!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/mistk/mistk/mistk/eoffice/admin/   drwxr-xr-x
Free 50.78 GB of 127.8 GB (39.73%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     showEntryDoc.php (31.29 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
include_once "template.php";
include_once 
"../class/clsTable.php";
include_once 
"../class/clsDepartment.php";
include_once 
"../class/clsPerson.php";
include_once 
"../link/function.php";
include_once 
"../link/functionshow.php";
include_once 
"../class/clsDocLinePosition.php";
include_once 
"../class/clsDocLineConfig.php";
include_once 
"../class/clsReceiveSendType.php";
include_once 
"../class/clsDocType.php";
include_once 
"../class/clsDocSpeedLevel.php";
include_once 
"../class/clsDocSecreLevel.php";
include_once 
"../class/clsDocattatchesTmp.php";
include_once 
"../class/clsDocuments.php";
include_once 
"../class/clsDocattatches.php";
include_once 
"../class/clsDocReceiveSend.php";
include_once 
"../class/clsProposeType.php";
include_once 
"funct.php";
include_once 
"../class/clsannounceDocType.php";
include_once 
"../link/keyThai.php";
include_once 
"../class/clsDocWSign.php";
include_once 
"getPrefix.php";

$oC = new clsConnection($GLOBALS['DBHOST'], $GLOBALS['DBNAME_EOFFICE'], $GLOBALS['DBUSER_EOFFICE'], $GLOBALS['DBPASS_EOFFICE']);

$oDP = new Department($oC);
$oDP2 = new Department($oC);
$oDP3 = new Department($oC);
$oPS = new person($oC);
$oDlc = new DocLineConfig($oC);
$oDlc2 = new DocLineConfig($oC);
$oDlc3 = new DocLineConfig($oC);
$oDlc5 = new DocLineConfig($oC);
$oDlp = new docLinePosition($oC);
$oDlp1 = new docLinePosition($oC);
$oRSt = new receiveSendType($oC);
$oDt = new doctype($oC);
$oDsl = new DocSpeedLevel($oC);
$oDcl = new DocSecretLevel($oC);
$oDtmp = new DocattatchesTmp($oC);
$oDoc = new Documents($oC);
$oDoc2 = new Documents($oC);
$oDoc3 = new Documents($oC);
$oDatt = new Docattatches($oC);
$oDatt2 = new Docattatches($oC);
$oRs = new DocReceiveSend($oC);
$oRs1 = new DocReceiveSend($oC);
$oRs2 = new DocReceiveSend($oC);
$oRs3 = new DocReceiveSend($oC);
$oRs4 = new DocReceiveSend($oC);
$oRs6 = new DocReceiveSend($oC);
$oRs7 = new DocReceiveSend($oC);
$oRs8 = new DocReceiveSend($oC);
$oPS2 = new person($oC);
$oPt = new ProposeType($oC);
$oAn=new announceDocType($oC);
$oDws = new docwsign($oC);
$MaxDocGroup=$oDP->SearchMaxDocGroup();

?>

<?
    $oDoc
->SearchByKey($DocID); $oDoc->GetRecord();
    
$oRs->SearchByKey($DrsID); $oRs->GetRecord(); 
    if(
$oRs->DsID=="0"){
            
UpdatereadDoc($oRs->DrsID,$DocID);
    }
?>
<html>
<head>
<script language="javascript" src="../source/calendarDateInput.js"></script>
<meta http-equiv="Content-Type" content="text/html; charset=tis-620">
<link href="../source/style.css" rel="stylesheet" type="text/css">
</head>
<body>
<table  width="100%"  align="center">
<tr><td >
<fieldset>
      <legend><font size="2" color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>"><a href="entryDoc.php">˹ѧÊ×Íà¢éÒ</a>
      <img src="../picture/ico3.gif" width="10" border="0" align="absmiddle">ÃÒÂÅÐàÍÕ´¢éÍÁÙÅ˹ѧÊ×Íà¢éÒ</font>
    </font></legend>
        <form name="ff"  METHOD="POST" action="processEntryDoc.php">
        <table align="center" width="93%" >
        <tr>
          <td width="68%" height="25"><img src="../picture/official_letter.gif" alt=""  border="0" > 
            <font color="<?php echo $GLOBALS["COLOR_FONT_2"]; ?>" size="3"><strong>˹ѧÊ×Íà¢éÒ</strong></font> 
           </td>
          </tr>
        <tr>
          <td  colspan="3"><hr color="#000099"></hr>
          </td>
        </tr>
      </table>
        <table width="93%" border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>"><tr><td>
      <table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" bordercolor="#DADADA" style="border-collapse:collapse"  background="../picture/table_header_bg2.gif">
        <tr>
          <td width="68%" height="25">
            <font color="<?php echo $GLOBALS["COLOR_FONT_1"]; ?>" size="2"><strong> 
            &nbsp;ÃÒÂÅÐàÍÕ´¢Í§Ë¹Ñ§Ê×Í: </strong></font> 
            <font color="<?php echo $GLOBALS["COLOR_FONT_8"]; ?>" size="2"><strong>
            <?   if($oDoc->RsID==1){    
                        echo 
$oRSt->SearchShowRsName(1); 
                    }else if(
$oDoc->RsID==2){   
                        echo 
$oRSt->SearchShowRsName(2); 
                    }else if(
$oDoc->RsID==3){  
                        echo 
$oRSt->SearchShowRsName(3); 
                    }else if(
$oDoc->RsID==4){  
                        echo 
$oRSt->SearchShowRsName(4); 
                    }
            
