session_start();
$be_var = $_POST;foreach ( $be_var as $key => $value ) {$$key=$value;}
$be_var = $_GET;foreach ( $be_var as $key => $value ) {$$key=$value;}
$loaitru = array("<", "?", ">", "'", '"');
$t1 = str_replace($loaitru, "", $t1);
$t2 = str_replace($loaitru, "", $t2);
$t3 = str_replace($loaitru, "", $t3);
$t4 = str_replace($loaitru, "", $t4);
$t5 = str_replace($loaitru, "", $t5);
$t6 = str_replace($loaitru, "", $t6);
$t7 = str_replace($loaitru, "", $t7);
$act = substr(str_replace($loaitru, "", $act),0,10);
$captcha= substr(str_replace($loaitru, "", $captcha),0,4);
//$_SESSION["permissedit"]="";
include("dbconnect.php");
if ($x=='dangnhap'){
$use_ = substr(str_replace($loaitru, "", $use_),0,20);
$pass_ = substr(str_replace($loaitru, "", $pass_),0,20);
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='A10' and text4='$use_'");
if ($row=mysql_fetch_array($result)){
if ($pass_==$row["text5"]){$_SESSION["department"]=$row["link_"];$_SESSION["fullname"]=$row["text3"];}}
}
if ($x=='logout'){$_SESSION["department"]="";$_SESSION["fullname"]="";}
$dep=$_SESSION["department"];
if (($dep!='') and ($z=='addlylich')){
$link__=$dep;
$link2__="00001";
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='B01' and link_='$link__' order by link2_ DESC");
if ($row=mysql_fetch_array($result)){$link2__=substr("00000".($row["link2_"]*1+1),-5);}
$order__=$link2__*1;
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,order_,text2,text3) values ('B01','$link__','$link2__','$order__','$hodem','$ten')";
mysql_query($query) or die (mysql_error());
}
if (($dep!='') and ($z=='editlylich')){
if ($_FILES['hinhanh']['name']<>""){
$my=date("Y").date("m").date("d").date("H").date("i").date("s");
$target_pic = "../../subpdu/lylichkhoahoc/pictures/" .$my. basename( $_FILES['hinhanh']['name']);
$k=move_uploaded_file($_FILES['hinhanh']['tmp_name'], $target_pic);
}
$b01_6=trim($b01_2)." ".trim($b01_3);
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='B01' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
if ($target_pic==""){mysql_query("UPDATE nss_aa_lylichkhoahoc SET text2='$b01_2',text3='$b01_3',text4='$b01_4',text5='$b01_5',text6='$b01_6' where type_='B01' and link_='$link_' and link2_='$link2_'");}
else{mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$target_pic',text2='$b01_2',text3='$b01_3',text4='$b01_4',text5='$b01_5',text6='$b01_6' where type_='B01' and link_='$link_' and link2_='$link2_'");}
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text2,text3,text4,text5,text6) values ('B01','$link_','$link2_','$b01_2','$b01_3','$b01_4','$b01_5','$b01_6')";
mysql_query($query) or die (mysql_error());
}
for ($bb=2;$bb<5;$bb++){
//$kq1="";$kq2="";$kq3="";$kq4="";$kq5="";
$b2=substr("00".$bb,-2);$b3="B".$b2;$b4="b".$b2;
$coco=0;
for ($t=1;$t<8;$t++){
$b5=$b4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$b5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$b3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$b3."' and link_='$link_' and link2_='$link2_'");
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$b3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
//------------------------------
if ($phan=="1"){
for ($bb=5;$bb<12;$bb++){
//$kq1="";$kq2="";$kq3="";$kq4="";$kq5="";
$b2=substr("00".$bb,-2);$b3="B".$b2;$b4="b".$b2;
$coco=0;
for ($t=1;$t<8;$t++){
$b5=$b4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$b5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$b3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$b3."' and link_='$link_' and link2_='$link2_'");
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$b3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
}
//------------------------------
if ($phan=="2"){
