$insert['ORDER_ID'] = "1"; $insert['IMG_NAME'] = "'MyApplication'"; $sql = "INSERT INTO trn_content_picture (" . implode(",", array_keys($insert)) . ") VALUES (" . implode(",", array_values($insert)) . ")"; mysql_query($sql, $conn) or die($sql); } } chmod($path1, 0755); chmod($path2, 0755); chmod($path3, 0755); header('Location: contact-eapp-register.php'); } if (isset($_GET['edit'])) { $update = ""; $update[] = "CAT_ID = '" . $eapp_sub_cat . "'"; $update[] = "LAT = '" . $_POST['jobname'] . "'"; $update[] = "CONTENT_DESC_LOC = '" . $_POST['name_th'] . "'"; $update[] = "CONTENT_DESC_ENG = '" . $_POST['name_eng'] . "'"; $update[] = "EVENT_START_DATE = '" . ConvertDateToDB($_POST['birthdate']) . "'"; $update[] = "PLACE_DESC_ENG ='" . $_POST['email'] . "'"; $update[] = "PLACE_DESC_LOC = '" . $_POST['address'] . "'"; $update[] = "BRIEF_LOC = '" . $_POST['telephone'] . "'"; $update[] = "BRIEF_ENG = '" . $_POST['mobile'] . "'"; $update[] = "CONTENT_DETAIL_LOC = '" . $_POST['sex'] . "'"; $update[] = "CONTENT_DETAIL_ENG = '" . $_POST['nationality'] . "'"; $update[] = "LON = '" . $_POST['salary'] . "'"; $update[] = "LAST_UPDATE_USER = '******'user_name'] . "'"; $update[] = "LAST_UPDATE_DATE = NOW()"; $sql = "UPDATE trn_content_detail SET " . implode(",", $update) . " WHERE CONTENT_ID = " . $conid; mysql_query($sql, $conn); header('Location: ' . $returnPage . ''); }
$insert['CONTENT_DESC_ENG'] = "'" . $_POST['txtDescEng'] . "'"; $insert['ORDER_DATA'] = "'" . $max . "'"; $insert['CONTENT_DETAIL_LOC'] = "'" . $_POST['txtDetailLoc'] . "'"; $insert['CONTENT_DETAIL_ENG'] = "'" . $_POST['txtDetailEng'] . "'"; $insert['CONTENT_STATUS_FLAG'] = "'0'"; $insert['CONTENT_VIEW_COUNT'] = "0"; $insert['BRIEF_LOC'] = "'" . $_POST['txtBriefDescLoc'] . "'"; $insert['BRIEF_ENG'] = "'" . $_POST['txtBriefDescEng'] . "'"; $insert['MUSUEM_ID'] = "'" . $_POST['museumID'] . "'"; $insert['APPROVE_FLAG'] = "'N'"; $insert['USER_CREATE'] = "'" . $_SESSION['user_name'] . "'"; $insert['CREATE_DATE'] = "NOW()"; $insert['LAST_UPDATE_USER'] = "******" . $_SESSION['user_name'] . "'"; $insert['LAST_UPDATE_DATE'] = "NOW()"; $insert['EVENT_START_DATE'] = "'" . ConvertDateToDB($_POST['txtStartDate']) . "'"; $insert['EVENT_END_DATE'] = "'" . ConvertDateToDB($_POST['txtEndDate']) . "'"; $insert['PLACE_DESC_LOC'] = "'" . nvl($_POST['txtPlaceLoc'], "") . "'"; $insert['PLACE_DESC_ENG'] = "'" . nvl($_POST['txtPlaceEng'], "") . "'"; $insert['LAT'] = "'" . nvl($_POST['txtLat'], "") . "'"; $insert['LON'] = "'" . nvl($_POST['txtLon'], "") . "'"; $insert['EVENT_START_TIME'] = "'" . $_POST['startdate'] . "'"; $insert['EVENT_END_TIME'] = "'" . $_POST['enddate'] . "'"; $insert['PRICE_RATE_LOC'] = "'" . $_POST['txtPriceLoc'] . "'"; $insert['PRICE_RATE_ENG'] = "'" . $_POST['txtPriceEng'] . "'"; $sql = "INSERT INTO