$portfoliodir = "../portfolios/banners/"; if (!is_readable($portfoliodir) || !is_writable($portfoliodir) || !is_executable($portfoliodir)) { // $error = 1; $message .= " * Please request admin to change the permission of 'portfolios/banners' folder in the root to 777 <br>"; } if ($_FILES['txtBannerImage']['name'][0] != "") { if (!isValidWebImageType($bannerfiletype, $bannerfilename, $bannertempname)) { $message .= " * Invalid Image !! Upload an image (jpg/gif/png)" . "<br>"; } else { $imagewidth_height_type_array = explode(":", ImageTypeBanner($_FILES['txtBannerImage']['tmp_name'])); $imagetype = $imagewidth_height_type_array[0]; $assignedname = "banner" . time() . "." . $imagetype; if (move_uploaded_file($_FILES['txtBannerImage']['tmp_name'], "../portfolios/banners/" . $assignedname)) { chmod("../portfolios/banners/" . $assignedname, 0777); $banner_size = split(',', $banner_image_size); generateThumbNail("../portfolios/banners/" . $assignedname, "../portfolios/banners/" . $assignedname, $banner_size[0], $banner_size[1]); $insert_banner = "INSERT INTO " . $tableprefix . "seller_banner\n (vBannerName, nSellerId)\n\t\t\t\t\t\t\t\t\t VALUES('" . mysql_real_escape_string($assignedname) . "','" . mysql_real_escape_string($artistid) . "')"; mysql_query($insert_banner) or die(mysql_error()); header('Location:sellerbanners.php?artistid=' . $artistid . '&msg=Banner Added Successfully !!'); } } } else { $message .= " * Please select an image (jpg/gif/png)" . "<br>"; } } $sql = "SELECT CONCAT(a.first_name,' ' , a.last_name)as sellerName FROM " . $tableprefix . "artists a WHERE a.artist_id = '" . addslashes($artistid) . "' "; $res = mysql_query($sql); if (mysql_num_rows($res) > 0) { $row = mysql_fetch_array($res); $sellerName = $row["sellerName"]; }
//if($_POST[$bulk_image_buffer]) $assignedname = "affiliate_" . time() . $i . str_replace(' ', '', $_FILES[$product_image]['name']); if (move_uploaded_file($_FILES[$product_image]['tmp_name'], "../banners/" . $assignedname)) { chmod("../banners/" . $assignedname, 0777); //$banner_size = split(',',$banner_image_size); /*$update_product_images = "UPDATE ".$tableprefix."product_view_images SET vimage_name = ".GetSQLValueString($assignedname,"text")." WHERE nimage_productid = ".$_GET['edit_id'];*/ $update_product_images = "UPDATE " . $tableprefix . "affiliate_banner\n\t\t\t\t\t\t\t \t \t\t\t\t\t\t SET vaff_banner_name = " . GetSQLValueString($assignedname, "text") . " WHERE vaff_banner_name = " . GetSQLValueString($_POST[$bulk_image_buffer], "text"); mysql_query($update_product_images) or die(mysql_error()); //$image_flag = 1; if ($_POST[$bulk_image_buffer] != '') { $buffer_image = $_POST[$bulk_image_buffer]; unlink('../banners/' . $buffer_image); } generateThumbNail("../banners/" . $assignedname, "../banners/" . $assignedname, 174, 54); } } } } } if ($image_flag == 0) { $message = "Details Updated Successfully !!"; } } ?> <script> function checkAddBannerForm() {
if (isset($_POST['add'])) { /*check whether banner with the same name exists in the database*/ $bannerfiletype = $_FILES['txtBannerImage']['type']; $bannerfilename = $_FILES['txtBannerImage']['name']; $bannertempname = $_FILES['txtBannerImage']['tmp_name']; if ($_FILES['txtBannerImage']['name'][0] != "") { if (!isValidWebImageType($bannerfiletype, $bannerfilename, $bannertempname)) { $message .