MINI MINI MANI MO

Path : /home/phaetpan/domains/phaetpanya.com/public_html/vibharamadmin/
File Upload :
Current File : /home/phaetpan/domains/phaetpanya.com/public_html/vibharamadmin/saveedit_banner6.php

<html>
<body>
<?php
	include("connect.php");
	
	$img6 = $_POST["img6"];
	if($img6 != "") 
	{
		if($_FILES["filUpload"]["name"] != "") 
		{
			date_default_timezone_set('Asia/Bangkok');
			$time = date("His");
			$date = date("Ymd");
			$type = substr($_FILES['filUpload']['name'],-4);
			$name = $date.$time.$type;         
			if(move_uploaded_file($_FILES["filUpload"]["tmp_name"],"../upload_file/$name"))
			{
				$picDelete = unlink("../upload_file/$img6");
				$strSQL = "UPDATE home_banner SET 
				img6 = '".$name."',admin_id = '".$_POST["admin"]."' 
				WHERE banner_id = '".$_POST["banner_id"]."'";
				$objQuery = mysqli_query($objCon,$strSQL);
			}
		}
	}else{
		if($_FILES["filUpload"]["name"] != "") 
		{
			date_default_timezone_set('Asia/Bangkok');
			$time = date("His");
			$date = date("Ymd");
			$type = substr($_FILES['filUpload']['name'],-4);
			$name = $date.$time.$type;         
			if(move_uploaded_file($_FILES["filUpload"]["tmp_name"],"../upload_file/$name"))
			{
				$strSQL = "UPDATE home_banner SET 
				img6 = '".$name."',admin_id = '".$_POST["admin"]."' 
				WHERE banner_id = '".$_POST["banner_id"]."'";
				$objQuery = mysqli_query($objCon,$strSQL);
			}
		}
	}
	$strSQL = "UPDATE home_banner SET 
			title6 = '".$_POST["title6"]."',sub6 = '".$_POST["sub6"]."',admin_id = '".$_POST["admin"]."'
			WHERE banner_id = '".$_POST["banner_id"]."' ";
			$objQuery = mysqli_query($objCon,$strSQL);

?>
</body>
	<script type='text/javascript'>
		window.location.href = "edit_banner.php?banner_id=<?php echo $_POST["banner_id"];?>"
	</script>
</html>

OHA YOOOO