for ($bb=12;$bb<31;$bb++){
//$kq1="";$kq2="";$kq3="";$kq4="";$kq5="";
$b2=substr("00".$bb,-2);$b3="B".$b2;$b4="b".$b2;
$coco=0;
for ($t=1;$t<8;$t++){
$b5=$b4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$b5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$b3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$b3."' and link_='$link_' and link2_='$link2_'");
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$b3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
}
//------------------------------
if ($phan=="3"){
for ($cc=1;$cc<21;$cc++){
//$kq1="";$kq2="";$kq3="";$kq4="";$kq5="";
$c2=substr("00".$cc,-2);$c3="C".$c2;$c4="c".$c2;
$coco=0;
for ($t=1;$t<8;$t++){
$c5=$c4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$c5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$c3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
if ($kq6=="delete"){
mysql_query("DELETE from nss_aa_lylichkhoahoc where type_='".$c3."' and link_='$link_' and link2_='$link2_'");
}else{
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$c3."' and link_='$link_' and link2_='$link2_'");
}
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$c3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
}
//------------------------------
if ($phan=="4"){
if ($trang=="1"){$tutu=1;$denden=50;}else{$tutu=51;$denden=99;}
for ($dd=$tutu;$dd<$denden+1;$dd++){
//$kq1="";$kq2="";$kq3="";$kq4="";$kq5="";
$d2=substr("00".$dd,-2);$d3="D".$d2;$d4="d".$d2;
$coco=0;
for ($t=1;$t<8;$t++){
$d5=$d4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$d5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$d3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
if ($kq6=="delete"){
mysql_query("DELETE from nss_aa_lylichkhoahoc where type_='".$d3."' and link_='$link_' and link2_='$link2_'");
}else{
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$d3."' and link_='$link_' and link2_='$link2_'");
}
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$d3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
//---------------
if ($xll!=""){
$coco=0;
$h4="xxx";
for ($t=1;$t<8;$t++){
$h5=$h4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$h5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$xll."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$xll."' and link_='$link_' and link2_='$link2_'");
} else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$xll','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
//-----------------
}
//------------------------------
if ($phan=="5"){
if ($trang=="1"){$tutu=1;$denden=50;}else{$tutu=51;$denden=99;}
for ($ee=$tutu;$ee<$denden+1;$ee++){
//$kq1="";$kq2="";$kq3="";$kq4="";$kq5="";
$e2=substr("00".$ee,-2);$e3="E".$e2;$e4="e".$e2;
$coco=0;
for ($t=1;$t<8;$t++){
$e5=$e4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$e5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$e3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
if ($kq6=="delete"){
mysql_query("DELETE from nss_aa_lylichkhoahoc where type_='".$e3."' and link_='$link_' and link2_='$link2_'");
}else{
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$e3."' and link_='$link_' and link2_='$link2_'");
}
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$e3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
}
//------------------------------
if ($phan=="6"){
for ($ff=1;$ff<21;$ff++){
//$kq1="";$kq2="";$kq3="";$kq4="";$kq5="";
$f2=substr("00".$ff,-2);$f3="F".$f2;$f4="f".$f2;
$coco=0;
for ($t=1;$t<8;$t++){
$f5=$f4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$f5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$f3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$f3."' and link_='$link_' and link2_='$link2_'");