= " * Invalid Image !! Upload an image (jpg/gif/png)" . "<br>"; } else { $imagewidth_height_type_array = explode(":", ImageTypeBanner($_FILES['txtBannerImage']['tmp_name'])); $imagetype = $imagewidth_height_type_array[0]; $assignedname = "banner" . time() . "." . $imagetype; if (move_uploaded_file($_FILES['txtBannerImage']['tmp_name'], "../homepagebanners/" . $assignedname)) { chmod("../homepagebanners/{$assignedname}", 0777); $banner_size = split(',', $banner_image_size); generateThumbNail("../homepagebanners/" . $assignedname, "../homepagebanners/" . $assignedname, $banner_size[0], $banner_size[1]); $insert_banner = "INSERT INTO " . $tableprefix . "homepagebanners(image)\n\t\t\t\t\t\t\t\t\t VALUES('" . $assignedname . "')"; mysql_query($insert_banner) or die(mysql_error()); header('Location:homepagebanners.php?msg=Banner Added Successfully !!'); } } } else { $message .= " * Please select an image (jpg/gif/png)" . "<br>"; } } ?> <body topmargin="0"> <script> function checkAddBannerForm() {
if ($_FILES['userfile']['tmp_name'][0] != "") { chmod("../products/{$final_image_small}", 0777); generateThumbNail("../products/" . $final_image_small, "../products/" . $final_image_small, 120, 150); } } if ($picbigname != "") { //checking extension and replace $replaceArray = array('jpg', 'jpeg', 'gif'); $findArray = array('JPG', 'JPEG', 'GIF'); @(list($piName, $ext) = @split("[.]", $final_image_big)); $final_image_big = $piName . '.' . str_replace($findArray, $replaceArray, $ext); //checking extension and replace move_uploaded_file($_FILES['userfile']['tmp_name'][1], "../products/" . $final_image_big); if ($_FILES['userfile']['tmp_name'][1] != "") { chmod("../products/{$final_image_big}", 0777); generateThumbNail("../products/" . $final_image_big, "../products/" . $final_image_big, 400, 400); } } $sql = "UPDATE " . $tableprefix . "products SET\n\t\t\tproduct_name = '" . addslashes($txtProductName) . "',\n\t\t\tproduct_code = '" . addslashes($txtProductCode) . "',\n\t\t\tproduct_description = '" . addslashes($txtDescription) . "',\n\t\t\tproduct_price = '" . addslashes($txtPrice) . "',\n\t\t\tproduct_category = '" . addslashes($ddlCategory) . "',"; if ($picsmallname != "") { $sql .= "product_image_small = '" . addslashes($final_image_small) . "',"; } if ($picbigname != "") { $sql .= "product_image_big = '" . addslashes($final_image_big) . "',"; } if ($txtlength != 0) { $sql .= "product_length = '" . addslashes($txtlength) . "',"; } if ($txtwidth != 0) { $sql .= "product_width = '" . addslashes($txtwidth) . "',"; }
$bannerfilename = $_FILES['txtBannerImage']['name']; $bannertempname = $_FILES['txtBannerImage']['tmp_name']; $update_banner = "UPDATE " . $tableprefix . "banners\n\t\t\t\t\t\t SET vbanner_name = " . GetSQLValueString($_POST['txtBannerName'], "text") . ",\n\t\t\t\t\t\t vbanner_locurl = " . GetSQLValueString(str_replace('http://', '', $_POST['txtBannerLocation']), "text"); $message = "Banner Details Updated Successfully !!"; if ($_FILES['txtBannerImage']['name'][0] != "") { if (!isValidWebImageType($bannerfiletype, $bannerfilename, $bannertempname)) { $message = " * Invalid Image !! Upload an image (jpg/gif/png)" . "<br>"; $invalid_image_flag = 1; } else { $imagewidth_height_type_array = explode(":", ImageTypeBanner($_FILES['txtBannerImage']['tmp_name'])); $imagetype = $imagewidth_height_type_array[0]; $assignedname = "banner" . time() . "." . $imagetype; if (move_uploaded_file($_FILES['txtBannerImage']['tmp_name'], "../banners/" . $assignedname)) { chmod("../banners/{$assignedname}", 0777); $banner_size = split(',', $banner_image_size); $file_status = generateThumbNail("../banners/" . $assignedname, "../banners/" . $assignedname, $banner_size[0], $banner_size[1]); if ($file_status == 1) { unlink('../banners/' . $assignedname); $assignedname = "file_uplod_error.JPG"; } $update_banner .= ",vbanner_image = '" . $assignedname . "'"; if ($_POST['image_buffer'] != '') { $buffer_image = $_POST['image_buffer']; unlink('../banners/' . $buffer_image); } } } } $update_banner .= " WHERE nbanner_id = " . $_GET['edit_id']; mysql_query($update_banner) or die(mysql_error()); if ($invalid_image_flag == 0) {