><div align="center"><font color="#993333" size="2" face="Tahoma">
                          <?php 
							$Teacher_code = $row[Teacher_code];
							$sql8 = "Select * From committee_tb Where Scp10 ='Yes' AND Teacher_code='$Teacher_code' AND Year_com='$Year_com' ";
							$result8 = mysql_query($sql8);
							$rs11 = mysql_num_rows($result8);
								echo $rs11;
							?>
							</font></div></td>
							<td width="20%" bgcolor="#FDFCEC"><div align="center"><font color="#993333" size="2" face="Tahoma">
							<?php 
							$Teacher_code = $row[Teacher_code];
						   $sql5 = "Select * From committee_tb Where Club_bcnlp='Yes' AND Teacher_code='$Teacher_code'  ";
						   $result5 = mysql_query($sql5);
						   $rs12 = mysql_num_rows($result5);
							echo $rs12;
						  ?>
                          </font></div></td>
                          <td width="20%" bgcolor="#FDFCEC"><div align="center"><font color="#993333" size="2" face="Tahoma">
                          <?php 
							$Teacher_code = $row[Teacher_code];
							$sql5 = "Select * From committee_tb Where North_network='Yes' AND Teacher_code='$Teacher_code' ";
							$result5 = mysql_query($sql5);
							$rs13 = mysql_num_rows($result5);
								echo $rs13;
						  ?>
                          </font></div></td>
                          <td width="20%" bgcolor="#FDFCEC"><div align="center"><font color="#993333" size="2" face="Tahoma">
                          <?php 
							$Teacher_code = $row[Teacher_code];
							$sql8 = "Select * From committee_tb Where Else_commit ='Yes' AND Teacher_code='$Teacher_code' ";
							$result8 = mysql_query($sql8);
							$rs14 = mysql_num_rows($result8);
								echo $rs14;
						  ?>
                          </font></div></td>
                        </tr>
                    </table></td>
                </tr>
                  <tr>
                    <td align="left" bgcolor="#F0FDE8"><font size="2" face="Tahoma">จำนวนการไม่เป็นกรรมการ 
                    (แยกตามประเภท) </font></td>
                  <td><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr>
                          <td width="25%" bgcolor="#F0FDE8"><div align="center"><font color="#993333" size="2" face="Tahoma">
						  <?php 
						  $Teacher_code = $row[Teacher_code];
						  $sql3 = "Select * From committee_tb Where Edu='No' AND Teacher_code='$Teacher_code' ";
						  $result3 = mysql_query($sql3);
						  $Srs3 = mysql_num_rows($result3);
						  echo $Srs3;
						  ?>
                          </font></div></td>
                          <td width="25%" bgcolor="#F0FDE8"><div align="center"><font color="#993333" size="2" face="Tahoma">
						  <?php 
							$Teacher_code = $row[Teacher_code];
							$sql6 = "Select * From committee_tb Where Edu_job='No' AND Teacher_code='$Teacher_code' ";
							$result6 = mysql_query($sql6);
							$Srs6 = mysql_num_rows($result6);
							echo $Srs6;
						  ?>
                          </font></div></td>
                          <td width="25%" bgcolor="#F0FDE8"><div align="center"><font color="#993333" size="2" face="Tahoma">
                              <?php 
							$Teacher_com = $row[Teacher_code];
							$sql8 = "Select * From committee_tb Where Tsis='No' AND Teacher_code='$Teacher_code' ";
							$result8 = mysql_query($sql8);
							$Srs9 = mysql_num_rows($result8);
							echo $Srs9;
						  ?>
                          </font></div></td>
                        </tr>
                    </table></td>
                    <td colspan="2"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr>
                          <td width="20%" bgcolor="#F0FDE8"><div align="center"><font color="#993333" size="2" face="Tahoma">
                              <?php 
							$Teacher_code = $row[Teacher_code];
							$sql1 = "Select * From committee_tb Where Check_tool='No' AND Teacher_code='$Teacher_code' ";
							$result1 = mysql_query($sql1);
							$rs15 = mysql_num_rows($result1);
							echo $rs15;
						  ?>
                          </font></div></td>
                          <td width="20%" bgcolor="#F0FDE8"><div align="center"><font color="#993333" size="2" face="Tahoma">
                              <?php 
							$Teacher_code = $row[Teacher_code];
							$sql8 = "Select * From committee_tb Where Scp10 ='NO' AND Teacher_code='$Teacher_code' ";
							$result8 = mysql_query($sql8);
							$rs16 = mysql_num_rows($result8);
							echo $rs16;
						  ?>
                          </font></div></td>
                          <td width="20%" bgcolor="#F0FDE8"><div align="center"><font color="#993333" size="2" face="Tahoma">
                              <?php 
							$Teacher_code = $row[Teacher_code];
							$sql5 = "Select * From committee_tb Where Club_bcnlp='No' AND Teacher_code='$Teacher_code' ";
							$result5 = mysql_query($sql5);
							$rs17 = mysql_num_rows($result5);
							echo $rs17;
						  ?>
                          </font></div></td>
                          <td width="20%" bgcolor="#F0FDE8"><div align="center"><font color="#993333" size="2" face="Tahoma">
                              <?php 
						   $Teacher_code = $row[Teacher_code];
						   $sql5 = "Select * From committee_tb Where North_network='No' AND Teacher_code='$Teacher_code' ";
						   $result5 = mysql_query($sql5);
						   $rs18 = mysql_num_rows($result5);
							echo $rs18;
						  ?>
                          </font></div></td>
                          <td width="20%" bgcolor="#F0FDE8"><div align="center"><font color="#993333" size="2" face="Tahoma">
