01.
<?php
02.
$serverName
=
"localhost"
;
03.
04.
$userName
=
"duangjai_root"
;
05.
06.
$userPassword
=
"jai"
;
07.
08.
$dbName
=
"duangjai_newversion_bible"
;
09.
10.
$objCon
= mysqli_connect(
$serverName
,
$userName
,
$userPassword
,
$dbName
);
11.
12.
mysqli_set_charset(
$objCon
,
"utf8"
);
13.
14.
echo
$_POST
[
"lmName1"
];
15.
16.
echo
"<hr>"
;
17.
18.
$id
=
$_GET
[
'id'
];
19.
$strSQL
=
"SELECT * FROM uploadfile WHERE id = '"
.
$_GET
['id
']."'
";
20.
$objQuery
= mysqli_query(
$objCon
,
$strSQL
);
21.
22.
23.
$pat_img
=
"^(image)"
;
24.
$pat_swf
=
"(flash)$"
;
25.
26.
27.
if
(!
eregi
(
$pat_img
,
$type
) && !
eregi
(
$pat_swf
,
$type
)) {
28.
29.
while
(
$result
= mysqli_fetch_array(
$objQuery
,MYSQLI_ASSOC))
30.
31.
{
32.
$name
= mysql_result(
$result
,0,
"file_name"
);
33.
$size
= mysql_result(
$result
,0,
"file_size"
);
34.
$type
= mysql_result(
$result
,0,
"file_type"
);
35.
$content
= mysql_result(
$result
,0,
"file_content"
);
36.
header(
"Content-Type: $type"
);
37.
header(
"Content-Length : $size"
);
38.
header(
"Content-Disposition : attachment; filename=$name"
);
39.
40.
echo
$content
;
41.
exit
();
42.
}
43.
}
44.
45.
46.
echo
"<html><body>"
;
47.
48.
if
(
eregi
(
$pat_img
,
$type
)) {
49.
echo
"<img src=\"read_image.php?id=$id\" />"
;
50.
}
51.
else
if
(
eregi
(
$pat_swf
,
$type
)) {
52.
echo
"<object width=468 height=60>
53.
<param name=movie value=\
"read_image.php?id=$id\"
/>
54.
<embed width=468 height=60 src=\
"read_image.php?id=$id\"
></embed>
55.
</object>";
56.
}
57.
58.
echo
"</body></html>"
;
59.
?>
60.
</body>
61.
</html>
62.
<?php
63.
64.
mysqli_close(
$objCon
);
65.
66.
?>