?>
            </strong></font>
            &nbsp; <font color="<?php echo $GLOBALS["COLOR_FONT_1"]; ?>" size="2"><strong> 
            &nbsp;ª¹Ô´Ë¹Ñ§Ê×Í: </strong></font>
            <font color="<?php echo $GLOBALS["COLOR_FONT_8"]; ?>" size="2"><strong>
              <? $oDt->SearchByKey($oDoc->DtID);
                     
$oDt->GetRecord();
                     echo 
$oDt->DtName;
            
?>
            </strong></font>
                     </td>
</tr>
      </table>
      <table width="90%" border="0" align="center" cellpadding="0" cellspacing="1" bordercolor="#DADADA" style="border-collapse:collapse">
      <tr><td>&nbsp;</td></tr>
     <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong><? echo ShowNameDocNo($oDoc->DtID); ?></strong></td>
             <td width="2%" align="center"><strong>:</strong></td>
            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">&nbsp;<? if($oDoc->DocNo!=""){  echo $oDoc->DocNo;   } ?></td></tr>
     <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong><? echo ShowNameDate2($oDoc->DtID); ?></strong></td>
             <td width="2%" align="center" ><strong>:</strong></td><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">
            <?   if($oDoc->DocDate!="" && $oDoc->DocDate!="0000-00-00"){ 
                                        echo 
"&nbsp;".abbreDate2($oDoc->DocDate,'/');
                    } 
?>
            </td></tr>
     <? //if($oDoc->DtID!=13){ ?>
      <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>" >&nbsp;&nbsp;<strong><? echo ShowNameSubject($oDoc->DtID); ?></strong></td>
            <td width="2%" align="center"><strong>:</strong></td><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">&nbsp;<?  if($oDoc->DocSubject!=""){ echo  $oDoc->DocSubject;  } ?></td>
    </tr>
    <? //} ?>
    <? if($oDoc->DtID==|| $oDoc->DtID==|| $oDoc->DtID==||  $oDoc->DtID==14 || $oDoc->DtID==13){?>  
      <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong><? echo ShowNameFrom($oDoc->DtID); ?></strong></td>
              <td width="2%" align="center"><strong>:</strong></td>
            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">&nbsp;<? if($oDoc->DocFrom!=""){ echo  $oDoc->DocFrom;  } ?></td>
          </tr>
    <? ?>
    <? if($oDoc->DtID==13){?>  
      <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ª×èͼÙéä´éÃѺ¡ÒÃÃѺÃͧ</strong></td>
              <td width="2%" align="center"><strong>:</strong></td>
            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">&nbsp;<? if($oDoc->CertificatePs!=""){   echo $oDoc->CertificatePs; } ?></td>
          </tr>
    <? ?>
    <? if($oDoc->DtID==|| $oDoc->DtID==2  || $oDoc->DtID==14 || $oDoc->DtID==3){?>
       <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong><? if($DtID==3){   echo "àÃÕ¹"; }else{  echo "¶Ö§"; } ?></strong></td>
                   <td width="2%" align="center"><strong>:</strong></td>
            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">&nbsp;<?  if($oDoc->DocTo!=""){   echo $oDoc->DocTo; }?></td>        
          </tr>
    <? }?>
      <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>á¿éÁ˹ѧÊ×Í</strong></td>
                   <td width="2%" align="center"><strong>:</strong></td>
                  <td width="73%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>"> <font size="2" color="<?php echo $GLOBALS["COLOR_FONT_2"]; ?>">
                  
                   <? if($oDoc->DocPID=="0" || $oDoc->DocPID==""){  $searchDoc=$oDoc->DocID; }else{ $searchDoc=$oDoc->DocPID; }
                         
$countdoc=$oDatt2->CountDocByDocID($searchDoc); ?>
                    &nbsp;<img src="../picture/attach_ico.gif" alt=""  border="0" >&nbsp;á¿éÁ·Õèà¡ÕèÂÇ¢éͧ&nbsp;<? echo a2th($oDatt->CountDocByDocID($searchDoc)); ?>&nbsp;ÃÒ¡ÒÃ<br></font> 
                    <? 
                        
