Server IP : 103.191.208.50 / Your IP : 216.73.216.53 Web Server : LiteSpeed System : Linux orion.herosite.pro 4.18.0-553.53.1.lve.el8.x86_64 #1 SMP Wed May 28 17:01:02 UTC 2025 x86_64 User : celkcksm ( 1031) PHP Version : 7.4.33 Disable Function : show_source, system, shell_exec, passthru, popen, exec MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : ON Directory (0750) : /home/celkcksm/websites/miereducation.e-campus.co.in/ |
[ Home ] | [ C0mmand ] | [ Upload File ] |
---|
<?php include_once('include/config.inc.php'); include_once('include/function.php'); switch($_REQUEST['do']) { case "StudentEnquiryEntry" : $StudentName = mysqli_escape_string($con,$_REQUEST['StudentName']); $Mobile = mysqli_escape_string($con,$_REQUEST['Mobile']); $AlternateMobNo = mysqli_escape_string($con,$_REQUEST['AlternateMobNo']); $LastQualification = mysqli_escape_string($con,$_REQUEST['LastQualification']); $Marks = mysqli_escape_string($con,$_REQUEST['Marks']); $rdbappllicant = mysqli_escape_string($con,$_REQUEST['rdbappllicant']); $ddlcaste = mysqli_escape_string($con,$_REQUEST['ddlcaste']); $University_Last_Attended = mysqli_escape_string($con,$_REQUEST['University_Last_Attended']); $Degree = mysqli_escape_string($con,$_REQUEST['Degree']); $SubjectCode = mysqli_escape_string($con,$_REQUEST['SubjectCode']); $UserID = mysqli_escape_string($con,$_REQUEST['UserID']); mysqli_query($con,"insert into studentenquiry(StudentName,PrimaryMobileNo,AlternateMobileNo,LastQualification,LastQualificationMarks,ApplicationType,Cast,UniversityLastAttended,DegreeName,SubjectName,UserName) values('".$StudentName."','".$Mobile."','".$AlternateMobNo."','".$LastQualification."','".$Marks."','".$rdbappllicant."','".$ddlcaste."','".$University_Last_Attended."','".$Degree."','".$SubjectCode."','".$UserID."')"); header("Location:StudentEnquiryReport.php"); break; case "EditStudentEnquiryEntry" : $StudentName = mysqli_escape_string($con,$_REQUEST['StudentName']); $Mobile = mysqli_escape_string($con,$_REQUEST['Mobile']); $AlternateMobNo = mysqli_escape_string($con,$_REQUEST['AlternateMobNo']); $LastQualification = mysqli_escape_string($con,$_REQUEST['LastQualification']); $Marks = mysqli_escape_string($con,$_REQUEST['Marks']); $rdbappllicant = mysqli_escape_string($con,$_REQUEST['rdbappllicant']); $ddlcaste = mysqli_escape_string($con,$_REQUEST['ddlcaste']); $University_Last_Attended = mysqli_escape_string($con,$_REQUEST['University_Last_Attended']); $Degree = mysqli_escape_string($con,$_REQUEST['Degree']); $SubjectCode = mysqli_escape_string($con,$_REQUEST['SubjectCode']); mysqli_query($con,"update studentenquiry set StudentName = '".$StudentName."', PrimaryMobileNo='".$Mobile."' , AlternateMobileNo='".$AlternateMobNo."', LastQualification='".$LastQualification."', LastQualificationMarks = '".$Marks."', ApplicationType='".$rdbappllicant."', Cast='".$ddlcaste."', UniversityLastAttended='".$University_Last_Attended."', DegreeName='".$Degree."', SubjectName='".$SubjectCode."' where id=".(int)$_REQUEST['doid']); header("Location:StudentEnquiryReport.php"); break; case "EditStudentEnquiryEntry" : $LanguageTitle = mysqli_escape_string($con,$_REQUEST['LanguageTitle']); mysqli_query($con,"update language set LanguageName='".$LanguageTitle."' where LanguageID=".(int)$_REQUEST['doid']); header("Location:Language.php"); break; case "LanguageEntry" : $LanguageTitle = mysqli_escape_string($con,$_REQUEST['LanguageTitle']); mysqli_query($con,"insert into language(LanguageName) values('".$LanguageTitle."')"); header("Location:Language.php"); break; case "EditLanguageEntry" : $LanguageTitle = mysqli_escape_string($con,$_REQUEST['LanguageTitle']); mysqli_query($con,"update language set LanguageName='".$LanguageTitle."' where LanguageID=".(int)$_REQUEST['doid']); header("Location:Language.php"); break; case "CourseEntry" : $CourseTitle = mysqli_escape_string($con,$_REQUEST['CourseTitle']); mysqli_query($con,"insert into course(c_name) values('".