01.
<html>
02.
<head>
03.
<meta http-equiv=Content-Type content=
"text/html; charset=utf-8"
>newsearch_show_new4_file</title>
04.
<link rel=
"stylesheet"
href=
"../css/style.css"
/>
05.
</head>
06.
07.
<body>
08.
<?php
09.
ini_set
(
'display_errors'
, 1);
10.
error_reporting
(~0);
11.
$serverName
=
"localhost"
;
12.
13.
$userName
=
"duangjai_root"
;
14.
15.
$userPassword
=
"jai"
;
16.
17.
$dbName
=
"duangjai_newversion_bible"
;
18.
19.
$objCon
=
new
mysqli(
$serverName
,
$userName
,
$userPassword
,
$dbName
);
20.
21.
mysqli_set_charset(
$objCon
,
"utf8"
);
22.
23.
echo
$_POST
[
"lmName1"
];
24.
$id
=
$_POST
[
"lmName1"
];
25.
26.
echo
"<hr>"
;
27.
$strSQL
=
"SELECT * FROM uploadfile WHERE id ="
;
28.
$stmt
=
$objCon
->prepare(
$strSQL
);
29.
$stmt
->bind_param(
's'
,
$id
);
30.
$stmt
->execute();
31.
32.
$result
=
$stmt
->get_result();
33.
$row
=
$result
->fetch_assoc();
34.
35.
$objQuery
= mysqli_query(
$objCon
,
$strSQL
);
36.
37.
38.
$pat_img
=
"^(image)"
;
39.
$pat_swf
=
"(flash)$"
;
40.
41.
42.
if
(!
eregi
(
$pat_img
,
$type
) && !
eregi
(
$pat_swf
,
$type
)) {
43.
44.
while
(
$result
= mysqli_fetch_array(
$objQuery
,MYSQLI_ASSOC))
45.
46.
{
47.
$name
= mysql_result(
$result
,0,
"file_name"
);
48.
$size
= mysql_result(
$result
,0,
"file_size"
);
49.
$type
= mysql_result(
$result
,0,
"file_type"
);
50.
$content
= mysql_result(
$result
,0,
"file_content"
);
51.
header(
"Content-Type: $type"
);
52.
header(
"Content-Length : $size"
);
53.
header(
"Content-Disposition : attachment; filename=$name"
);
54.
55.
echo
$content
;
56.
exit
();
57.
}
58.
}
59.
60.
61.
echo
"<html><body>"
;
62.
63.
if
(
eregi
(
$pat_img
,
$type
)) {
64.
echo
"<img src=\"read_image.php?id=$id\" />"
;
65.
}
66.
else
if
(
eregi
(
$pat_swf
,
$type
)) {
67.
echo
"<object width=468 height=60>
68.
<param name=movie value=\
"read_image.php?id=$id\"
/>
69.
<embed width=468 height=60 src=\
"read_image.php?id=$id\"
></embed>
70.
</object>";
71.
}
72.
73.
echo
"</body></html>"
;
74.
?>
75.
</body>
76.
</html>
77.
<?php
78.
79.
mysqli_close(
$objCon
);
80.
81.
?>