403Webshell
Server IP : 119.59.102.212  /  Your IP : 3.141.244.88
Web Server : Apache/2
System : Linux narin 2.6.32-042stab142.1 #1 SMP Tue Jan 28 23:44:17 MSK 2020 x86_64
User : yangkam ( 1022)
PHP Version : 5.6.40
Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/yangkam/domains/yangkam.go.th/public_html/coremain/module/link/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/yangkam/domains/yangkam.go.th/public_html/coremain/module/link/manage_header1.php
<?php
session_start();
include ("../../function_sql_query.php");
include ("../../function_form.php");
echo"<meta http-equiv='Content-Type' content='text/html; charset=utf-8'>";
echo"<link href='../../ccs/style.php' rel='stylesheet' type='text/css'>";
echo "<title>จัดการเมนู</title>";
import_request_variables('pG', 'p_');
if($p_oncheck!="")						{	     $oncheck=trim($p_oncheck);				}
if($p_id_top!="")						{	     $id_top=trim($p_id_top);				}
if($p_id_subs!="")						{	     $id_subs=trim($p_id_subs);				}
if($p_namemenu!="")						{	     $namemenu=trim($p_namemenu);			}
if($p_dele!="")							{	     $dele=trim($p_dele);					}
if($p_web_name!="")						{	     $web_name=trim($p_web_name);			}
if($p_module!="")						{	     $module=trim($p_module);				}
if($p_id_type!="")						{	     $id_type=trim($p_id_type);				}
if($p_check_up!="")						{	     $check_up=trim($p_check_up);			}
if($p_id_show!="")						{	     $id_show=trim($p_id_show);				}
if($p_id_order!="")						{	     $id_order=trim($p_id_order);			}
if($p_id_del!="")						{	     $id_del=trim($p_id_del);				}
if($p_name!="")							{	     $name=trim($p_name);					}

if($_SESSION[web_name]=="")		$_SESSION[web_name]=$web_name;
include("../../../$_SESSION[web_name]/connect.php");
if($oncheck==1){	

?>
		<script language="JavaScript"> 
			window.opener.location.href='../../../index.php';
			window.close();
		</script>
<?php
}
// ############################################## เมนูย่อย
// แก้ไขเมนูย่อย
if($check_up==1){
	$sql="UPDATE `cms_menu_sub` SET  name='$namemenu'  WHERE `id_sub` ='$id_subs'";
	$result=mysql_query($sql) or die(mysql_error());
}
// ซ่อน - แสดง ข้อมูล
if($id_subs!="" and $id_show==1){ 
		$sql="UPDATE `cms_menu_sub` SET `status` = '0'  WHERE id_sub ='$id_subs'";
		$result=mysql_query($sql) or die(mysql_error());
}if($id_subs!="" and $id_show==2){
		$sql="UPDATE `cms_menu_sub` SET `status` = '1'  WHERE id_sub ='$id_subs'";
		$result=mysql_query($sql) or die(mysql_error());
}
//  เลื่อนตำแหน่งเมนู ขึ้น-ลง 
if($id_subs!="" and $id_order!=""){
		$sql="SELECT * FROM `cms_menu_sub` WHERE  id_sub='$id_subs'";
		$re=mysql_query($sql) or die(mysql_error());
		$data=mysql_fetch_array($re);
			if($id_order==1){		$up=$data[position]-1; }
			if($id_order==2){		$up=$data[position]+1; }
		// แก้ไขเลื่อนขึ้น
		$sql="UPDATE `cms_menu_sub` SET position='$up' WHERE id_sub ='$data[id_sub]'";
		$re=mysql_query($sql) or die(mysql_error());
		// แก้ไขเลื่อนลง
		$sql="UPDATE `cms_menu_sub` SET position='$data[position]'  WHERE id_sub!='$data[id_sub]' and position='$up'";
		$re=mysql_query($sql) or die(mysql_error());
}
// ลบข้อมูลทุกอย่างใน โมดูล
if($id_del!="" and $module!=""){
			if($module=="blog") {
				$sql="DELETE FROM `cms_blog`  WHERE id_sub='$id_del'";
				$re=mysql_query($sql) or die(mysql_error());

				$sql="DELETE FROM `cms_menu_sub`  WHERE id_sub='$id_del'";
				$re=mysql_query($sql) or die(mysql_error());
			}
			if($module=="news_page") {
				$sql="DELETE FROM `cms_menu_sub`  WHERE id_sub='$id_del'";
				$re=mysql_query($sql) or die(mysql_error());