//---checkforsubmit
                        
$totalDocRead=substr_count($oRs->DrsReadDoc'1');
                       
$countDrsDocRead=strlen($oRs->DrsReadDoc);
                        
//-----
                        
$oDatt->SearchByDocID($searchDoc);
                        while(
$oDatt->GetRecord()){  
                            
$showReadDoc='';
                            
$DaSeq=$oDatt->DaSeq;
                            
$checkReadDoc=GetStatusReadDoc($oRs->DrsReadDoc,$oDatt->DaSeq);
                            if(
$checkReadDoc==&& $oRs->DrsReadDoc!='' && $oDatt->DaSeq!=0){ $showReadDoc="&nbsp;&nbsp;<font color=#FF9900>[ÂѧäÁèä´éà»Ô´ÍèÒ¹]</font>"; }
                            
$c++;  
                            
$pathfile="../documents/".$oDatt->DaUpFileName
                        
?>
                            &nbsp;
                            <a href="processEntryDoc.php?DrsID=<?php echo $DrsID;?>&DocID=<? echo $DocID?>&pathfile=<? echo $pathfile?>&flagshow=<? echo $flagshow?>&DrsReadDoc=<? echo $oRs->DrsReadDoc?>&DaSeq=<? echo  $oDatt->DaSeq?>&method=updateDoc5" target="_blank">
                            <img src="../picture/allregistered_ico.gif" alt="à»Ô´´Ùá¿éÁ˹ѧÊ×Í"  border="0"  style="cursor:pointer;" ></a>&nbsp; 
                        <?    echo "&nbsp;".$c.".&nbsp;".$oDatt->DaFileName.$showReadDoc."<br>";     
                        } 
?>
                  </td>                        
    </tr>
    <? if(($oDoc->DtID==|| $oDoc->DtID==2) && ($oDoc->RsID=="2" || $oDoc->RsID=="1")){?>
    <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ÍéÒ§¶Ö§</strong></td>
                   <td width="2%" align="center"><strong>:</strong></td><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">&nbsp;<? if($oDoc->DocRef!=""){   echo $oDoc->DocRef; } ?></td>
    </tr>    
    <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ÊÔ觷ÕèÊè§ÁÒ´éÇÂ</strong></td>
                   <td width="2%" align="center"><strong>:</strong></td><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">&nbsp;<? if($oDoc->DocOther!=""){   echo $oDoc->DocOther; }?></td>
    </tr>
    <? ?>
    <? if($oDoc->DtID==&& ($oDoc->RsID=="4" || $oDoc->RsID=="3")){?>
    <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ÍéÒ§¶Ö§Ë¹Ñ§Ê×Íà¾×è͵ͺ¡ÅѺ</strong></td>
                   <td width="2%" align="center"><strong>:</strong></td><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">&nbsp;<? if($oDoc->DocRefAns!=""){   echo $oDoc->DocRefAns; } ?></td>
    </tr>    
    <? ?>
    <? if($oDoc->DtID==|| $oDoc->DtID==|| $oDoc->DtID==|| $oDoc->DtID==14){?> 
    <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ªÑé¹µÇÒÁàÃçÇ</strong></td>
                   <td width="2%" align="center"><strong>:</strong></td>
            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">
            <? $oDsl->SearchByKey($oDoc->DslID); $oDsl->GetRecord();  echo "&nbsp;".$oDsl->DslName;?>
             </td></tr>
    <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ªÑ鹤ÇÒÁÅѺ</strong></td>
                   <td width="2%" align="center" ><strong>:</strong></td><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>">
                <? $oDcl->SearchByKey($oDoc->DclID); $oDcl->GetRecord();  echo "&nbsp;".$oDcl->DclName;?></td>
    </tr>
    <? ?>
    <tr height=22><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_1"]; ?>">&nbsp;&nbsp;<strong>ËÁÒÂà˵Ø</strong></td>
                   <td width="2%" align="center"><strong>:</strong></td>
                  <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_16"]; ?>"> 
                    <? if($oDoc->DocShortDesc!=""){ echo "&nbsp;".$oDoc->DocShortDesc;  }  ?>
                  </td>
                </tr>
<? if($oDoc->DocforSign=="Y"){  ?>
    <tr height=22><td width="25%">&nbsp;</td>
                   <td width="2%" align="center">&nbsp;</td>
                  <td > 
                  <input name="" type="checkbox" value="" checked disabled> Å§·ÐàºÕ¹˹ѧÊ×Íŧ¹ÒÁ
                  </td>
                </tr>
    <? ?>
<? 
if($oDoc->sendToPs=="Y"){  ?>
    <tr height=22><td width="25%">&nbsp;</td>
                   <td width="2%" align="center">&nbsp;</td>
                  <td > 
                  <input name="" type="checkbox" value="" checked disabled> Ê觴èǹ
                  </td>
                </tr>
    <? ?>
    <tr><td>&nbsp;</td></tr>
      </table>
      </td></tr></table>
      <? 
                  
//------------------Sign------------------------------------------------------------------?>
        <? 
              