$CourseTitle."')"); header("Location:course.php"); break; case "EditCourseEntry" : $CourseTitle = mysqli_escape_string($con,$_REQUEST['CourseTitle']); mysqli_query($con,"update language set c_name='".$CourseTitle."' where id=".(int)$_REQUEST['doid']); header("Location:course.php"); break; case "ReligionEntry" : $ReligionTitle = mysqli_escape_string($con,$_REQUEST['ReligionTitle']); mysqli_query($con,"insert into religion(ReligionName) values('".$ReligionTitle."')"); header("Location:Religion.php"); break; case "EditReligionEntry" : $ReligionTitle = mysqli_escape_string($con,$_REQUEST['ReligionTitle']); mysqli_query($con,"update religion set ReligionName='".$ReligionTitle."' where ReligionID=".(int)$_REQUEST['doid']); header("Location:Religion.php"); break; case "CasteEntry" : $CasteTitle = mysqli_escape_string($con,$_REQUEST['CasteTitle']); mysqli_query($con,"insert into caste(CasteName) values('".$CasteTitle."')"); header("Location:Caste.php"); break; case "EditCasteEntry" : $CasteTitle = mysqli_escape_string($con,$_REQUEST['CasteTitle']); mysqli_query($con,"update caste set CasteName='".$CasteTitle."' where CasteID=".(int)$_REQUEST['doid']); header("Location:Caste.php"); break; case "GenderEntry" : $GenderTitle = mysqli_escape_string($con,$_REQUEST['GenderTitle']); mysqli_query($con,"insert into gender(GenderName) values('".$GenderTitle."')"); header("Location:Gender.php"); break; case "EditGenderEntry" : $GenderTitle = mysqli_escape_string($con,$_REQUEST['GenderTitle']); mysqli_query($con,"update gender set GenderName='".$GenderTitle."' where GenderID=".(int)$_REQUEST['doid']); header("Location:Gender.php"); break; case "CommunicationEntry" : $CommunicationTitle = mysqli_escape_string($con,$_REQUEST['CommunicationTitle']); mysqli_query($con,"insert into communication(CommunicationName) values('".$CommunicationTitle."')"); header("Location:Communication.php"); break; case "EditCommunicationEntry" : $CommunicationTitle = mysqli_escape_string($con,$_REQUEST['CommunicationTitle']); mysqli_query($con,"update communication set CommunicationName='".$CommunicationTitle."' where CommunicationID=".(int)$_REQUEST['doid']); header("Location:Communication.php"); break; case "BEDSubjectEntry" : $SubjectTitle = mysqli_escape_string($con,$_REQUEST['SubjectTitle']); $SubjectCode = mysqli_escape_string($con,$_REQUEST['SubjectCode']); $Subjectperiod = mysqli_escape_string($con,$_REQUEST['Subjectperiod']); mysqli_query($con,"insert into subject(SubjectTitle,SubjectCode,TotalPeriod,Status) values('".$SubjectTitle."','".$SubjectCode."','".$Subjectperiod."','1')"); header("Location:BEDSubjectEntry.php"); break; case "EditBEDSubjectEntry" : $SubjectTitle = mysqli_escape_string($con,$_REQUEST['SubjectTitle']); $SubjectCode = mysqli_escape_string($con,$_REQUEST['SubjectCode']); $Subjectperiod = mysqli_escape_string($con,$_REQUEST['Subjectperiod']); mysqli_query($con,"update subject set SubjectTitle='".$SubjectTitle."',SubjectCode='".$SubjectCode."',TotalPeriod='".$Subjectperiod."' where SubjectID=".(int)$_REQUEST['doid']); header("Location:BEDSubjectEntry.php"); break; case "BEDAcademicYearEntry" : $Degree = mysqli_escape_string($con,$_REQUEST['Degree']); $AcademicTitle = mysqli_escape_string($con,$_REQUEST['AcademicTitle']); $AcademicStartDate = mysqli_escape_string($con,$_REQUEST['AcademicStartDate']); $AcademicEndDate = mysqli_escape_string($con,$_REQUEST['AcademicEndDate']); $currentyear = mysqli_escape_string($con,$_REQUEST['currentyear']); mysqli_query($con,"insert into academicyear(Degree,AcademicTitle,AcademicStartDate,AcademicEndDate,CurrentYear,Status) values('".$Degree."','".$AcademicTitle."','".$AcademicStartDate."','".$AcademicEndDate."','".$currentyear."','1')"); header("Location:BEDAcademicYearEntry.php"); break; case "EditBEDAcademicYearEntry" : $AcademicTitle = mysqli_escape_string($con,$_REQUEST['AcademicTitle']); $AcademicStartDate = mysqli_escape_string($con,$_REQUEST['AcademicStartDate']); $AcademicEndDate = mysqli_escape_string($con,$_REQUEST['AcademicEndDate']); $currentyear = mysqli_escape_string($con,$_REQUEST['currentyear']); mysqli_query($con,"update academicyear set AcademicTitle='".