				$sql1="select pic1,pic2,pic3,pic4,files from cms_news_page where id_sub='$id_del'";
				$result1=mysql_query($sql1);
				$data1=mysql_fetch_row($result1);
				if($data1[0]!="")		{			unlink("../../../$_SESSION[web_name]/mainfile/$data1[0]");		}
				if($data1[1]!="")		{			unlink("../../../$_SESSION[web_name]/mainfile/$data1[1]");		}
				if($data1[2]!="")		{			unlink("../../../$_SESSION[web_name]/mainfile/$data1[2]");		}
				if($data1[3]!="")		{			unlink("../../../$_SESSION[web_name]/mainfile/$data1[3]");		}
				if($data1[4]!="")		{			unlink("../../../$_SESSION[web_name]/mainfile/$data1[4]");		}
				$sql = "delete from cms_news_page where id_sub='$id_del'";
				$result = mysql_query($sql) or die(mysql_error());
			}
			
			if($module=="faq") {
				$sql="DELETE FROM `cms_faq`  WHERE id_sub='$id_del'";
				$re=mysql_query($sql) or die(mysql_error());	

				$sql="DELETE FROM `cms_menu_sub`  WHERE id_sub='$id_del'";
				$re=mysql_query($sql) or die(mysql_error());		
			}

			if($module=="director_chart") {
				$sql="DELETE FROM `cms_menu_sub`  WHERE id_sub='$id_del'";
				$re=mysql_query($sql) or die(mysql_error());	
				
				
				$sql="SELECT * FROM cms_director_chart WHERE id_sub='$id_del'";
				$re=mysql_query($sql);
					while($data=mysql_fetch_array($re)){							
						$sql="SELECT * FROM cms_director_chart_profile WHERE id_chart=$data[id_chart]";
						$re=mysql_query($sql);
							while($data=mysql_fetch_array($re)){
							if($data[picture]!="")		{	
								unlink("../../../$_SESSION[web_name]/module_chart/$id_del/$data[picture]");	
								}
								$sql = "delete from cms_director_chart_profile where id_chart='$data[id_chart]'";
								$result = mysql_query($sql) or die(mysql_error());							
							}
					}	
					$sql = "delete from cms_director_chart where id_sub='$id_del'";
						$result = mysql_query($sql) or die(mysql_error());		
			}
						

			if($module=="link") { // Level 1
				if($_SESSION['id_del']=="")  $_SESSION['id_del']=$id_del;
				$sql="SELECT * FROM cms_link_group WHERE id_sub='$_SESSION[id_del]'";
				$re=mysql_query($sql);
				$ch_1=mysql_num_rows($re);
						if($ch_1>=1)
						{
						while($data=mysql_fetch_array($re)){
							$sql="DELETE FROM cms_link_group WHERE id_group='$data[id_group]'";
							$result=mysql_query($sql);

							// DELETE cms_link_group
						$sqla="select id_link,picture from cms_link where id_group='$data[id_group]' order by id_link";
							$resulta=mysql_query($sqla);
							$ch_2=mysql_num_rows($resulta);
			if($ch_2>=1){
			while($dataa=mysql_fetch_array($resulta)){
			if($dataa[picture]!="")		{			unlink("../../../$_SESSION[web_name]/mainfile/$dataa[picture]");		}
													$sql="DELETE FROM cms_link WHERE id_link=$dataa[id_link]";
													$result=mysql_query($sql);
										}
									}
							}
				}
				$sql="DELETE FROM cms_menu_sub WHERE id_sub='$_SESSION[id_del]'";
				$result=mysql_query($sql);
				session_unregister("id_del");
			}// End Level 1

}


// ######################################## เพิ่มเมนูย่อย ในโมดูลประเภทต่าง ๆ 
if($module!="" and $namemenu!="" and $check_up!=1){
// หาค่า id_sub Max ของ  cms_menu_sub
$maxid="select max(id_sub+1) from `cms_menu_sub`";
$resultmaxid=mysql_query($maxid);
$datamaxid=mysql_fetch_row($resultmaxid);
if($datamaxid[0]=="") { $datamaxid[0]=1;}

// หาค่า position Max ของ id_top นั้น ๆ ใน cms_menu_sub
$maxposition="select max(position+1) from `cms_menu_sub` WHERE id_top='$id_top'";
$resultmaxposition=mysql_query($maxposition);
$datamaxposition=mysql_fetch_row($resultmaxposition);
if($datamaxposition[0]=="") { $datamaxposition[0]=1;}

