MINI MINI MANI MO

Path : /home/phaetpan/domains/phaetpanya.com/public_html/vibharamadmin/
File Upload :
Current File : /home/phaetpan/domains/phaetpanya.com/public_html/vibharamadmin/saveadd_list.php

<html>
<body>
<?php
	include("connect.php");
	
	date_default_timezone_set('Asia/Bangkok');
	$time = date("His");
	$date = date("Ymd");
	$type = substr($_FILES['filUpload']['name'],-4);

	$name = $date.$time.$type;   
	if(move_uploaded_file($_FILES["filUpload"]["tmp_name"],"../upload_file/$name"))
	{
		$departid = $_POST['depart'];

		$sqldepart = " SELECT * FROM department WHERE depart_id = '".$departid."' ";
		$Querydepart = mysqli_query($objCon,$sqldepart);
		$rsDepart = mysqli_fetch_array($Querydepart,MYSQLI_ASSOC);

		$depart1 = $rsDepart['depart1'];
		$depart2 = $rsDepart['depart2'];
		$depart3 = $rsDepart['depart3'];
		$depart4 = $rsDepart['depart4'];
		$depart5 = $rsDepart['depart5'];
		$depart6 = $rsDepart['depart6'];

		$strSQL = "INSERT INTO doctor_list";
		$strSQL .="(admin_id,depart_id,img,name1,name2,name3,name4,name5,name6,branch1,branch2,branch3,branch4,branch5,branch6,blog1,blog2,blog3,blog4,blog5,blog6) 
		VALUES ('".$_POST["admin"]."','".$_POST["depart"]."','".$name."',
		'".$_POST["name1"]."','".$_POST["name2"]."','".$_POST["name3"]."','".$_POST["name4"]."','".$_POST["name5"]."','".$_POST["name6"]."',
		'".$depart1."','".$depart1."','".$depart1."','".$depart1."','".$depart1."','".$depart1."',
		'".$_POST["blog1"]."','".$_POST["blog2"]."','".$_POST["blog3"]."','".$_POST["blog4"]."','".$_POST["blog5"]."','".$_POST["blog6"]."')";      
		$objQuery = mysqli_query($objCon,$strSQL);	
		
		if ($objQuery){
		  echo "<script>alert('Success')</script>";
		  echo '<script> window.location="doctor2.php"</script> ';
		  exit();                        
		}
	}
?>
</body>
	<!-- <script type='text/javascript'>
		window.location.href = "doctor2.php"     
	</script> -->
</html>

OHA YOOOO