403Webshell
Server IP : 119.59.102.212  /  Your IP : 216.73.216.183
Web Server : Apache/2
System : Linux narin 2.6.32-042stab142.1 #1 SMP Tue Jan 28 23:44:17 MSK 2020 x86_64
User : yangkam ( 1022)
PHP Version : 5.6.40
Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/yangkam/domains/yangkam.go.th/private_html/coremain/module/e_service/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/yangkam/domains/yangkam.go.th/private_html/coremain/module/e_service/e_service.php
<?php
$navig['send_mail']="ร้องเรียน-ร้องทุกข์";
navigator($navig);
echo"<br>";
bar_header("ร้องเรียน-ร้องทุกข์"); // Bar_Header
fieldset_top("บริการ ร้องเรียน-ร้องทุกข์");

import_request_variables('pG', 'p_');

if($_SESSION['admin_web']=="admin" || $_SESSION['per']=="ok"){
  $array_title = array();
  $sel_title = "select * from cms_service_title";
  $que_title = mysql_query($sel_title);
  while($obj_title = mysql_fetch_assoc($que_title)){
    $array_title[$obj_title['title_id']] = $obj_title;
  }
?>

<form name="fm_title_new" method="post" action="index.php?mod=e_service_update&path=e_service" onsubmit="return check_new();" style="margin: 0;">
  <table width="90%">
    <tr>
      <td><img src="coremain/images/marker.gif" />&nbsp;<b>ชื่อหัวข้อ</b></td>
      <td>
        <input type="text" name="title_name" size="40" />
        <button type="submit" id="Submit" class="ui-button ui-widget ui-corner-all ui-state-focus" style="padding: 2px 5px; font-size: 12px;"><img src="coremain/images/bullet2.gif" /> เพิ่มหัวข้อ</button>
        <br/><br/>
      </td>
    </tr>
  </table>
</form>

<table width="80%" border="0" cellpadding="0" cellspacing="0" align="center">
  <tr>
    <td>
      <table width="100%" border="1" cellpadding="3" cellspacing="0" style="border-collapse: collapse;" id="tb_title">
        <?php
          foreach($array_title as $id => $data){
            $selESv = "select * from cms_eservice where type_id = '$id'";
            $queESv = mysql_query($selESv);
            $numEsv = mysql_num_rows($queESv);
            $chk_del = 1;// $numEsv > 0 ? 0 : 1;
        ?>
        <tr class="row_data">
          <td>
            <?php if($p_title_edit == $id){ ?>
              <form name="fm_title_edit" method="post" action="index.php?mod=e_service_update&path=e_service" onsubmit="return check_edit();" style="margin: 0;">
                <input type="hidden" name="title_id" value="<?= $id ?>" />
                &nbsp;&nbsp;&bullet; <input type="text" name="title_edit" value="<?= $data['title_name'] ?>" size="40" />&nbsp;&nbsp;<a href="javascript:void(0);" class="title_update"><img src='coremain/images/save.png' title='บันทึกข้อมูล' border='0'></a>
                &nbsp;<a href="index.php?mod=e_service&path=e_service"><img src='coremain/images/ban.png' title='ยกเลิก' border='0'></a>
              </form>
            <?php }else{ ?>
              &nbsp;&nbsp;&bullet; <?= $data['title_name'] ?>
                <div style="float: right;">
                  <?php if($data['title_status'] == '1'){ ?>
                    <a href='index.php?mod=e_service_update&path=e_service&id=<?= $id ?>&status=0'><img src='coremain/images/show.gif' border='0'></a>
                  <?php }else{ ?>
                    <a href='index.php?mod=e_service_update&path=e_service&id=<?= $id ?>&status=1'><img src='coremain/images/hide.gif' border='0'></a>
                  <?php } ?>
                  &nbsp;<a href="index.php?mod=e_service&path=e_service&title_edit=<?= $id ?>"><img src='coremain/images/edit.gif' title='แก้ไขข้อมูล' border='0'></a>
                  <?php if($chk_del){ ?>
                  &nbsp;<a href="javascript:void(0)" class="del_data" id="<?= $id ?>"><img src='coremain/images/del1.gif' title='ลบข้อมูล' border='0'></a>
                  <?php }else{
                    echo '&nbsp;&nbsp;&nbsp;&nbsp;';
                  } ?>
                </div>
            <?php } ?>
          </td>
        </tr>
        <?php } ?>
      </table>
    </td>
  </tr>
</table>

<br/><br/>
<button type="button" onclick="window.location.href='index.php?mod=e_service_report&path=e_service'" class="ui-button ui-widget ui-corner-all ui-state-focus" style="padding: 5px 10px;">รายงาน ร้องเรียนการทุจริต</button>
<br/><br/>

<script language="javascript">
  
  function check_new(){
    if(document.fm_title_new.title_name.value == ''){
      alert('กรุณากรอกชื่อหัวข้อ !')
      document.fm_title_new.title_name.focus();
      return false;
    }else{
      return true;
    }
  }
  
  $('.title_update').on('click', function(){
    $('form[name="fm_title_edit"]').submit();
  });
  function check_edit(){
    if(document.fm_title_edit.title_edit.value == ''){
      alert('กรุณากรอกชื่อหัวข้อ !')
      document.fm_title_edit.title_edit.focus();
      return false;
    }else{
      return true;
    }
  }
  
  $('.del_data').on('click', function(){
    if(confirm("คุณต้องการลบหัวข้อนี้ ?")){
      var id = $(this).attr('id');
      window.location.href = "index.php?mod=e_service_update&path=e_service&del_id="+ id;
    }
  });
  