$url="index.php?mod=$module&path=$module&id_sub=$datamaxid[0]";

// Blog
		if($module=="blog"){
		// Insert cms_menu_sub
			$sql="INSERT INTO `cms_menu_sub` (`id_sub` ,`id_top`,`id_type` ,`name` ,`url` ,`position` ,`status`) VALUES ('$datamaxid[0]', '$id_top', '$id_type','$namemenu', '$url', '$datamaxposition[0]', '1')";
			$result = query($sql,TRUE);
		// Insert cms_blog
			$sql="INSERT INTO `cms_blog` (`id_blog`,`id_sub`,`fulltexts`) VALUES ('','$datamaxid[0]','')";
			$result = query($sql,TRUE);
		}
// News
		if($module=="news_page"){
			// Insert cms_menu_sub
			$sql="INSERT INTO `cms_menu_sub` (`id_sub` ,`id_top`,`id_type` ,`name` ,`url` ,`position` ,`status`) VALUES ('$datamaxid[0]', '$id_top', '$id_type','$namemenu', '$url', '$datamaxposition[0]', '1')";
			$result=query($sql);	
			// Insert_clms_news_page
			$sql="INSERT INTO `cms_news_page` VALUES ('', '$datamaxid[0]', '$id_type', '', '', '0000-00-00', '0000-00-00', '', '', '', '', '', '', '', '', '', '', '', '', '', '', '1', 0, 0)";		
			$result=query($sql);	
			}
// Link
		if($module=="link"){
			// Insert cms_menu_sub
			$sql="INSERT INTO `cms_menu_sub` (`id_sub` ,`id_top`,`id_type` ,`name` ,`url` ,`position` ,`status`) VALUES ('$datamaxid[0]', '$id_top', '$id_type','$namemenu', '$url', '$datamaxposition[0]', '1')";
			$result=query($sql);	
			// Insert_clms_news_page
			$sql="INSERT INTO `cms_link_group` (`id_group` ,`id_sub` ,`name_group` ,`status`) VALUES (NULL , '$datamaxid[0]', '$namemenu', '1')";
			$result=query($sql);	
			}
// Questions - Answers
		if($module=="faq"){
			// Insert cms_menu_sub
			$sql="INSERT INTO `cms_menu_sub` (`id_sub` ,`id_top`,`id_type` ,`name` ,`url` ,`position` ,`status`) VALUES ('$datamaxid[0]', '$id_top', '$id_type','$namemenu', '$url', '$datamaxposition[0]', '1')";
			$result=query($sql);	
			
			}
// Director chart
		if($module=="director_chart"){
			// Insert cms_menu_sub
		$sql="INSERT INTO `cms_menu_sub` (`id_sub` ,`id_top`,`id_type` ,`name` ,`url` ,`position` ,`status`) VALUES ('$datamaxid[0]', '$id_top', '$id_type','$namemenu', '$url', '$datamaxposition[0]', '1')";
			$result=query($sql);	
			
			}
} 


// ############################################# เมนูหลัก
// แก้ไขเมนูหลัก
if($id_top!="" and $check_up=='2'){
	$sql="UPDATE `cms_menu_top` SET  name='$name'  WHERE `id_top` ='$id_top'";
	$result=query($sql);
}


echo "<fieldset><legend>จัดการเมนู</legend>";
// ####################### แก้ไขชื่อเมนูหลัก #############################
echo "<br><table width='95%' border='0' align='center' cellpadding='1' cellspacing='1'>";
echo "<tr bgcolor='$datatm[color]'><td colspan='2' align=left><b>แก้ไขชื่อเมนูหลัก</b></td></tr>";
echo "<tr height=10><td colspan='2' align=center></td></tr>";
$sql="SELECT * FROM cms_menu_top WHERE id_top='$id_top'";
$result=mysql_query($sql);
$data=mysql_fetch_array($result);
echo"<FORM METHOD=POST ACTION='manage_header1.php?id_top=$id_top'>";
echo "    <tr>";
echo "     <td width='50%' align=center>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; &nbsp;<INPUT TYPE='text' NAME='name' value='$data[name]'></td> ";
echo "		<td width='20%'>";
echo"		<INPUT TYPE='submit' value='แก้ไขข้อมูล' onmouseover=this.style.cursor='hand'>";
echo	"	<INPUT TYPE='hidden' name='check_up' value='2'>";
echo"</td>";
echo "  </tr>";
echo "<tr height=10><td colspan='2' align=center></td></tr>";
echo"</FORM>";
echo "</table>";

if($id_top==0 or $id_top==4){
// ############################# แสดงเมนูย่อย #############################
echo "<table width='95%' border='0' align='center' cellpadding='1' cellspacing='1' bgcolor='eeeeee'>";
echo "<tr><td colspan='2' align=left><b>แสดงเมนูย่อย</b></td></tr>";
echo "    <tr>";
echo "     <td width='50%' align=center bgcolor='dddddd'><b>ชื่อเมนู</b></td> ";
echo "		<td width='25%' align=center bgcolor='dddddd'><b>จัดการ</b></td>";
echo "  </tr>";