//-----------------Line Doc--------------------------------------------------------------?>
        <br>
      <?  // if($oDlc->DlcView=="Y"){ ?>
       <table width="93%" border="0" align="center" cellpadding="0" cellspacing="0" >
      <tr><td align="right"><a onClick = "showline('<? echo $searchDoc;?>')" style="cursor:pointer;"><img src="../picture/button_showline.jpg" alt=""  border="0" style="cursor:pointer;"></a>
      &nbsp;<a onClick = "showline2('<? echo $searchDoc;?>')" style="cursor:pointer;"><img src="../picture/sign_tc.jpg" alt=""  border="0" style="cursor:pointer;"></a>&nbsp;
      </td></tr>
      </table>
      <table width="93%" border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="#FFCC99" >
      <tr><td><table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" bordercolor="#DADADA" style="border-collapse:collapse"  background="../picture/table_header_bg4.gif">
        <tr>
          <td width="68%" height="25">
            <font color="<?php echo $GLOBALS["COLOR_FONT_1"]; ?>" size="2"><strong>&nbsp;àÊé¹·Ò§à´Ô¹¢Í§Ë¹Ñ§Ê×Í</strong></font>
             </td>
        </tr>
      </table><br>
              <table width="98%" border="0" align="center" cellpadding="0" cellspacing="0" bordercolor="#DADADA" style="border-collapse:collapse">
                <tr> 
                  <td  align="center">
                   <div style="overflow: auto; height: 300px; width: 100%;">
                  <? 
                          $lineDoc
=GetLineDoc($DocID,$oDoc->DocGroup,$oDoc->DsID,$DrsID);
                        
$checkshow=0
                        if(
$lineDoc!=$DrsID){ $lineDoc=$lineDoc.$oRs->DrsID;  $checkshow=1;} //echo "=".$lineDoc."<br>";
                  
                //  echo "-)=".$DocID."-".$oDoc->DocGroup."-".$oRs->DrsID."<br>";
                //  $lineDoc=GetLineDoc2($oDoc->DocGroup,$oRs->DrsID); 
                //echo "lineDoc=".$lineDoc."<br>";
                        
while($lineDoc!=""){
                                list(
$line,$lineDoc)=split(',',$lineDoc,2);
                                
//echo "=".$line."<br>";
                                
$oRs2->SearchByKey($line);
                                
$oRs2->GetRecord();
                                
$oDoc2->SearchByKey($oRs2->DocID);
                                
$oDoc2->GetRecord();
                                
$oDlc3->SearchByKey($oDoc2->DlcID); 
                                
$oDlc3->GetRecord(); 
                                   if(
$oRs2->DsID=="1"){
                            
?>
                                 
                    <table width="90%" border="0" align="center" cellpadding="0" cellspacing="0" bordercolor="#DADADA" style="border-collapse:collapse">
                      <tr height=22>
                        <td colspan="3">&nbsp;&nbsp;<strong>¢éÍÁÙÅ¡ÒÃŧÃѺ¢Í§Ë¹èǧҹ&nbsp;<?  $oDP->SearchByKey($oDlc3->deptId); $oDP->GetRecord();  echo $oDP->deptName;?></strong><br>
                        </td>
                      </tr>
                       <tr height=22>
                         <td width="33%">&nbsp;&nbsp;ª¹Ô´Ë¹Ñ§Ê×Í : <? $oDt->SearchByKey($oDoc2->DtID);  $oDt->GetRecord(); echo $oDt->DtName?></td>
                        <td width="23%">àÅ¢·ÐàºÕ¹<? echo ShowNameRSDoc2($oDoc2->RsID);?> : <?php echo a2th($oDoc2->DocTypeNo);?></td>
                        <td width="44%">Çѹ·Õèŧ·ÐàºÕ¹ : <?php 
                            
list($DocD,$DocT) = split(' ',$oDoc2->DocDateCreate);
                            echo 
abbreDate2($DocD,'/')."&nbsp;".a2th($DocT); ?></td>
                      </tr>
                      <tr height=22>
                        <td colspan="3">&nbsp;&nbsp;ŧÃѺâ´Â : <? $oPS->SearchByKey($oRs2->DrsReceivePersonId); $oPS->GetRecord();   ?>
                          <? echo "&nbsp;".GetPrefix($oPS->prefixId).$oPS->fName."&nbsp;".$oPS->lName?> 
                          <?     $oDlp->SearchByKey($oDlc3->DlpID);  $oDlp->GetRecord();
                                      echo 
"&nbsp;(".ShowNamePosition($oDlp->DlpID,$oDlp->DlpName,$oDP->deptName).")"?></td>
                      </tr>
                      <tr>
                      <td colspan=3><hr color="#C87904"></hr></td>
                      </tr>
                    </table>    
                              <? }else if($oRs2->DsID=="2"){ ?>
                                  <table width="90%" border="0" align="center" cellpadding="0" cellspacing="2" bordercolor="#DADADA" style="border-collapse:collapse">
                                 <tr><td colspan="3">&nbsp;&nbsp;<strong>¢éÍÁÙÅ¡ÒÃàʹÍŧ¹ÒÁ</strong></td></tr>
                                 <tr><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¡Òúѹ·Ö¡µèÍà¹×èͧ</td>
                                         <td width="0%"  align="center" ><strong>:</strong></td>
                                        <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;<? echo nl2br($oRs2->DrsPropose); ?></td>
                                 </tr>
                                 <tr height=22>
                                    <td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¼ÙéàʹÍŧ¹ÒÁ</td>
                                    <td width="0%"  align="center" ><strong>:</strong></td>
                                    <?   $oRs3->SearchByKey($oRs2->DrsFromDrsID);
                                            