$AcademicTitle."',AcademicStartDate='".$AcademicStartDate."',AcademicEndDate='".$AcademicEndDate."',CurrentYear='".$currentyear."' where AcademicYearID=".(int)$_REQUEST['doid']); header("Location:BEDAcademicYearEntry.php"); break; case "ConsultantEntry" : $Degree = mysqli_escape_string($con,$_REQUEST['Degree']); $PersonName = mysqli_escape_string($con,$_REQUEST['PersonName']); $ContactNo = mysqli_escape_string($con,$_REQUEST['ContactNo']); mysqli_query($con,"insert into consultant(Degree,PersonName,ContactNo,Status) values('".$Degree."','".$PersonName."','".$ContactNo."','1')"); header("Location:BEDConsultantMaster.php"); break; case "EditConsultantEntry" : $PersonName = mysqli_escape_string($con,$_REQUEST['PersonName']); $ContactNo = mysqli_escape_string($con,$_REQUEST['ContactNo']); mysqli_query($con,"update consultant set PersonName='".$PersonName."',ContactNo='".$ContactNo."' where ConsultantID=".(int)$_REQUEST['doid']); header("Location:BEDConsultantMaster.php"); break; case "ApplicationEntry" : $ApplicantType = mysqli_escape_string($con,$_REQUEST['ApplicantType']); mysqli_query($con,"insert into applicant(ApplicationTypeName,Status) values('".$ApplicantType."','1')"); header("Location:ApplicantType.php"); break; case "EditApplicationEntry" : $ApplicantType = mysqli_escape_string($con,$_REQUEST['ApplicantType']); mysqli_query($con,"update applicant set ApplicationTypeName='".$ApplicantType."' where ApplicantID=".(int)$_REQUEST['doid']); header("Location:ApplicantType.php"); break; case "BEDMarksheetUploadEntry" : $StudentCode = mysqli_escape_string($con,$_REQUEST['StudentCode']); $Semester = mysqli_escape_string($con,$_REQUEST['Semester']); $SubjectName = mysqli_escape_string($con,$_REQUEST['SubjectName']); $MarksheetPhoto = ''; if($_FILES['MarksheetPhoto']['name']!= NULL){ $MarksheetPhoto = time().'_'.$_FILES['MarksheetPhoto']['name']; move_uploaded_file($_FILES['MarksheetPhoto']['tmp_name'],"images/MarksheetPhoto/".$MarksheetPhoto); } mysqli_query($con,"insert into studentmarksheetupload(StudentCode,Semester,SubjectName,MarksheetPhoto) values('".$StudentCode."','".$Semester."','".$SubjectName."','".$MarksheetPhoto."')"); header("Location:BEDMarksheetUpload.php"); break; case "EditBEDMarksheetUploadEntry" : $StudentCode = mysqli_escape_string($con,$_REQUEST['StudentCode']); $Semester = mysqli_escape_string($con,$_REQUEST['Semester']); $SubjectName = mysqli_escape_string($con,$_REQUEST['SubjectName']); if($_FILES['MarksheetPhoto']['name']!= NULL){ $MarksheetPhoto = time().'_'.$_FILES['MarksheetPhoto']['name']; move_uploaded_file($_FILES['MarksheetPhoto']['tmp_name'],"images/MarksheetPhoto/".$MarksheetPhoto); }else{$MarksheetPhoto = mysqli_escape_string($con,$_REQUEST['OldMarksheetPhoto']);} mysqli_query($con,"update studentmarksheetupload set StudentCode='".$StudentCode."',Semester='".$Semester."',SubjectName='".$SubjectName."',MarksheetPhoto='".$MarksheetPhoto."' where SMUID=".(int)$_REQUEST['doid']); header("Location:BEDMarksheetUpload.php"); break; case "AdmissionFormEntry" : header("Location:OnlyAdmissionForm.php"); echo '<pre>'; //print_r($_REQUEST); echo '</pre>'; exit; $StudentCode = mysqli_escape_string($con,$_REQUEST['StudentCode']); $EnrollmentNo = mysqli_escape_string($con,$_REQUEST['EnrollmentNo']); $DegreeName = mysqli_escape_string($con,$_REQUEST['Degree']); $ApplicationTypeName = mysqli_escape_string($con,$_REQUEST['rdbappllicant']); $AcademicYear = mysqli_escape_string($con,$_REQUEST['AcademicYear']); $UniversityLastAttended = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $RNULU = mysqli_escape_string($con,$_REQUEST['RNOTULA']); $Language = mysqli_escape_string($con,$_REQUEST['Language']); $Religion = mysqli_escape_string($con,$_REQUEST['Religion']); $Cast = mysqli_escape_string($con,$_REQUEST['Caste']); $OBCdetails = mysqli_escape_string($con,$_REQUEST['Gender']); $Gender = mysqli_escape_string($con,$_REQUEST['Nationality']); $Nationality = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $StudentFirstName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $StudentLastName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $DOB = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $PlaceofBirth = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $BloodGroup = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $IdentificationMarks = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $FatherFirstName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $FatherLastName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $MotherFirstName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $MotherLastName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianFirstName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianLastName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianRelationship = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianLandLineNo = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianMobileNo = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianAddress = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianCity = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianDistrict = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianState = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GuardianPinCode = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $HTCDistance = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $SourceName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $ConsultantName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $ContactNo = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $SubjectName = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $RegistrationDate = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $StudentPhoto = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $StudentSignature = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $AADHAAR_CARD = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $MADHYAMICK_REGISTRATION = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $GRADUATION_MARKSHEET = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $MASTERS_MARKSHEET = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $MC_RESOLUTION = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $DI_PERMISION = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $CAST_CERTIFICATE = mysqli_escape_string($con,$_REQUEST['UniversityLastAttended']); $MarksheetPhoto = ''; if($_FILES['MarksheetPhoto']['name']!= NULL){ $MarksheetPhoto = time().'_'.$_FILES['MarksheetPhoto']['name']; move_uploaded_file($_FILES['MarksheetPhoto']['tmp_name'],"images/MarksheetPhoto/".$MarksheetPhoto); } mysqli_query($con,"insert into studentmarksheetupload(StudentCode,Semester,SubjectName,MarksheetPhoto) values('".$StudentCode."','".$Semester."','".$SubjectName."','".$MarksheetPhoto."')"); header("Location:BEDMarksheetUpload.php"); break; case "EditAdmissionFormEntry" : $StudentCode = mysqli_escape_string($con,$_REQUEST['StudentCode']); $Semester = mysqli_escape_string($con,$_REQUEST['Semester']); $SubjectName = mysqli_escape_string($con,$_REQUEST['SubjectName']); if($_FILES['MarksheetPhoto']['name']!= NULL){ $MarksheetPhoto = time().'_'.$_FILES['MarksheetPhoto']['name']; move_uploaded_file($_FILES['MarksheetPhoto']['tmp_name'],"images/MarksheetPhoto/".$MarksheetPhoto); }else{$MarksheetPhoto = mysqli_escape_string($con,$_REQUEST['OldMarksheetPhoto']);} mysqli_query($con,"update studentmarksheetupload set StudentCode='".$StudentCode."',Semester='".$Semester."',SubjectName='".$SubjectName."',MarksheetPhoto='".$MarksheetPhoto."' where SMUID=".(int)$_REQUEST['doid']); header("Location:OnlyAdmissionForm.php"); break; case "FeesHeadEntry" : $FeesHead = mysqli_escape_string($con,$_REQUEST['FeesHead']); $Amount = mysqli_escape_string($con,$_REQUEST['Amount']); mysqli_query($con,"insert into FeesHead(FeesHeadTitle,Amount) values('".$FeesHead."','".