                              <?php 
							$Teacher_code = $row[Teacher_code];
							$sql8 = "Select Count(Else_commit ) as sum8 From committee_tb Where Else_commit ='No' AND Teacher_code='$Teacher_code'";
							$result8 = mysql_query($sql8);
							$rs19 = mysql_num_rows($result8);
							echo $rs19;
						  ?>
                          </font></div></td>
                        </tr>
                    </table></td>
                  </tr>
                  <tr>
                    <td align="left" bgcolor="#DFEBF9"><font size="2" face="Tahoma">จำนวนการเป็นกรรมการวิชาการ/วิชาชีพ/วิทยานิพนธ์</font></td>
                  <td><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr>
                          <td width="25%">&nbsp;</td>
                          <td width="25%">&nbsp;</td>
                          <td width="25%" bgcolor="#DFEBF9"><div align="center"><font color="#009966" size="2" face="Tahoma">
                              <?php
							 $SumCommit = $Srs1 + $Srs5 + $Srs8;
							 echo"$SumCommit";
						?>
                          </font></div></td>
                        </tr>
                    </table></td>
                    <td colspan="2"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr>
                          <td width="20%" bgcolor="#FFFFFF">&nbsp;</td>
                          <td width="20%" bgcolor="#FFFFFF">&nbsp;</td>
                          <td width="20%" bgcolor="#FFFFFF">&nbsp;</td>
                          <td width="20%" bgcolor="#FFFFFF">&nbsp;</td>
                          <td width="20%" bgcolor="#DFEBF9"><div align="center"><font color="#009966" size="2" face="Tahoma">
                              <?php
							 $SumCommit = $rs10 + $rs11 + $rs12 + $rs13; + $rs14 ;
							 echo"$SumCommit";
						?>
                          </font></div></td>
                        </tr>
                    </table></td>
                  </tr>
                  <tr>
                    <td align="left" bgcolor="#DFEBF9"><font size="2" face="Tahoma">จำนวนการไม่เป็นกรรมการวิชาการ/วิชาชีพ/วิทยานิพนธ์</font></td>
                  <td><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr>
                          <td width="25%">&nbsp;</td>
                          <td width="25%">&nbsp;</td>
                          <td width="25%" bgcolor="#DFEBF9"><div align="center"><font color="#FF0000" size="2" face="Tahoma">
                              <?php
							 $SumUCommit = $Srs3 + $Srs6 + $Srs9;
							 echo"$SumUCommit";
						?>
                          </font></div></td>
                        </tr>
                    </table></td>
                    <td colspan="2"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
                        <tr bgcolor="#FCF4E9">
                          <td width="20%" bgcolor="#FFFFFF">&nbsp;</td>
                          <td width="20%" bgcolor="#FFFFFF">&nbsp;</td>
                          <td width="20%" bgcolor="#FFFFFF">&nbsp;</td>
                          <td width="20%" bgcolor="#FFFFFF">&nbsp;</td>
                          <td width="20%" bgcolor="#DFEBF9"><div align="center"><font color="#FF0000" size="2" face="Tahoma">
                              <?php
							 $SumCommit = $rs15 + $rs16 + $rs17 + $rs18 + $rs19;
							 echo"$SumCommit";
						?>
                          </font></div></td>
                        </tr>
                    </table></td>
                  </tr>
                  <tr bgcolor="#CCE6FF">
                    <td colspan="4" align="center"><strong><font color="#003366" size="2" face="Tahoma">ทั้งหมด</font><font color="#FF0000" size="2" face="Geneva, Arial, Helvetica, sans-serif"> <? echo $num ?><font color="#003366" face="Tahoma"> เรื่อง</font></font></strong> </td>
                  </tr>
                </table>
          		<br />
           	    <table width="760" border="0" align="center" cellpadding="1" cellspacing="1">
                  <tr>
                    <td colspan="2"><font color="#993333" size="2" face="Tahoma"><strong>หมายเหตุ***</strong></font></td>
                  </tr>
                  <tr bgcolor="#eeeeee">
                    <td width="13%" align="center"><strong><font size="2" face="Tahoma">Yes</font></strong></td>
                    <td width="87%"><font color="#000000" size="2" face="Tahoma">เป็นกรรมการ</font></td>
                  </tr>
                  <tr bgcolor="#eeeeee">
                    <td align="center"><strong><font size="2" face="Tahoma">No</font></strong></td>
                    <td><font color="#000000" size="2" face="Tahoma">ไม่ได้เป็นกรรมการ</font></td>
                  </tr>
                  <tr bgcolor="#eeeeee">
                    <td height="19" align="center"><strong><font size="2" face="Tahoma">S</font></strong></td>
                    <td><font size="2" face="Tahoma">ลาศึกษาต่อ/ไปช่วยราชการ </font></td>
                  </tr>
                </table>
              <br />
            <input type="button" name="button" id="button" value="&laquo; ย้อนกลับ" onclick="window.history.back()" class="CURSOR-HAND" /></td>
      </tr>
      <tr>
        <td>&nbsp;</td>
      </tr></form>
    </table>
   </fieldset></td>
  </tr>
</table>
<?php include("../templates/incFooter.php"); ?>
</body>
</html>
<?php
	/**  Free Resource */
	$dbObj->freeresult($result1);
	
	/**  Close the Database  */
	$dbObj->disconn();
	
	/**  Unset Class  */
	unset($dbObj);
?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0061 ]--