File Manager V1.5

[SYSTEM@ROOT]: /home/ketechno/public_html/QuickCheck/
INJECT_FILE:
NEW_ENTRY:

FILE_CONTENT: upload.php

<?php
session_start();
require_once('db_conn.php');
ini_set('upload_max_filesize', '10000M');
ini_set('post_max_size', '10000M');
ini_set('max_input_time', 300);
ini_set('max_execution_time', 300);

 $description	= ( isset( $_REQUEST['description'] ) )? 		$_REQUEST['description']: null;
$projectname	= ( isset( $_REQUEST['projectname'] ) )? 		$_REQUEST['projectname']: null;
 $location	= ( isset( $_REQUEST['location'] ) )? 		$_REQUEST['location']: null;
 $user_id	= ( isset( $_REQUEST['id'] ) )? 		$_REQUEST['id']: null;
	
	$firstname = $_SESSION['firstname'];
	$surname = $_SESSION['surname'];
   //$user_id = $_SESSION['id'];	
   // $user_id = $_SESSION['id2'];	
	
	$sql2 = "SELECT * FROM projects where projectname ='".$projectname."' and user_id ='".$user_id."' ";
        $result = $conn->query($sql2);

        if ($result->num_rows > 0) {
        while($row = $result->fetch_assoc()) {
	
	 $location = $row['location'];
	}
}  

	 if(isset($_FILES['uploads'])){
      $countfiles = count($_FILES['uploads']['name']);
 // Looping all files
 for($i=0;$i<$countfiles;$i++){
  $filename = $_FILES['uploads']['name'][$i];
  // Upload file
   move_uploaded_file($_FILES['uploads']['tmp_name'][$i],'uploads/'.$filename);


  $sql = "INSERT INTO projects (user_id, description, projectname, uploads, location, user)
 VALUES ('$user_id','$description','$projectname','$filename','$location','$firstname $surname')";	
  
 
if ($conn->multi_query($sql) == TRUE) {
	
	echo ("<SCRIPT LANGUAGE='JavaScript'>
    window.alert(' Your Uploads Submitted Successfully  ')
    window.location.href='home.php';
    </SCRIPT>");
	   
}
 

	 }
	 }
 
 	 
	     
else {
  
	echo ("<SCRIPT LANGUAGE='JavaScript'>
    window.alert('Error Your project was not Submitted  try again')
    window.location.href='home.php';
    </SCRIPT>");

}
	
$conn->close();
?> 
[ KEMBALI ]