</script>

<?php }else{
  $array_title = array();
  $sel_title = "select * from cms_service_title where title_status = '1'";
  $que_title = mysql_query($sel_title);
  while($obj_title = mysql_fetch_assoc($que_title)){
    $array_title[$obj_title['title_id']] = $obj_title;
  }
?>

<label>ข้อมูลของท่านจะถูกส่งไปยังเจ้าหน้าที่ ที่เกี่ยวข้อง</label>

<form  action="index.php?mod=e_service_output&path=e_service" method="post" enctype="multipart/form-data" name="add">
  <table width="98%" border="0" align="center" cellpadding="1" cellspacing="3">
    <tr height="40">
      <td width="25%" style="vertical-align: top;"><div align="left"><img src='coremain/images/marker.gif'> <strong>รายการติดต่อ</strong></div></td> 
      <td>
		<?php foreach($array_title as $id => $value){ ?>
		  <input type="radio" name="service_title" <?php if($p_e == $id) echo 'checked'; ?> value="<?= $id ?>" /> <?= $value['title_name'] ?><br/>
        <?php } ?>
        <!--<select name="service_title" style="width: 370px;">
          <option value="">เลือกรายการติดต่อ</option>
          <?php /*foreach($array_title as $id => $value){ ?>
            <option value="<?= $id ?>" <?php if($p_e == $id) echo 'selected'; ?>><?= $value['title_name'] ?></option>
          <?php }*/ ?>
        </select>-->
      </td>
    </tr>
    
    <tr height="40">
      <td width="25%"><div align="left"><img src='coremain/images/marker.gif'> <strong>เรื่อง</strong></div></td> 
      <td><div align="left"><input name="topic" type="text" size="50"></div></td> 
    </tr>
    
    <?php text_editor("445", "260", "รายละเอียด", 2, $data['fulltexts']); ?>

    <tr height="40">      	
      <td><div align="left"><img src='coremain/images/marker.gif'> <strong>ไฟล์แนบ</strong></div></td> 
      <td><div align="left"><input name="file_send" type="file" size="46"></div></td> 
    </tr>

    <tr height="40">      	
      <td><div align="left"><img src='coremain/images/marker.gif'> <strong>ชื่อผู้ติดต่อ</strong></div></td> 
      <td><div align="left"><input name="sender_name" type="text" size="50"></div></td> 
    </tr>

    <tr height="40">      	
      <td><div align="left"><img src='coremain/images/marker.gif'> <strong>โทรศัพท์</strong></div></td> 
      <td><div align="left"><input name="sender_tel" type="text" size="50"></div></td> 
    </tr>

    <tr height="40">      	
      <td><div align="left"><img src='coremain/images/marker.gif'> <strong>อีเมล์</strong></div></td> 
      <td><div align="left"><input name="sender_mail" type="text" size="50" value="-"></div></td> 
    </tr>

    <tr height='40px'>
      <td ><div align="left"><img src='coremain/images/marker.gif'> <strong>รหัสลับ</strong></div></td>
      <td>
        <div class='iframe' valign=top>
          <iframe name='ifrm' id='ifrm' src='coremain/module/e_service/secure_image.php' frameborder='0' WIDTH='120' HEIGHT='20' SCROLLING='no'></iframe>
          <a href='javascript:void(0)' onclick="loadIframe('ifrm', 'coremain/module/e_service/secure_image.php')"><img src='coremain/module/question/img/view_refresh.png' border=0 title="เปลี่ยนรูปใหม่"></a>
        </div>
      </td>
    </tr>
    <tr height='30px'>
      <td><div align="left"><img src='coremain/images/marker.gif'> <strong>กรอกรหัสลับ</strong></div></td>
      <td><input name='secure_code'></td>
    </tr>
    
      <tr>
      <td colspan="2" align="center">
        <button type="button" id="send_data" class="ui-button ui-widget ui-corner-all ui-state-focus" style="padding: 5px 10px;">ส่งข้อมูล</button>
      </td>
    </tr>
    
  </table>
</form>

<script language="javascript">
  
  function loadIframe(iframeName, url) {
    if (window.frames[iframeName]) {
      $('input[name="secure_code"]').val('');
      window.frames[iframeName].location = url;
      return false;
    }
    return true;
  }
  
  function checkadd() {
    var ret = true;
    if(document.add.service_title.value == ''){
      alert("กรุณาเลือกรายการติดต่อ !") ;
      document.add.service_title.focus() ;
      ret &= false ;
    }else if(document.add.topic.value=="") {
      alert("กรุณากรอกเรื่อง !") ;
      document.add.topic.focus() ;
      ret &= false ;
    }else if(document.add.sender_name.value==''){
      alert('กรุณากรอกชื่อผู้ติดต่อ !');
      document.add.sender_name.focus();
      ret &= false;
    }else if(document.add.secure_code.value == ''){
      alert('กรุณากรอกรหัสลับ !');
      document.add.secure_code.focus();
      ret &= false;
    }else{
      $.ajax({
        url: 'coremain/module/e_service/set_secure_code.php',
        type: 'post',
        async: false,
        data: {secure_code: $('input[name="secure_code"]').val()},
        success: function(response){
          if(response == 'OK'){
            ret &= true;
          }else{
            alert('รหัสลับไม่ถูกต้อง !');
            $('input[name="secure_code"]').focus();
            ret &= false;
          }
        }
      });
    }
    
    return ret;
  }
  
  $('#send_data').on('click', function(){
    var chk = checkadd();
    if(chk){
      $('form[name="add"]').submit();
    }
  });
  
</script>

<?php
}

echo fieldset_down();
?>

Youez - 2016 - github.com/yon3zu
LinuXploit