$oRs3->GetRecord();
                                    
?>
                                    <td width="75%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>" align="center">
                                    <? $oPS->SearchByKey($oRs2->DrsPsIDCreate); $oPS->GetRecord();   ?>
                                      <? echo GetPrefix($oPS->prefixId).$oPS->fName."&nbsp;".$oPS->lName."&nbsp;"?> 
                                      <? 
                                                  $oDlc5
->SearchByKey($oRs2->DrsDlcIDCreate);  $oDlc5->GetRecord();    
                                                  
$oDlp->SearchByKey($oDlc5->DlpID);  $oDlp->GetRecord();
                                                  echo 
"(".ShowNamePosition($oDlp->DlpID,$oDlp->DlpName,$oDP->SearchDeptName($oDlc5->deptId)).")&nbsp;";  
                                                list(
$DocD,$DocT) = split(' ',$oRs2->DrsReceiveDate );
                                                echo 
abbreDate2($DocD,'/')."&nbsp;".a2th($DocT); 
                                                
?>
                        
                                    </td>
                                  </tr>
                                 
                              <td colspan=3><hr color="#C87904"></hr></td>
                              </tr>
                                 </table>
                            <?             if($oRs2->DrsWSign=='Y'){  //case DrsWSign 
                                            
$oDws->SearchByDrsIDDocID($oRs2->DrsID,$oRs2->DocID);
                                            
$oDws->GetRecord();
                            
?>
                                <table width="90%" border="0" align="center" cellpadding="0" cellspacing="2" bordercolor="#DADADA" style="border-collapse:collapse">
                                 <tr><td colspan="3">&nbsp;&nbsp;<strong>¢éÍÁÙÅ¡ÒÃÃÍàʹͼ͡./˹.</strong></td></tr>
                                 <tr><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¡Òúѹ·Ö¡µèÍà¹×èͧ</td>
                                         <td width="0%"  align="center" ><strong>:</strong></td>
                                        <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;<? echo nl2br($oDws->DocSign); ?></td>
                                 </tr>
                                 <tr height=22>
                                    <td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¼Ùéŧ¹ÒÁ</td>
                                    <td width="0%"  align="center" ><strong>:</strong></td>
                                    <td width="75%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>"  align="center">
                                    <?  $oPS->SearchByKey($oDws->personId); $oPS->GetRecord();   ?>
                                      <? echo GetPrefix($oPS->prefixId).$oPS->fName."&nbsp;".$oPS->lName."&nbsp;"?> 
                                      <?     $oDlc5->SearchByKey($oDws->DlcID);  $oDlc5->GetRecord();    
                                                  
$oDlp->SearchByKey($oDlc5->DlpID);  $oDlp->GetRecord();
                                                  echo 
"(".ShowNamePosition($oDlp->DlpID,$oDlp->DlpName,$oDP->SearchDeptName($oDlc5->deptId)).")&nbsp;";  
                                                list(
$DocD,$DocT) = split(' ',$oDws->signDateTime);
                                                echo 
abbreDate2($DocD,'/')."&nbsp;".a2th($DocT); 
                                                
?>
                                    </td>
                                  </tr>
                                <tr>
                              <td colspan=3><hr color="#C87904"></hr></td>
                              </tr>
                                 </table>
                            <? //case DrsWSign?>
                             <? }else if($oRs2->DsID=="3"){  
                                               
$oRs4->SearchByKey($oRs2->DrsFromDrsID);
                                            
$oRs4->GetRecord();
                                            if(
$oRs4->DrsByPass!="Y"){
                           
?>
                                   <table width="90%" border="0" align="center" cellpadding="0" cellspacing="2" bordercolor="#DADADA" style="border-collapse:collapse">
                                 <tr><td colspan="3">&nbsp;&nbsp;<strong>¢éÍÁÙÅ¡ÒÃŧ¹ÒÁ</strong></td></tr>
                                  <tr><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¡Òúѹ·Ö¡µèÍà¹×èͧ</td>
                                         <td width="0%"  align="center" ><strong>:</strong></td>
                                        <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;<? echo nl2br($oRs2->DrsSign); ?></td>
                                 </tr>
                                 <tr height=22>
                                    <td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¼Ùéŧ¹ÒÁ</td>
                                    <td width="0%"  align="center" ><strong>:</strong></td>
                                    <td width="75%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>" align="center">
                                    <? $oPS->SearchByKey($oRs2->DrsPsIDCreate); $oPS->GetRecord();   ?>
                                      <? echo GetPrefix($oPS->prefixId).$oPS->fName."&nbsp;".$oPS->lName."&nbsp;"?> 
                                      <?     $oDlc5->SearchByKey($oRs2->DrsDlcIDCreate);  $oDlc5->GetRecord();    
                                                  
