Файловый менеджер - Редактировать - /home/umudio/public_html/repo/editcontentpic.php.tar
Назад
home/umudio/public_html/OLD/editcontentpic.php 0000644 00000012205 14773626311 0015455 0 ustar 00 <?php if (!$_SESSION){ session_start(); } $acc=$_SESSION['acc']; $yto=$_SESSION['yto']; if(isset($acc) && ($acc=="administratoroftheUmuahiasiteDiocese2016Byto")){?> <?php include("Connecter/dataconn.php"); ?> <?php if (isset($_GET['deltab'])) { unset($temp); if(isset($_GET['deltab'])){ $_GET['deltab']=trim($_GET['deltab']); if(preg_match('/^[0-9]/u',$_GET['deltab'])){ settype($_GET['deltab'], 'int'); $temp=(int)$_GET['deltab']; } } if(!isset($temp)){echo "Sorry! Wrong Data!"; exit();} $deltab=$temp; $sql=sprintf("delete from contentphotos where sn = %s", mysql_real_escape_string($deltab)); $result=mysql_query($sql,$csn) or die(mysql_error()); } if (isset($_GET['tab'])) { unset($temp); $theValue = trim($_GET['tab']); if($theValue!=""){ if(preg_match('/^[0-9]/u',$theValue)){ settype($theValue, 'int'); $temp=(int)$theValue; } if(!isset($temp)){echo "Sorry! Wrong Data!"; exit();} } $oid=$temp; $query_dio=sprintf("select * from thecontent where sn = %s", mysql_real_escape_string($oid)); $dio = mysql_query($query_dio, $csn) or die(mysql_error()); $row_dio = mysql_fetch_assoc($dio); $totalRows_dio = mysql_num_rows($dio); ?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <?php include("head.php"); ?> </head> <body> <?php include("top.php"); ?> <?php include("titlebar.php"); ?> <?php include("mast.php"); ?> <?php include("navbar.php"); ?> <?php include("contenttop.php"); ?> <?php include("sidebar.php"); ?> <?php include("mainbartop.php"); ?> <!--Content Goes here--> <div class="headingbigger">Add/Remove Pictures from <?php echo ($row_dio['titler']); ?>…</div> <form id="form1" name="form1" method="post" action="dadmin.php" enctype="multipart/form-data"> <table width="100%" cellpadding="1" cellspacing="2"> <tr valign="top"> <td style="font-weight:bold; text-align:center" colspan="2"><br />EXISTING PHOTOS FOR THIS SECTION<br /> <?php $query_dio1 = "SELECT * FROM contentphotos where whose='" . $oid . "'"; $dio1 = mysql_query($query_dio1, $csn) or die(mysql_error()); $row_dio1 = mysql_fetch_assoc($dio1); $totalRows_dio1 = mysql_num_rows($dio1); ?> <?php if ($totalRows_dio1>0) { ?> <table width="90%"> <?php do { ?><tr valign="middle"> <td style="border-bottom:1px solid #333333;" align="right"><img src="<?php echo $row_dio1['photo']; ?>" width="75" /></td> <td style="border-bottom:1px solid #333333;" align="left"> <a href="editcontentpic.php?deltab=<?php echo $row_dio1['sn']; ?>&tab=<?php echo $oid; ?>">Delete</a> </td></tr> <?php } while ($row_dio1 = mysql_fetch_assoc($dio1)); ?> </table> <?php } else { echo ("None Found!"); } ?> </td> </tr> <tr valign="top"> <td style="font-weight:bold; text-align:center" colspan="2"><br />ADDITIONAL PHOTOS FOR THIS SECTION</td> </tr> <tr valign="top"> <td style="font-weight:bold; text-align:center">Photo 1:</td> <td align="left" ><input type="file" name="uploader1" size="65" /></td> </tr> <tr valign="top"> <td style="font-weight:bold; text-align:center">Photo 2:</td> <td align="left" ><input type="file" name="uploader2" size="65" /></td> </tr> <tr valign="top"> <td style="font-weight:bold; text-align:center">Photo 3:</td> <td align="left" ><input type="file" name="uploader3" size="65" /></td> </tr> <tr valign="top"> <td style="font-weight:bold; text-align:center">Photo 4:</td> <td align="left" ><input type="file" name="uploader4" size="65" /></td> </tr> <tr valign="top"> <td style="font-weight:bold; text-align:center">Photo 5:</td> <td align="left" ><input type="file" name="uploader5" size="65" /></td> </tr> <tr valign="top"> <td style="text-align:right; font-size:10px;" colspan="2"><a href="dadmin.php">Cancel</a> <input name="editcontentpic" type="submit" style="font-size:12px;" id="editcontentpic" value=" Add Pictures " /> <input name="sn" type="hidden" value="<?php echo ($oid); ?>" /> </td> </tr> </table> </form> <p> </p> <!--Content Ends here--> <?php include("mainbarbottom.php"); ?> <?php include("contentbottom.php"); ?> <?php include("footbar.php"); ?> <?php include("bottom.php"); ?> </body> </html> <?php } else { include("dadmin.php"); } ?> <?php } else { include("ddadmin.php"); }?>