trn_content_detail (" . implode(",", array_keys($insert)) . ") VALUES (" . implode(",", array_values($insert)) . ")"; mysql_query($sql, $conn) or die($sql . ' Err : ' . mysql_error()); $retrunID = mysql_insert_id(); if (count($_POST['EVENT_PIC_file']) > 0) { $sql_max = "SELECT MAX(ORDER_ID) AS MAX_ORDER FROM trn_content_picture WHERE CONTENT_ID = " . $retrunID . " AND IMG_TYPE = 1 "; //$_POST['cmbCategory']; $query_max = mysql_query($sql_max, $conn) or die($sql_max);
echo mysql_num_rows($query); } else { //insert unset($insert); $insert['USER_ID'] = "'" . $_POST['email'] . "'"; $insert['EMAIL'] = "'" . $_POST['email'] . "'"; $insert['NAME'] = "'" . $_POST['name'] . "'"; $insert['LAST_NAME'] = "'" . $_POST['surname'] . "'"; $insert['SEX'] = "'" . $_POST['sex'] . "'"; $insert['ADDRESS1'] = "'" . $_POST['address'] . "'"; $insert['CITIZEN_ID'] = "'" . $_POST['idcard'] . "'"; $insert['PROVINCE_ID'] = "'" . $_POST['province'] . "'"; $insert['DISTRICT_ID'] = "'" . $_POST['district'] . "'"; $insert['SUB_DISTRICT_ID'] = "'" . $_POST['sub_district'] . "'"; $insert['POST_CODE'] = "'" . $_POST['postcode'] . "'"; $insert['BIRTHDAY'] = "'" . ConvertDateToDB($_POST['birthday']) . "'"; $insert['PWD'] = "'" . createPasswordHash($_POST['password1']) . "'"; $insert['USER_CREATE'] = "'" . $_POST['email'] . "'"; $insert['CREATE_DATE'] = "NOW()"; $insert['ACTIVE_FLAG'] = "'0'"; $insert['TELEPHONE'] = "'" . $_POST['telephone'] . "'"; $insert['MOBILE_PHONE'] = "'" . $_POST['mobile'] . "'"; $insert['FAX'] = "'" . $_POST['fax'] . "'"; $sql = "INSERT INTO sys_app_user (" . implode(",", array_keys($insert)) . ") VALUES (" . implode(",", array_values($insert)) . ")"; mysql_query($sql, $conn) or die($sql); $retrunID = mysql_insert_id(); unset($insert); $insert['USER_ID'] = "'" . $_POST['email'] . "'"; $insert['USER_TYPE_ID'] = "'2'"; $sql = "INSERT INTO sys_mapping_user_type (" . implode(",", array_keys($insert)) . ") VALUES (" . implode(",", array_values($insert)) . ")"; mysql_query($sql, $conn) or die($sql);
//$_POST['cmbSubCategory']; } $update = ""; $update[] = "CONTENT_DESC_LOC = '" . $_POST['txtDescLoc'] . "'"; $update[] = "CONTENT_DESC_ENG = '" . $_POST['txtDescEng'] . "'"; $update[] = "CONTENT_DETAIL_LOC= '" . $_POST['txtDetailLoc'] . "'"; $update[] = "CONTENT_DETAIL_ENG= '" . $_POST['txtDetailEng'] . "'"; $update[] = "BRIEF_LOC= '" . $_POST['txtBriefDescLoc'] . "'"; $update[] = "BRIEF_ENG= '" . $_POST['txtBriefDescEng'] . "'"; $update[] = "LAST_UPDATE_USER = '******'user_name'] . "'"; $update[] = "LAST_UPDATE_DATE = NOW()"; $update[] = "CAT_ID = '" . $CID . "'"; ///$_POST['cmbCategory'] . "'"; $update[] = "SUB_CAT_ID = '" . $subCatID . "'"; $update[] = "EVENT_START_DATE = '" . ConvertDateToDB($_POST['txtStartDate']) . "'"; $update[] = "EVENT_END_DATE = '" . ConvertDateToDB($_POST['txtEndDate']) . "'"; $update[] = "PLACE_DESC_LOC = '" . nvl($_POST['txtPlaceLoc'], "") . "'"; $update[] = "PLACE_DESC_ENG = '" . nvl($_POST['txtPlaceEng'], "") . "'"; $update[] = "LAT = '" . nvl($_POST['txtLat'], "") . "'"; $update[] = "LON = '" . nvl($_POST['txtLon'], "") . "'"; $update[] = "EVENT_START_TIME = '" . nvl($_POST['cmbHourStart'], '') . ':' . nvl($_POST['cmbMinuteStart'], '') . "'"; $update[] = "EVENT_END_TIME = '" . nvl($_POST['cmbHourEnd'], '') . ':' . nvl($_POST['cmbMinuteEnd'], '') . "'"; $update[] = "PRICE_RATE_LOC = '" . $_POST['txtPriceLoc'] . "'"; $update[] = "PRICE_RATE_ENG = '" . $_POST['txtPriceEng'] . "'"; $sql = "UPDATE trn_content_detail SET " . implode(",", $update) . " WHERE CONTENT_ID = " . $conid; mysql_query($sql, $conn); if (count($_POST['photo_file']) > 0) { $sql_max = "SELECT MAX(ORDER_ID) AS MAX_ORDER FROM trn_content_picture WHERE CONTENT_ID = " . $conid . " AND CAT_ID = " . $CID; //$_POST['cmbCategory']; $query_max = mysql_query($sql_max, $conn) or die($sql_max); $row_max = mysql_fetch_array($query_max);
if (isset($_GET['add'])) { $sql_max = "SELECT MAX( ORDER_DATA ) AS MAX_ORDER FROM trn_product WHERE FLAG <> 2 AND CAT_ID =" . $_GET['cid']; $query_max = mysql_query($sql_max, $conn); $row_max = mysql_fetch_array($query_max); $max = $row_max['MAX_ORDER']; $max++; unset($insert); $insert['CAT_ID'] = "'" . $_GET['cid'] . "'"; $insert['PRODUCT_DESC_LOC'] = "'" . $_POST['product_name_th'] . "'"; $insert['PRODUCT_DESC_ENG'] = "'" . $_POST['product_name_en'] . "'"; $insert['PRICE'] = "'" . $_POST['price'] . "'"; $insert['SALE'] = "'" . $_POST['sale'] . "'"; $insert['DETAIL'] = "'" . $_POST['detail'] . "'"; $insert['DETAIL_ENG'] = "'" . $_POST['detailEn'] . "'"; $insert['EVENT_START_DATE'] = "'" . ConvertDateToDB($_POST['start']) . "'"; $insert['EVENT_END_DATE'] = "'" . ConvertDateToDB($_POST['end']) . "'"; $insert['BRIEF_LOC'] = "'" . $_POST['brief_name_th'] . "'"; $insert['BRIEF_ENG'] = "'" . $_POST['brief_name_en'] . "'"; $insert['ORDER_DATA'] = $max; $insert['USER_CREATE'] = "'" . $_SESSION['user_name'] . "'"; $insert['CREATE_DATE'] = "NOW()"; $sql = "INSERT INTO trn_product (" . implode(",", array_keys($insert)) . ") VALUES (" . implode(",", array_values($insert)) . ")"; mysql_query($sql, $conn) or die($sql); $retrunID = mysql_insert_id(); if (count($_POST['photo_file']) > 0) { $index = 1; foreach ($_POST['photo_file'] as $k => $file) { $filename = admin_move_image_upload_dir('virsual', end(explode('/', $file)), 1000, '', false, 150, 150); unset($insert); $insert['CONTENT_ID'] = $retrunID; $insert['IMG_TYPE'] = 1;