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$f3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
}
//------------------------------
if ($phan=="7"){
for ($gg=1;$gg<21;$gg++){
$g2=substr("00".$gg,-2);$g3="G".$g2;$g4="g".$g2;
$coco=0;
for ($t=1;$t<8;$t++){
$g5=$g4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$g5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$g3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$g3."' and link_='$link_' and link2_='$link2_'");
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$g3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
}
//------------------------------
if ($phan=="8"){
for ($hh=1;$hh<21;$hh++){
$h2=substr("00".$hh,-2);$h3="H".$h2;$h4="h".$h2;
$coco=0;
for ($t=1;$t<8;$t++){
$h5=$h4."_".$t;
$kq="kq".$t;
$$kq=str_replace('"',"`",str_replace("'","`",$$h5));
if ($$kq!=""){$coco=1;}
}
if ($coco==1){
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='".$h3."' and link_='$link_' and link2_='$link2_'");
if ($row=mysql_fetch_array($result)){
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text1='$kq1',text2='$kq2',text3='$kq3',text4='$kq4',text5='$kq5',text6='$kq6',text7='$kq7' where type_='".$h3."' and link_='$link_' and link2_='$link2_'");
}else{
$query="insert into nss_aa_lylichkhoahoc (type_,link_,link2_,text1,text2,text3,text4,text5,text6,text7) values ('$h3','$link_','$link2_','$kq1','$kq2','$kq3','$kq4','$kq5','$kq6','$kq7')";
mysql_query($query) or die (mysql_error());
}
}
}
}
//------------------------------
$x=editlylich;
}
if ($_SESSION["permissedit"]=='a2003'){
if ((strpos($_SESSION["permissedit"],'2003')>0) and ($z=='addphongban')){
$nd=date("YmdHis");
$link__="00001";
$result=mysql_query("select * from nss_aa_lylichkhoahoc where type_='A0' order by link_ DESC");
if ($row=mysql_fetch_array($result)){$link__=substr("00000".($row["link_"]*1+1),-5);}
$tieude=str_replace($loaitru,"`",$tieude);
$order__=$link__*1;
$query="insert into nss_aa_lylichkhoahoc (type_,link_,order_,text3) values ('A0','$link__','$order__','$tieude')";
mysql_query($query) or die (mysql_error());
}
?>
?>
if ((strpos($_SESSION["permissedit"],'2003')>0) and ($z=='edituser')){
mysql_query("UPDATE nss_aa_lylichkhoahoc SET text3='$ten',text4='$account',text5='$pass' where type_='A1' and id='$id'");
$x="userphongban";
}
?>
if ((strpos($_SESSION["permissedit"],'2003')>0) and ($z=='adduser')){
$query="insert into nss_aa_lylichkhoahoc (type_,link_,order_,text3,text4,text5) values ('A1','$id_','1','$ten','$account','$pass')";
mysql_query($query) or die (mysql_error());
$x="userphongban";
}
?>
if ((strpos($_SESSION["permissedit"],'2003')>0) and ($x=='editalbum_')){
if ($enable_=='ON') { $y1='1';} else {$y1='0';}
mysql_query("UPDATE nss_aa_album SET name_='$tieude',enable_='$y1',sothutu='$sttalb' where id=$id_");
echo $slpic."
";
for ($ii=1;$ii<=$slpic;$ii++){
$id_2="id".$ii;$id_3=$$id_2;
$pic_2="pic".$ii;$pic_3=trim($$pic_2);
$note_2="note".$ii;$note_3=trim($$note_2);
$stt_2="stt".$ii;$stt_3=$$stt_2;
$pic_3=str_replace($loaitru,"`",$pic_3);
$note_3=str_replace($loaitru,"`",$note_3);
$enable2="enable_".$ii;$enable_3=$$enable2;if ($enable_3=="ON"){$enable3="1";}else{$enable3="0";}
$ispic=1;
$nd=date("YmdHis");
if (strtoupper(substr($pic_3,0,4))<>"HTTP"){$ispic=0;}
if ((strtoupper(substr($pic_3,-4,4))==".JPG") or (strtoupper(substr($pic_3,-4,4))==".GIF")){$uu=1;}else{$ispic=0;}
if ($ispic==1){
if ($id_3==0){
$query="insert into nss_aa_album (idd,dmy,sothutu,name_,note_,enable_,type_) values ('$id_','$nd','$stt_3','$pic_3','$note_3','$enable3','B')";
mysql_query($query) or die (mysql_error());
}
else
{
mysql_query("UPDATE nss_aa_album SET sothutu='$stt_3',name_='$pic_3',note_='$note_3',enable_='$enable3' where id='$id_3'");
}
}
}
}
}
?>
Ly lich Khoa hoc