$Amount."')"); header("Location:BEDFeesHeadMaster.php"); break; case "EditFeesHeadEntry" : $FeesHead = mysqli_escape_string($con,$_REQUEST['FeesHead']); $Amount = mysqli_escape_string($con,$_REQUEST['Amount']); mysqli_query($con,"update FeesHead set FeesHeadTitle='".$FeesHead."',Amount='".$Amount."' where FeesHeadID=".(int)$_REQUEST['doid']); header("Location:BEDFeesHeadMaster.php"); break; case "MEDSubjectEntry" : $SubjectTitle = mysqli_escape_string($con,$_REQUEST['SubjectTitle']); $SubjectCode = mysqli_escape_string($con,$_REQUEST['SubjectCode']); $Subjectperiod = mysqli_escape_string($con,$_REQUEST['Subjectperiod']); mysqli_query($con,"insert into medsubject(SubjectTitle,SubjectCode,TotalPeriod,Status) values('".$SubjectTitle."','".$SubjectCode."','".$Subjectperiod."','1')"); header("Location:MEDSubjectEntry.php"); break; case "EditMEDSubjectEntry" : $SubjectTitle = mysqli_escape_string($con,$_REQUEST['SubjectTitle']); $SubjectCode = mysqli_escape_string($con,$_REQUEST['SubjectCode']); $Subjectperiod = mysqli_escape_string($con,$_REQUEST['Subjectperiod']); mysqli_query($con,"update medsubject set SubjectTitle='".$SubjectTitle."',SubjectCode='".$SubjectCode."',TotalPeriod='".$Subjectperiod."' where SubjectID=".(int)$_REQUEST['doid']); header("Location:MEDSubjectEntry.php"); break; case "SectionEntry" : $ddlSubject = mysqli_escape_string($con,$_REQUEST['ddlSubject']); $Year = mysqli_escape_string($con,$_REQUEST['Year']); $TotalPeriod = mysqli_escape_string($con,$_REQUEST['TotalPeriod']); mysqli_query($con,"insert into sectionyear(Subject,Year,TotalPeriod) values('".$ddlSubject."','".$Year."','".$TotalPeriod."')"); header("Location:SectionEntry.php"); break; case "EditSectionEntry" : $ddlSubject = mysqli_escape_string($con,$_REQUEST['ddlSubject']); $Year = mysqli_escape_string($con,$_REQUEST['Year']); $TotalPeriod = mysqli_escape_string($con,$_REQUEST['TotalPeriod']); mysqli_query($con,"update sectionyear set Subject='".$ddlSubject."',Year='".$Year."',TotalPeriod='".$TotalPeriod."' where YearID=".(int)$_REQUEST['doid']); header("Location:SectionEntry.php"); break; case "MEDAcademicYearEntry" : $Degree = mysqli_escape_string($con,$_REQUEST['Degree']); $AcademicTitle = mysqli_escape_string($con,$_REQUEST['AcademicTitle']); $AcademicStartDate = mysqli_escape_string($con,$_REQUEST['AcademicStartDate']); $AcademicEndDate = mysqli_escape_string($con,$_REQUEST['AcademicEndDate']); $currentyear = mysqli_escape_string($con,$_REQUEST['currentyear']); mysqli_query($con,"insert into medacademicyear(Degree,AcademicTitle,AcademicStartDate,AcademicEndDate,CurrentYear,Status) values('".$Degree."','".$AcademicTitle."','".$AcademicStartDate."','".$AcademicEndDate."','".$currentyear."','1')"); header("Location:MEDAcademicYearEntry.php"); break; case "EditMEDAcademicYearEntry" : $AcademicTitle = mysqli_escape_string($con,$_REQUEST['AcademicTitle']); $AcademicStartDate = mysqli_escape_string($con,$_REQUEST['AcademicStartDate']); $AcademicEndDate = mysqli_escape_string($con,$_REQUEST['AcademicEndDate']); $currentyear = mysqli_escape_string($con,$_REQUEST['currentyear']); mysqli_query($con,"update medacademicyear set AcademicTitle='".$AcademicTitle."',AcademicStartDate='".$AcademicStartDate."',AcademicEndDate='".$AcademicEndDate."',CurrentYear='".$currentyear."' where AcademicYearID=".(int)$_REQUEST['doid']); header("Location:MEDAcademicYearEntry.php"); break; case "MEDConsultantEntry" : $Degree = mysqli_escape_string($con,$_REQUEST['Degree']); $PersonName = mysqli_escape_string($con,$_REQUEST['PersonName']); $ContactNo = mysqli_escape_string($con,$_REQUEST['ContactNo']); mysqli_query($con,"insert into medconsultant(Degree,PersonName,ContactNo,Status) values('".$Degree."','".$PersonName."','".$ContactNo."','1')"); header("Location:MEDConsultantMaster.php"); break; case "EditMEDConsultantEntry" : $PersonName = mysqli_escape_string($con,$_REQUEST['PersonName']); $ContactNo = mysqli_escape_string($con,$_REQUEST['ContactNo']); mysqli_query($con,"update medconsultant set PersonName='".