HEX
Server: Apache
System: Linux sg2plmcpnl492417.prod.sin2.secureserver.net 4.18.0-553.58.1.lve.el8.x86_64 #1 SMP Fri Jul 4 12:07:06 UTC 2025 x86_64
User: nyiet8349bzl (9207396)
PHP: 8.1.34
Disabled: NONE
Upload Files
File: /home/nyiet8349bzl/Backup/sbc_back/homedir/public_html/classes/site_class.php
<?php
	include('../config/connection.php');
	class Site extends createCon
	{
		function __construct()
		{
			$this->connect();
		}

		//*******************Category List Function***************************/
		function getCategoryList($selected="")
		{
			$listStates = ""; 
			$states_array = array();
			$states = mysqli_query($this->myconn, "SELECT * FROM category ORDER BY name ASC");
			while ($states_values = mysqli_fetch_array($states))
			{
				$states_array[$states_values['id']] = $states_values['name'];
			}
			foreach($states_array as $key => $value)
			{
				$listStates.="<option value=\"".$key."\"".((strtolower($selected) == strtolower($key)) ? " selected=\"selected\"" : "").">".$value."</option>";
			}
			return $listStates;
		}
	
		//*************** ADD AND UPDATE News ***************//
		function addNews()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['name']) and !empty($_REQUEST['name']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$name = mysqli_real_escape_string($this->myconn, $_REQUEST['name']);
				$category = mysqli_real_escape_string($this->myconn, $_REQUEST['category']);
				$imagequery ='';
				$dir_name = "../uploads/pdf";
	
				if($_FILES['image']['name']!='')
				{
					$fsize = $_FILES['image']['size'];
					if($fsize > FILESIZE)
					{
						return 7; //##### file is greater then 15 MB
					}                 
					$filename = explode(".",$_FILES["image"]["name"]);
					$file_ext =  strtolower(end($filename));
					$imgname = substr($_FILES["image"]["name"],0,-(strlen($file_ext)+1));
					$filename = str_replace(" ","_",$imgname);
					
					//################CHECK EXTENTION FOR IMAGE ######################//                
					$allExtarray = array("pdf","docx","doc","png","jpg","jpeg");
					
					if(!in_array($file_ext,$allExtarray))
					{
						return 8; //##### file extension not accepted
					}      
					$profile_image = time().'_'.$filename.'.'.$file_ext;
					if(!file_exists($dir_name))
					{
						$flag = mkdir($dir_name, 0777,true);                    
					}
					if(file_exists($dir_name."/".$profile_image))
					{                    
						@unlink($dir_name."/".$profile_image);
					}
					$movefile=move_uploaded_file($_FILES["image"]["tmp_name"],$dir_name."/".$profile_image);
					if($movefile)
					{
						$imagequery = ",image='".$profile_image."'";
					}
				}
				$select = mysqli_query($this->myconn, "SELECT * FROM category WHERE id='".$category."'");
				$categoryName = mysqli_fetch_array($select);
				$location = $categoryName['name'];
				//echo "insert into aurobindo_news set name = '".$name."' $imagequery, category='".$location."', status='1', created_on='".$timeNdate1."'";	exit;
				$sql = "INSERT INTO news SET name = '".$name."' $imagequery, category='".$location."', status='1', created_on='".$timeNdate1."'";
				
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		function updateNews()
		{
			if(isset($_REQUEST['name']) and !empty($_REQUEST['name']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$id = $_REQUEST['id'];
				$name = mysqli_real_escape_string($this->myconn, $_REQUEST['name']);
				
				$imagequery ='';
				$dir_name = "../uploads/pdf";
	
				if($_FILES["image"]["name"]!='')
				{
					$fsize = $_FILES["image"]["size"];
					if($fsize > FILESIZE)
					{
						return 7; //##### file is greater then 15 MB
					}                 
					$filename = explode(".",$_FILES["image"]["name"]);
					$file_ext =  strtolower(end($filename));
					$imgname = substr($_FILES["image"]["name"],0,-(strlen($file_ext)+1));
					$filename = str_replace(" ","_",$imgname);
					
					//################CHECK EXTENTION FOR IMAGE ######################//                
					$allExtarray = array("pdf","docx","doc","png","jpg","jpeg");
					
					if(!in_array($file_ext,$allExtarray))
					{
						return 8; //##### file extension not accepted
					}      
					$profile_image = time().'_'.$filename.'.'.$file_ext;
					if(!file_exists($dir_name))
					{
						$flag = mkdir($dir_name, 0777,true);                    
					}
					if(file_exists($dir_name."/".$profile_image))
					{                    
						@unlink($dir_name."/".$profile_image);
					}
					$movefile=move_uploaded_file($_FILES["image"]["tmp_name"],$dir_name."/".$profile_image);
					if($movefile)
					{
						$imagequery = ",image='".$profile_image."'";
					}
				}
				