header('Content-type: text/html; charset=utf-8'); if (isset($_GET['edit'])) { $update = ""; $update[] = "NAME = '" . $_POST['name'] . "'"; $update[] = "LAST_NAME = '" . $_POST['surname'] . "'"; $update[] = "ADDRESS1 = '" . $_POST['address'] . "'"; $update[] = "DISTRICT_ID = '" . $_POST['cmbDistrict'] . "'"; $update[] = "SUB_DISTRICT_ID = '" . $_POST['cmbSubDistrict'] . "'"; $update[] = "PROVINCE_ID = '" . $_POST['cmbProvince'] . "'"; $update[] = "POST_CODE = '" . $_POST['postcode'] . "'"; $update[] = "TELEPHONE = '" . $_POST['tel'] . "'"; $update[] = "CITIZEN_ID = '" . $_POST['citizen'] . "'"; $update[] = "MOBILE_PHONE = '" . $_POST['mobile'] . "'"; $update[] = "FAX = '" . $_POST['fax'] . "'"; $update[] = "SEX = '" . $_POST['sex'] . "'"; $update[] = "BIRTHDAY = '" . ConvertDateToDB($_POST['birthday']) . "'"; $update[] = "TITLE = '" . $_POST['title-name'] . "'"; $update[] = "LAST_UPDATE_DATE = NOW()"; $update[] = "LAST_UPDATE_USER = '******'user_name'] . "'"; // echo $_POST['browseAvarta']; // var_dump($_POST['browseAvarta']); //echo $_FILES["browseAvarta"]["tmp_name"] ; if (isset($_FILES['browseAvarta'])) { $target_dir = "upload/USER_IMG/"; $target_dir_museum = $target_dir . 'USER_ID_' . $_SESSION['UID'] . '/'; $target_file = $target_dir_museum . basename($_FILES["browseAvarta"]["name"]); // echo $target_save_file ; $uploadOk = 1; $imageFileType = pathinfo($target_file, PATHINFO_EXTENSION); $target_save_file = $target_dir_museum . date("YmdGis") . '.' . $imageFileType; if (!is_dir($target_dir)) {
$sql = "INSERT INTO trn_content_picture (" . implode(",", array_keys($insert)) . ") VALUES (" . implode(",", array_values($insert)) . ")"; mysql_query($sql, $conn) or die($sql); } } header('Location: viewVirsualExhib.php?p=' . $_GET['p'] . ''); } if (isset($_GET['edit'])) { $id = $_GET['p']; $update = ""; $update[] = "CONTENT_DESC_LOC = '" . $_POST['name_th'] . "'"; $update[] = "CONTENT_DESC_ENG = '" . $_POST['name_en'] . "'"; $update[] = "BRIEF_LOC = '" . $_POST['brief_name_th'] . "'"; $update[] = "BRIEF_ENG = '" . $_POST['brief_name_en'] . "'"; $update[] = "DETAIL = '" . $_POST['detail'] . "'"; $update[] = "EVENT_START_DATE ='" . ConvertDateToDB($_POST['start']) . "'"; $update[] = "EVENT_END_DATE ='" . ConvertDateToDB($_POST['end']) . "'"; $update[] = "USER_CREATE = 'admin'"; $update[] = "CREATE_DATE= NOW()"; $update[] = "LAST_UPDATE_USER = '******'"; $update[] = "LAST_UPDATE_DATE = NOW()"; $sql = "UPDATE trn_content_detail SET " . implode(",", $update) . " WHERE CONTENT_ID =" . $id; mysql_query($sql, $conn); if (count($_POST['photo_file']) > 0) { $sql_max = "SELECT MAX(ORDER_ID) AS MAX_ORDER FROM trn_content_picture WHERE CONTENT_ID = " . $id . " AND CAT_ID = " . $_POST['cat_id']; $query_max = mysql_query($sql_max, $conn); $row_max = mysql_fetch_array($query_max); $max = $row_max['MAX_ORDER']; $max++; foreach ($_POST['photo_file'] as $k => $file) { $filename = admin_move_image_upload_dir('virsual', end(explode('/', $file)), 1000, '', false, 150, 150); unset($insert);