$PersonName."',ContactNo='".$ContactNo."' where ConsultantID=".(int)$_REQUEST['doid']); header("Location:MEDConsultantMaster.php"); break; case "MEDMarksheetUploadEntry" : $StudentCode = mysqli_escape_string($con,$_REQUEST['StudentCode']); $Semester = mysqli_escape_string($con,$_REQUEST['Semester']); $SubjectName = mysqli_escape_string($con,$_REQUEST['SubjectName']); $MarksheetPhoto = ''; if($_FILES['MarksheetPhoto']['name']!= NULL){ $MarksheetPhoto = time().'_'.$_FILES['MarksheetPhoto']['name']; move_uploaded_file($_FILES['MarksheetPhoto']['tmp_name'],"images/MarksheetPhoto/".$MarksheetPhoto); } mysqli_query($con,"insert into medstudentmarksheetupload(StudentCode,Semester,SubjectName,MarksheetPhoto) values('".$StudentCode."','".$Semester."','".$SubjectName."','".$MarksheetPhoto."')"); header("Location:MEDMarksheetUpload.php"); break; case "EditMEDMarksheetUploadEntry" : $StudentCode = mysqli_escape_string($con,$_REQUEST['StudentCode']); $Semester = mysqli_escape_string($con,$_REQUEST['Semester']); $SubjectName = mysqli_escape_string($con,$_REQUEST['SubjectName']); if($_FILES['MarksheetPhoto']['name']!= NULL){ $MarksheetPhoto = time().'_'.$_FILES['MarksheetPhoto']['name']; move_uploaded_file($_FILES['MarksheetPhoto']['tmp_name'],"images/MarksheetPhoto/".$MarksheetPhoto); }else{$MarksheetPhoto = mysqli_escape_string($con,$_REQUEST['OldMarksheetPhoto']);} mysqli_query($con,"update medstudentmarksheetupload set StudentCode='".$StudentCode."',Semester='".$Semester."',SubjectName='".$SubjectName."',MarksheetPhoto='".$MarksheetPhoto."' where SMUID=".(int)$_REQUEST['doid']); header("Location:MEDMarksheetUpload.php"); break; case "MEDStudentAdmitUploadEntry" : $StudentCode = mysqli_escape_string($con,$_REQUEST['StudentCode']); $AdmitPhoto = ''; if($_FILES['AdmitPhoto']['name']!= NULL){ $AdmitPhoto = time().'_'.$_FILES['AdmitPhoto']['name']; move_uploaded_file($_FILES['AdmitPhoto']['tmp_name'],"images/AdmitPhoto/".$AdmitPhoto); } mysqli_query($con,"insert into studentadmitupload(StudentCode,AdmitPhoto) values('".$StudentCode."','".$AdmitPhoto."')"); header("Location:MEDAdmitUpload.php"); break; case "EditMEDStudentAdmitUploadEntry" : $StudentCode = mysqli_escape_string($con,$_REQUEST['StudentCode']); if($_FILES['AdmitPhoto']['name']!= NULL){ $AdmitPhoto = time().'_'.$_FILES['AdmitPhoto']['name']; move_uploaded_file($_FILES['AdmitPhoto']['tmp_name'],"images/AdmitPhoto/".$AdmitPhoto); }else{$AdmitPhoto = mysqli_escape_string($con,$_REQUEST['OldAdmitPhoto']);} mysqli_query($con,"update studentadmitupload set StudentCode='".$StudentCode."',AdmitPhoto='".$AdmitPhoto."' where StudentAdmitUploadID=".(int)$_REQUEST['doid']); header("Location:MEDAdmitUpload.php"); break; case "MEDFeesHeadEntry" : $FeesHead = mysqli_escape_string($con,$_REQUEST['FeesHead']); $Amount = mysqli_escape_string($con,$_REQUEST['Amount']); mysqli_query($con,"insert into medfeeshead(FeesHeadTitle,Amount) values('".$FeesHead."','".$Amount."')"); header("Location:MEDFeesHeadMaster.php"); break; case "MEDEditFeesHeadEntry" : $FeesHead = mysqli_escape_string($con,$_REQUEST['FeesHead']); $Amount = mysqli_escape_string($con,$_REQUEST['Amount']); mysqli_query($con,"update medfeeshead set FeesHeadTitle='".$FeesHead."',Amount='".$Amount."' where FeesHeadID=".(int)$_REQUEST['doid']); header("Location:MEDFeesHeadMaster.php"); break; case "DepartmentEntry" : $DepartmentName = mysqli_escape_string($con,$_REQUEST['DepartmentName']); $EntryUser = mysqli_escape_string($con,$_REQUEST['EntryUser']); mysqli_query($con,"insert into departmentmaster(DepartmentName,EntryUser) values('".$DepartmentName."','".$EntryUser."')"); header("Location:DepartmentMaster.php"); break; case "EditDepartmentEntry" : $DepartmentName = mysqli_escape_string($con,$_REQUEST['DepartmentName']); mysqli_query($con,"update departmentmaster set DepartmentName='".$DepartmentName."' where DepartmentID=".