MINI MINI MANI MO

Path : /home/phaetpan/domains/phaetpanya.com/public_html/vibharamadmin/
File Upload :
Current File : /home/phaetpan/domains/phaetpanya.com/public_html/vibharamadmin/saveedit_list.php

<html>
<body>
<?php

	include("connect.php");
	
	$img = $_POST["img"];
	
	date_default_timezone_set('Asia/Bangkok');
	$time = date("His");
	$date = date("Ymd");
	$type = substr($_FILES['filUpload']['name'],-4);
	$name = $date.$time.$type;        
		if(move_uploaded_file($_FILES["filUpload"]["tmp_name"],"../upload_file/$name"))    
			{
				$picDelete = unlink("../upload_file/$img");
				$strSQL = "UPDATE doctor_list SET 
				img = '".$name."' ,admin_id = '".$_POST["admin"]."'    
				WHERE list_id = '".$_POST["list_id"]."'";
				$objQuery = mysqli_query($objCon,$strSQL);
			}

	$strSQL = "UPDATE doctor_list SET 
	name1 = '".$_POST["name1"]."',name2 = '".$_POST["name2"]."',name3 = '".isset($_POST["name3"])."',name4 = '".isset($_POST["name4"])."',name5 = '".isset($_POST["name5"])."',name6 = '".isset($_POST["name6"])."',
	blog1 = '".$_POST["blog1"]."',blog2 = '".$_POST["blog2"]."',blog3 = '".isset($_POST["blog3"])."',blog4 = '".isset($_POST["blog4"])."',blog5 = '".isset($_POST["blog5"])."',blog6 = '".isset($_POST["blog6"])."',admin_id = '".$_POST["admin"]."',depart_id = '".$_POST["department"]."'
	WHERE list_id = '".$_POST["list_id"]."'";
	$objQuery = mysqli_query($objCon,$strSQL);

?>
</body>
	<script type='text/javascript'>
		window.location.href = "doctor2.php"
	</script>
</html>

OHA YOOOO