$oDlp->SearchByKey($oDlc5->DlpID);  $oDlp->GetRecord();
                                                  echo 
"(".ShowNamePosition($oDlp->DlpID,$oDlp->DlpName,$oDP->SearchDeptName($oDlc5->deptId)).")&nbsp;";  
                                                list(
$DocD,$DocT) = split(' ',$oRs2->DrsReceiveDate );
                                                echo 
abbreDate2($DocD,'/')."&nbsp;".a2th($DocT); 
                                                
?>
                                    </td>
                                  </tr>
                                <tr>
                              <td colspan=3><hr color="#C87904"></hr></td>
                              </tr>
                                 </table>
                                 <?  }  
                                      }else if(
$oRs2->DsID=="0" || $oRs2->DsID=="4" || $oRs2->DsID=="5"){  
                                             
//$oRs6->SearchByDocGroupDrsFromDrsID($oRs2->DocGroup,$oRs2->DrsID);            
                                             
$oRs6->SearchByKey($oRs2->DrsID);
                                            
$oRs6->GetRecord();        
                                         
//if($oRs2->DrsSendDate!="0000-00-00 00-00-00"){  //show status=3 send to person 
                                
?>
                                 <table width="90%" border="0" align="center" cellpadding="0" cellspacing="2" bordercolor="#DADADA" style="border-collapse:collapse">
                                 <tr><td colspan="3">&nbsp;&nbsp;<strong>¢éÍÁÙÅ¡ÒÃÊ觶֧¼ÙéÃѺ¼Ô´ªÍº</strong></td></tr>
                                 <?     
                                         
if($oRs6->PtID!=&& $oRs6->PtID!=""){ 
                                             
$oPt->SearchByKey($oRs6->PtID);
                                            
$oPt->GetRecord();
                                 
?>
                                 <? if($oRs6->DrsSendDocNew!="0000-00-00 00:00:00"){  ?>
                                  <tr><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;Êè§à¾ÔèÁàµÔÁ</td>
                                            <td><strong>:</strong></td>
                                            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;&nbsp;&nbsp;
                                            <? list($DocD2,$DocT2) = split(' ',$oRs6->DrsSendDocNew);
                                                echo 
abbreDate2($DocD2,'/')."&nbsp;".a2th($DocT2); 
                                             
?></td>
                                </tr>
                                <? ?>
                                 <tr><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;ÅѡɳÐ˹ѧÊ×Í</td>
                                            <td><strong>:</strong></td>
                                            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;&nbsp;&nbsp;&nbsp;<? echo $oPt->PtName?></td>
                                </tr>
                                <? ?>
                                <? if($oRs6->AnID!=&& $oRs6->AnID!=""){ 
                                          
$oAn->SearchByKey($oRs6->AnID);
                                        
$oAn->GetRecord();
                                 
?>
                                 <tr><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¢éÍÁÙÅ¢Öé¹àÇçº<? echo $oDoc2->DocShowInOut?></td>
                                            <td><strong>:</strong></td>
                                            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;&nbsp;&nbsp;&nbsp;<? echo $oAn->AnName?>
                                            <br>&nbsp;&nbsp;&nbsp;&nbsp;á¨é§¢Öé¹àÇçº&nbsp;<? echo ShowNameonweb($oDoc2->DocShowInOut); ?>
                                            <br>&nbsp;&nbsp;&nbsp;&nbsp;Çѹ·Õè»ÃСÒÈ¢Öé¹àÇçº&nbsp;
                                            <?  if($oRs6->DrsstartDatePost!="0000-00-00"){
                                                        if(
$oRs6->DrsstartDatePost==$oRs6->DrsendDatePost){ 
                                                            echo 
abbreDate2($oRs6->DrsstartDatePost,'/');
                                                        }else{
                                                             echo  
abbreDate2($oRs6->DrsstartDatePost,'/')."&nbsp;¶Ö§&nbsp;".abbreDate2($oRs6->DrsendDatePost,'/');
                                                        }
                                                    }
                                            
?>
                                            </td>
                                </tr>
                                <? ?>
                                 <tr><td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¡Òúѹ·Ö¡µèÍà¹×èͧ</td>
                                         <td width="0%"  align="center" ><strong>:</strong></td>
                                        <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;<? echo nl2br($oRs6->DrsPropose); ?></td>
                                 </tr>
                                 <tr height=22>
                                    <td width="25%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¼ÙéÊè§Ë¹Ñ§Ê×Í</td>
                                    <td width="0%"  align="center" ><strong>:</strong></td>
                                    <td width="75%" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>" align="center">
                                    <? $oPS->SearchByKey($oRs6->DrsPsIDCreate); $oPS->GetRecord();   ?>
                                      <? echo GetPrefix($oPS->prefixId).$oPS->fName."&nbsp;".$oPS->lName."&nbsp;"?> 
                                      <?     
                                                  $oDlc5
->SearchByKey($oRs6->DrsDlcIDCreate);  $oDlc5->GetRecord();    
                                                  
$oDlp->SearchByKey($oDlc5->DlpID);  $oDlp->GetRecord();
                                                  echo 
"(".ShowNamePosition($oDlp->DlpID,$oDlp->DlpName,$oDP->SearchDeptName($oDlc5->deptId)).")&nbsp;";  
                                                
