01.
<?
02.
@session_start();
03.
ob_start();
04.
$useradmin
=
$_SESSION
[
"useradmin"
];
05.
if
(
empty
(
$useradmin
))
06.
{
07.
echo
"<script>alert('Admin access only');history.back();</script>"
;
08.
exit
();
09.
}
10.
require_once
"connectdb.php"
;
11.
require_once
"tdate.php"
;
12.
13.
$sql
=
"select * from adminlogin where useradmin='$useradmin'"
;
14.
$db_query
=mysql_db_query(
$db
,
$sql
);
15.
$result
=mysql_fetch_array(
$db_query
);
16.
$adminname
=
$result
[adminname];
17.
18.
$page
=
$_GET
[
'action'
];
19.
20.
if
(
$_FILES
[
"addsave"
][
"member_photo"
] !=
""
)
21.
{
22.
$name
=
$_FILES
[
'addsave'
][
'member_photo'
];
23.
$tmp
=
$_FILES
[
'member_photo'
][
"tmp_name"
];
24.
$date_time
=
date
(
"Y-m-d H:i:s"
);
25.
$oldname
=
explode
(
"."
,
$name
);
26.
$ext
=
""
;
27.
$ext
=
"."
.
$oldname
[
count
(
$oldname
)-1];
28.
$photo_1
=
date
(
'YmdHis'
).
$ext
;
29.
copy
(
$tmp
,
"IMG/"
.
$photo_1
);
30.
}
else
{
31.
$photo_1
=
""
;
32.
}
33.
mysql_query("INSERT INTO member (id,status_name, name_th, n_name_th, last_name_th, address, province, phone, member_photo, note_status_check)
34.
values(
''
,
'$_POST[status_name]'
,
35.
'$_POST[name_th]'
,
36.
'$_POST[n_name_th]'
,
37.
'$_POST[last_name_th]'
,
38.
'$_POST[address]'
,
39.
'$_POST[province]'
,
40.
'$photo_1'
,
41.
'$_POST[note_status_check]'
)
") or die ("
Cannot Add Database");
42.
43.
echo
"<script>alert('เพิ่มผู้ใช้ชื่อ $_POST[name] เรียบร้อยแล้วครับ');location='home.php';</script>"
;
44.
45.
?>