$sql="SELECT * FROM `cms_menu_sub` WHERE id_top='$data[id_top]' order by position asc";
$result=mysql_query($sql);
$count_l=1;
while($data=mysql_fetch_array($result)){
echo"<FORM METHOD=POST ACTION='manage_header1.php?id_top=$id_top&id_subs=$data[id_sub]&id_top=$id_top'>";
echo "    <tr>";
// ประเภท
		$pieces = explode("?", $data[url]);
		$pieces = explode("&", $pieces[1]);
		$pieces = explode("=", $pieces[1]);
		
		//echo $module;
		$mod_name = select_query_data("name","cms_module","mod_id",$module);

// ชื่อ
		echo "     <td align=center>";
				echo "<INPUT TYPE='text' NAME='namemenu' value='$data[name]'>";
				echo"		<INPUT TYPE='submit' value='แก้ไขข้อมูล' onmouseover=this.style.cursor='hand'>";
				echo	"	<INPUT TYPE='hidden' name='check_up' value='1'>";
		echo"</td>";

// จัดการ
		echo "		<td align=center>";
		$sql_num="SELECT count(*) FROM `cms_menu_sub` WHERE id_top='$data[id_top]' order by id_sub asc";
		$re_num=mysql_query($sql_num);
		$data_num=mysql_fetch_array($re_num);

				// Up 
				if($count_l>1)	{
					echo "<a href='manage_header1.php?id_subs=$data[id_sub]&id_order=1&id_top=$id_top'><img src='../../images/up.gif' border='0' title='เลื่อนขึ้น'></a> "; 
					}else {
					echo "&nbsp;&nbsp; &nbsp;&nbsp;";					
					}
				// Down
					if($count_l<$data_num[0])	{ 
					echo "<a href='manage_header1.php?id_subs=$data[id_sub]&id_order=2&id_top=$id_top'><img src='../../images/down.gif' border='0' title='เลื่อนลง'></a> "; 
					}else {
					echo "&nbsp;&nbsp; &nbsp;&nbsp;";
					}

				// show -hide
					if($data[status]=="1")	
					echo "<a href='manage_header1.php?id_subs=$data[id_sub]&id_show=1&id_top=$id_top' title='ซ่อนข้อมูล'><img src='../../images/show.gif' border='0'></a> ";
					else													
					echo "<a href='manage_header1.php?id_subs=$data[id_sub]&id_show=2&id_top=$id_top' title='แสดงข้อมูล'><img src='../../images/hide.gif' border='0'></a> ";

				// Del
					if($id_top!="4" and $id_top!="0"){
					echo " <a href='manage_header1.php?id_del=$data[id_sub]&id_top=$id_top&module=$pieces[1]'><img src='../../images/del1.gif' border='0' title='ลบข้อมูล'  onclick='return goURLdel();'></a><br>";
					}
		echo"</td>";
echo "  </tr>";
$count_l++;
echo"</FORM>";
}

echo "</table>";

}

// ปิดหน้าต่าง
echo "<form  action='manage_header1.php?oncheck=1' method='post' >";
echo "<center><INPUT TYPE='submit' value='ปิดหน้านี้'  onmouseover=this.style.cursor='hand'></center>";
echo"</FORM>";


?>


<script language="javascript">
		function checkadd() {
		if(document.add.namemenu.value=="") {
		alert("กรุณากรอก ชื่อเมนูย่อย!") ;
		document.add.namemenu.focus() ;
		return false ;
		}
		else if(document.add.module.value=="0") {
		alert("กรุณาเลือกประเภทโมดูล!") ;
		document.add.module.focus() ;
		return false ;
		}
		else 
		return true ;
		}
</script>


<script language="JavaScript">
<!--
function goURLdel() {
var blnLink
blnLink = confirm("Click OK เพื่อยืนยันการลบข้อมูล?")
if (!blnLink) { return false; }
return true;
}
//-->	
</script>

Youez - 2016 - github.com/yon3zu
LinuXploit