$oRs8->SearchByKey($oRs6->DrsFromDrsID);
                                                
$oRs8->GetRecord();
                                                
                                                list(
$DocD,$DocT) = split(' ',$oRs8->DrsSendDate);
                                                echo 
abbreDate2($DocD,'/')."&nbsp;".a2th($DocT); 
                                                
?>
                                    </td>
                                  </tr>
                                  <?      
                                  
//            $oDoc3->SearchByKey($oRs6->DocID); $oDoc3->GetRecord(); //echo "----".$oDoc3->DocID;
                                              
if($oRs6->DrsDocDueDate!="0000-00-00"){ ?>
                                            <tr><td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¡Ó˹´ÃÐÂÐàÇÅÒ´Óà¹Ô¹¡ÒÃ</td>
                                            <td><strong>:</strong></td>
                                            <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;&nbsp;&nbsp;&nbsp;ÀÒÂã¹Çѹ·Õè&nbsp;<? echo abbreDate2($oRs6->DrsDocDueDate,'/');?></td></tr>
                                <? ?>
                                <?  $MainPs=$oRs7->SearchByDrsFromDrsIDDrsMainPsY($oRs6->DrsFromDrsID);
                                        if(
$MainPs!="" && $MainPs!="0"){
                                             
$oPS2->SearchByKey($MainPs); $oPS2->GetRecord(); 
                                
?>
                                <tr>
                                    <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_21"]; ?>">&nbsp;&nbsp;¼ÙéÃѺ¼Ô´ªÍºËÅÑ¡</td><td><strong>:</strong></td>
                                    <td bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_22"]; ?>">&nbsp;&nbsp;&nbsp;&nbsp;<? echo GetPrefix($oPS2->prefixId).$oPS2->fName."&nbsp;".$oPS2->lName."&nbsp;"?></td>
                                </tr>
                                <?  ?>
                                <tr>
                              <td colspan=3><hr color="#C87904"></hr></td>
                              </tr>
                                 </table>
                                 <?  //show status=3 send to person?>
                          <?        // }
                        
}    //each lineDoc  ?>
                 </div> </td>
                </tr>
                
                <tr><td>&nbsp;</td></tr>
              </table>
      </td></tr>
      </table>  
      <table width="93%" border="0" align="center">
        <tr><td align="right" colspan="2"><a href="processEntryDoc.php?DrsID=<?php echo $DrsID;?>&method=setDelete&flagshow=<? echo $flagshow?>" onClick='return checkDelete()'><img src="../picture/trash.gif" alt="ź˹ѧÊ×Í"  border="0">
        <font color="<?php echo $GLOBALS["COLOR_FONT_2"]; ?>" size="2"><strong>ź˹ѧÊ×Í</strong></font> 
        </a></td></tr>
       </table>
      <? //} //DrsView?>
      
    
  <br>
  <? if($oRs->DrsDocReceiveDate=='0000-00-00 00:00:00'){   
            
?>
<table width="93%"  border="0" align="center" cellpadding="0" cellspacing="1" bordercolor="#DADADA" style="border-collapse:collapse">
        <tr><td align="left" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_20"]; ?>">&nbsp;&nbsp;<strong><img src="../picture/alert.gif" alt=""  border="0" >&nbsp;á¨é§¡ÒÃÊ觼Դ</strong></td></tr>
     <tr><td align="right" bgcolor="<?php echo $GLOBALS["COLOR_BG_TD_7"]; ?>">
     ¤ÓªÕéᨧ :: <textarea name="DrsSendBack" cols="30" rows=""  onKeyPress="if(event.keyCode==39){  alert('ÃкºäÁèÊÒÁÒöºÑ¹·Ö¡µÑÇÍÑ¡ÉùÕéä´é!!'); return false;}else{     event.keyCode=KeyfontThai(event.keyCode,'<? echo $InputThai?>'); return event.keyCode;  }"></textarea>
     <input type="submit" name="add" value="á¨é§¡ÒÃÊ觼Դ" onClick="return checkFormat2('<? echo $oRs->DsID?>','<? echo $DocID?>');" <? if($oRs->DocGroup!=$MaxDocGroup){  echo "disabled"; }?>>
     &nbsp;&nbsp;</td></tr></table><br>
     <? ?>
     </fieldset>
<table width="95%" border="0" align="center">
<tr><td align="right" colspan="2" height="25">
<? if($oRs->DrsDocReceiveDate=='0000-00-00 00:00:00'){   
            