(int)$_REQUEST['doid']); header("Location:DepartmentMaster.php"); break; case "DesignationEntry" : $DesignationName = mysqli_escape_string($con,$_REQUEST['DesignationName']); $EntryUser = mysqli_escape_string($con,$_REQUEST['EntryUser']); mysqli_query($con,"insert into designationmaster(DesignationName,EntryUser) values('".$DesignationName."','".$EntryUser."')"); header("Location:DesignationMaster.php"); break; case "EditDesignationEntry" : $DesignationName = mysqli_escape_string($con,$_REQUEST['DesignationName']); mysqli_query($con,"update designationmaster set DesignationName='".$DesignationName."' where DesignationID=".(int)$_REQUEST['doid']); header("Location:DesignationMaster.php"); break; case "EmployeeTypeEntry" : $EmployeeTypeName = mysqli_escape_string($con,$_REQUEST['EmployeeTypeName']); $EntryUser = mysqli_escape_string($con,$_REQUEST['EntryUser']); mysqli_query($con,"insert into employeetype(EmployeeTypeName,EntryUser) values('".$EmployeeTypeName."','".$EntryUser."')"); header("Location:EmployeeType.php"); break; case "EditEmployeeTypeEntry" : $EmployeeTypeName = mysqli_escape_string($con,$_REQUEST['EmployeeTypeName']); mysqli_query($con,"update employeetype set EmployeeTypeName='".$EmployeeTypeName."' where EmployeeTypeID=".(int)$_REQUEST['doid']); header("Location:EmployeeType.php"); break; case "EmployeeSalaryPayment" : $EmployeeId = mysqli_escape_string($con,$_REQUEST['EmployeeId']); $EnterMonth = mysqli_escape_string($con,$_REQUEST['EnterMonth']); $EnterYear = mysqli_escape_string($con,$_REQUEST['EnterYear']); $Latedays = mysqli_escape_string($con,$_REQUEST['Latedays']); $LateDeduction = mysqli_escape_string($con,$_REQUEST['LateDeduction']); $ExtraLeaves = mysqli_escape_string($con,$_REQUEST['ExtraLeaves']); $LeaveDeduction = mysqli_escape_string($con,$_REQUEST['LeaveDeduction']); $PaymentMode = mysqli_escape_string($con,$_REQUEST['PaymentMode']); mysqli_query($con,"insert into employeesalarypayment(EmployeeId,EnterMonth,EnterYear,Latedays,LateDeduction,ExtraLeaves,LeaveDeduction,PaymentMode) values('".$EmployeeId."','".$EnterMonth."','".$EnterYear."','".$Latedays."','".$LateDeduction."','".$ExtraLeaves."','".$LeaveDeduction."','".$PaymentMode."')"); header("Location:EmployeeSalaryPay.php"); break; case "EditEmployeeSalaryPayment" : $EmployeeId = mysqli_escape_string($con,$_REQUEST['EmployeeId']); $EnterMonth = mysqli_escape_string($con,$_REQUEST['EnterMonth']); $EnterYear = mysqli_escape_string($con,$_REQUEST['EnterYear']); $Latedays = mysqli_escape_string($con,$_REQUEST['Latedays']); $LateDeduction = mysqli_escape_string($con,$_REQUEST['LateDeduction']); $ExtraLeaves = mysqli_escape_string($con,$_REQUEST['ExtraLeaves']); $LeaveDeduction = mysqli_escape_string($con,$_REQUEST['LeaveDeduction']); $PaymentMode = mysqli_escape_string($con,$_REQUEST['PaymentMode']); mysqli_query($con,"update employeesalarypayment set EmployeeId='".$EmployeeId."',EnterMonth='".$EnterMonth."',EnterYear='".$EnterYear."',Latedays='".$Latedays."',LateDeduction='".$LateDeduction."',ExtraLeaves='".$ExtraLeaves."',LeaveDeduction='".$LeaveDeduction."',PaymentMode='".$PaymentMode."' where EmployeeSalaryPaymentID=".(int)$_REQUEST['doid']); header("Location:EmployeeSalaryPay.php"); break; case "MEDEmployeeEntryForm" : $EmployeeName = mysqli_escape_string($con,$_REQUEST['EmployeeName']); $EmployeeAddress = mysqli_escape_string($con,$_REQUEST['EmployeeAddress']); $ContactNo = mysqli_escape_string($con,$_REQUEST['ContactNo']); $DepartmentName = mysqli_escape_string($con,$_REQUEST['DepartmentName']); $DesignationName = mysqli_escape_string($con,$_REQUEST['DesignationName']); $EmployeeType = mysqli_escape_string($con,$_REQUEST['EmployeeName']); $PanNo = mysqli_escape_string($con,$_REQUEST['PanNo']); $AdharNo = mysqli_escape_string($con,$_REQUEST['AdharNo']); $DOB = mysqli_escape_string($con,$_REQUEST['DOB']); $DOJ = mysqli_escape_string($con,$_REQUEST['DOJ']); $ConfirmationDate = mysqli_escape_string($con,$_REQUEST['ConfirmationDate']); $CL = mysqli_escape_string($con,$_REQUEST['CL']); $EL = mysqli_escape_string($con,$_REQUEST['EL']); $Medical = mysqli_escape_string($con,$_REQUEST['Medical']); $PFNo = mysqli_escape_string($con,$_REQUEST['PFNo']); $BankAccNo = mysqli_escape_string($con,$_REQUEST['BankAccNo']); $AccountHolderName = mysqli_escape_string($con,$_REQUEST['AccountHolderName']); $BankName = mysqli_escape_string($con,$_REQUEST['BankName']); $BankBranchName = mysqli_escape_string($con,$_REQUEST['BankBranchName']); $IFSCCode = mysqli_escape_string($con,$_REQUEST['IFSCCode']); $AccountType = mysqli_escape_string($con,$_REQUEST['AccountType']); $BloodGroup = mysqli_escape_string($con,$_REQUEST['BloodGroup']); $LastCompanyJob = mysqli_escape_string($con,$_REQUEST['LastCompanyJob']); $EmergencyContactNo = mysqli_escape_string($con,$_REQUEST['EmergencyContactNo']);; if($_FILES['Photo']['name']!= NULL){ $Photo = time().'_'.$_FILES['Photo']['name']; move_uploaded_file($_FILES['Photo']['tmp_name'],"images/MarksheetPhoto/".$Photo); } if($_FILES['LastCompanyReleleseLatter']['name']!= NULL){ $LastCompanyReleleseLatter = time().'_'.$_FILES['LastCompanyReleleseLatter']['name']; move_uploaded_file($_FILES['LastCompanyReleleseLatter']['tmp_name'],"images/MarksheetPhoto/".$LastCompanyReleleseLatter); } if($_FILES['PanCard']['name']!= NULL){ $PanCard = time().'_'.$_FILES['PanCard']['name']; move_uploaded_file($_FILES['PanCard']['tmp_name'],"images/MarksheetPhoto/".$PanCard); } if($_FILES['AadhaarCard']['name']!= NULL){ $AadhaarCard = time().'_'.$_FILES['AadhaarCard']['name']; move_uploaded_file($_FILES['AadhaarCard']['tmp_name'],"images/MarksheetPhoto/".$AadhaarCard); } mysqli_query($con,"insert into employeeentryform(EmployeeName,EmployeeAddress,ContactNo,DepartmentName,DesignationName,EmployeeType,PanNo,AdharNo,DOB,DOJ,ConfirmationDate,CL,EL,Medical, PFNo,BankAccNo,AccountHolderName,BankName,BankBranchName,IFSCCode,AccountType,BloodGroup,LastCompanyJob,EmergencyContactNo,Photo,LastCompanyReleleseLatter,PanCard,AadhaarCard) values('".$EmployeeName."','".$EmployeeAddress."','".$ContactNo."','".$DepartmentName."','".$EmployeeType."','".$PanNo."','".$AdharNo."','".$DOB."','".$DOJ."','".$ConfirmationDate."','".$CL."','".$EL."','".$Medical."','".$PFNo."','".$BankAccNo."','".$AccountHolderName."','".$BankName."','".$BankBranchName."','".$IFSCCode."','".$AccountType."','".$BloodGroup."','".$LastCompanyJob."','".$EmergencyContactNo."','".$Photo."','".$LastCompanyReleleseLatter."','".$PanCard."','".$AadhaarCard."')"); header("Location:MEDEmployeeEntry.php"); break; case "EditMEDEmployeeEntryForm" : $EmployeeId = mysqli_escape_string($con,$_REQUEST['EmployeeId']); $EnterMonth = mysqli_escape_string($con,$_REQUEST['EnterMonth']); $EnterYear = mysqli_escape_string($con,$_REQUEST['EnterYear']); $Latedays = mysqli_escape_string($con,$_REQUEST['Latedays']); $LateDeduction = mysqli_escape_string($con,$_REQUEST['LateDeduction']); $ExtraLeaves = mysqli_escape_string($con,$_REQUEST['ExtraLeaves']); $LeaveDeduction = mysqli_escape_string($con,$_REQUEST['LeaveDeduction']); $PaymentMode = mysqli_escape_string($con,$_REQUEST['PaymentMode']); mysqli_query($con,"update employeeentryform set EmployeeId='".$EmployeeId."',EnterMonth='".$EnterMonth."',EnterYear='".$EnterYear."',Latedays='".$Latedays."',LateDeduction='".$LateDeduction."',ExtraLeaves='".$ExtraLeaves."',LeaveDeduction='".$LeaveDeduction."',PaymentMode='".$PaymentMode."' where EmployeeSalaryPaymentID=".(int)$_REQUEST['doid']); header("Location:MEDEmployeeEntry.php"); break; case "SubjectEntry" : $SubjectTitle = mysqli_escape_string($con,$_REQUEST['SubjectTitle']); $ddlcourse = mysqli_escape_string($con,$_REQUEST['ddlcourse']); mysqli_query($con,"insert into student_subject(SubjectName,CourseID) values('".$SubjectTitle."','".$ddlcourse."')"); header("Location:StudentSubject.php"); break; case "EditSubjectEntry" : $EmployeeTypeName = mysqli_escape_string($con,$_REQUEST['EmployeeTypeName']); mysqli_query($con,"update student_subject set SubjectName='".$SubjectTitle."' ,CourseID= '".$ddlcourse."'where CourseID=".(int)$_REQUEST['doid']); header("Location:StudentSubject.php"); break; }