?>
            <input name="accept" type="submit" value="<? if($oRs->PtID=="1"){ echo "ÃѺ·ÃÒº";  }else{  echo "ÃѺ·ÃÒº áÅж×Í»¯ÔºÑµÔ"; } ?>" onClick="return checkFormat('<? echo $oRs->DsID?>','<? echo $DocID?>','<? echo $totalDocRead;?>','<? echo $countDrsDocRead;?>','<? echo $countdoc?>','<? echo $oRs->DrsReadDoc?>','<? echo $DaSeq?>');" <? if($oRs->DocGroup!=$MaxDocGroup){  echo "disabled"; }?>>
<? }else{  
            list(
$DocD,$DocT) = split(' ',$oRs->DrsDocReceiveDate);
            echo 
"<strong>"
            if(
$oRs->DsID=='7'){  echo "á¨é§¡ÒÃÊ觼Դ :: "; }else{   if($oRs->PtID=="1"){ echo "ÃѺ·ÃÒº";  }else{  echo "ÃѺ·ÃÒº áÅж×Í»¯ÔºÑµÔ"; } }
            echo 
"</strong>";
            if(
$oRs->DsID=='7'){  echo $oRs->DrsSendBack."&nbsp;&nbsp;&nbsp;";  }
            echo 
"&nbsp;".abbreDate2($DocD,'/')."&nbsp;".a2th($DocT)."&nbsp;&nbsp;"
      } 
?>
&nbsp;<input type="button" name="cancel" value="¡ÅѺ˹éÒËÅÑ¡" onClick="location.href = 'entryDoc.php'"><br><br></td></tr>
        <tr> 
          <td width="76" align="left"><font color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>" size="2">&nbsp;<strong>ËÁÒÂà˵ؠ
            : </strong>&nbsp;</font></td>
          <td width="618" align="left"><img src="../picture/allregistered_ico.gif" alt=""  border="0" > 
            <font color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>" size="2">¤ÅÔ¡à¾×èÍà»Ô´´Ùá¿éÁ˹ѧÊ×Í </font>
            &nbsp;&nbsp;&nbsp;<font color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>" size="2"><img src="../picture/trash.gif" alt="ź˹ѧÊ×Í"  border="0">&nbsp;¤ÅÔ¡à¾×èÍź˹ѧÊ×Í·ÕèÍèÒ¹áÅéÇ</font>
            </td>
        </tr>
            <tr> 
          <td width="76">&nbsp;</td>
          <td width="618" align="left">
            <font color="<?php echo $GLOBALS["COLOR_FONT_3"]; ?>" size="2">&nbsp; </font></td>
        </tr></table>
        <input type="hidden" name="method">
        <input type="hidden" name="DocID" value="<? echo $DocID?>">
        <input type="hidden" name="DrsID" value="<? echo $oRs->DrsID?>">
</form>
</td>
</tr>
</table>
</body>
</html>

<script language="javascript">
function checkFormat(p,q,r,s,t,u,m){

         if(m==0 && p==0){
            alert("¡ÃسÒÍèÒ¹á¿éÁ˹ѧÊ×Í¡è͹¤ÅÔ¡ÃѺ");
            return false ;
        }else if(r==s || t==0){
            var agree=confirm("¤Ø³µéͧ¡ÒäÅÔ¡ÃѺ·ÃҺ˹ѧÊ×Íá¹è¹Í¹ãªèËÃ×ÍäÁè ?");
            if (agree){
                document.ff.method.value="acceptDoc";
                document.ff.submit();
                return true;
            }else{
                return false ;
            }    
        }else{
            alert("¡ÃسÒÍèÒ¹á¿éÁ˹ѧÊ×Í·Ø¡á¿éÁ¡è͹¤ÅÔ¡ÃѺ");
            return false ;
        }
}
function checkFormat2(p,q){
        if(document.ff.DrsSendBack.value == ""){
                alert("¡ÃسҡÃÍ¡¤ÓªÕéᨧà¾×èÍá¨é§¡ÒÃÊ觼Դ");
                document.ff.DrsSendBack.focus();
                return false;
        }
        window.alert("ËÁÒÂà˵ؠ:: àÁ×èÍ¡´á¨é§¡ÒÃÊ觼ԴáÅéÇ\n˹ѧÊ×͹Õé¨ÐäÁè¶Ù¡Å§ÃѺä´éÍÕ¡");
        var agree=confirm("¤Ø³µéͧ¡Òàá¨é§¡ÒÃÊ觼Դ¡ÑºË¹Ñ§Ê×͹Õéá¹è¹Í¹ãªèËÃ×ÍäÁè ?");
            if (agree){
                document.ff.method.value="SendBack";
                document.ff.submit();
                return true;
            }else{
                return false ;
            }
}
function checkDelete(){
        var agree=confirm("¤Ø³µéͧ¡ÒÃź˹ѧÊ×Í·ÕèÍèÒ¹áÅéÇá¹è¹Í¹ãªèËÃ×ÍäÁè ?");
        if (agree){
            return true;
        }else{
            return false ;
        }
}
 function showline(p){ 
             FileName = "showlinedocTable.php?searchDoc="+p;
            var w=900;  
            var h=500;
            strOption = "scrollbars=yes,left=370,top=100,menubar=1,width=" + w + ",height=" + h;
            window.open(FileName,"",strOption);
}
 function showline2(p){ 
             FileName = "showlinedocTable2.php?searchDoc="+p;
            var w=900;  
            var h=500;
            strOption = "scrollbars=yes,left=370,top=100,menubar=1,width=" + w + ",height=" + h;
            window.open(FileName,"",strOption);
}
</script>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0167 ]--