				//echo "update aurobindo_news set name = '".$name."' $imagequery, updated_on='".$timeNdate1."' where id='".$id."'";	exit;
				$sql = "update news set name = '".$name."' $imagequery where id='".$id."'";
				
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		//*************** ADD AND UPDATE Image ***************//
		function addImageCategory()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['image_title']) and !empty($_REQUEST['image_title']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$name = mysqli_real_escape_string($this->myconn, $_REQUEST['image_title']);
				$desc = mysqli_real_escape_string($this->myconn, $_REQUEST['image_desc']);
				$imagequery ='';
				$dir_name = "../uploads/image";
	
				if($_FILES["image"]["name"]!='')
				{
					$fsize = $_FILES["image"]["size"];
					if($fsize > FILESIZE)
					{
						return 7; //##### file is greater then 15 MB
					}                 
					$filename = explode(".",$_FILES["image"]["name"]);
					$file_ext =  strtolower(end($filename));
					$imgname = substr($_FILES["image"]["name"],0,-(strlen($file_ext)+1));
					$filename = str_replace(" ","_",$imgname);
					
					//################CHECK EXTENTION FOR IMAGE ######################//                
					$allExtarray = array("jpg","jpeg","png");
					
					if(!in_array($file_ext,$allExtarray))
					{
						return 8; //##### file extension not accepted
					}      
					$profile_image = time().'_'.$filename.'.'.$file_ext;
					if(!file_exists($dir_name))
					{
						$flag = mkdir($dir_name, 0777,true);                    
					}
					if(file_exists($dir_name."/".$profile_image))
					{                    
						@unlink($dir_name."/".$profile_image);
					}
					$movefile=move_uploaded_file($_FILES["image"]["tmp_name"],$dir_name."/".$profile_image);
					if($movefile)
					{
						$imagequery = ",image='".$profile_image."'";
					}
				}
				
				//echo "insert into aurobindo_image_category set image_title = '".$name."' $imagequery, description='".$desc."', created_on='".$timeNdate1."'";	exit;
				$sql = "insert into image_category set image_title = '".$name."' $imagequery, description='".$desc."', created_on='".$timeNdate1."'";
				
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		function updateImage()
		{
			if(isset($_REQUEST['image_title']) and !empty($_REQUEST['image_title']) and !empty($_REQUEST['id']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$id = $_REQUEST['id'];
				$title = mysqli_real_escape_string($this->myconn, $_REQUEST['image_title']);                   
				$description = mysqli_real_escape_string($this->myconn, $_REQUEST['description']); 
				$imagequery ='';
				$dir_name = "../uploads/image";
				if($_FILES["image"]["name"]!='')
				{
					$fsize = $_FILES["image"]["size"];
					if($fsize > FILESIZE)
					{
						return 7; //##### file is greater then 15 MB
					}                 
					$filename = explode(".",$_FILES["image"]["name"]);
					$file_ext =  strtolower(end($filename));
					$imgname = substr($_FILES["image"]["name"],0,-(strlen($file_ext)+1));
					$filename = str_replace(" ","_",$imgname);
					//################CHECK EXTENTION FOR IMAGE ######################//                
					$allExtarray = array("jpg","jpeg","png");
					if(!in_array($file_ext,$allExtarray))
					{                
						return 8; //##### file extension not accepted
					}      
					$profile_image = time().'_'.$filename.'.'.$file_ext;
					if(!file_exists($dir_name))
					{
						$flag = mkdir($dir_name, 0777,true);                    
					}
					if(file_exists($dir_name."/".$profile_image))
					{                    
						@unlink($dir_name."/".$profile_image);
					}
					$movefile=move_uploaded_file($_FILES["image"]["tmp_name"],$dir_name."/".$profile_image);
					if($movefile)
					{
						$imagequery = ",image='".$profile_image."'";
					}
				}
	
				$sql = "update image_category set image_title='".$title."'$imagequery,description='".$description."' where id='".$id."'"; 
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		//*******************IMAGE List Function***************************/
		function getImageList($selected="")
		{
			$listImage=""; 
			$image_array =array();
			$image = mysqli_query($this->myconn, "select * from image_category order by image_title ASC");
			while ($image_values = mysqli_fetch_array($image))
			{
				$image_array[$image_values['id']] = $image_values['image_title'];
			}
			foreach($image_array as $key => $value)
			{
				$listImage.="<option value=\"".$key."\"".((strtolower($selected) == strtolower($key)) ? " selected=\"selected\"" : "").">".$value."</option>";
			}
			return $listImage;
		}
	
		//*************** ADD AND UPDATE IMAGE ***************//
		function addImage()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['category']) and !empty($_REQUEST['category']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$category = mysqli_real_escape_string($this->myconn, $_REQUEST['category']);
				
				for ($k = 0; $k < count($_FILES['image']['name']); $k++) 
				{
					$snapshot_imagequery='';
					$dir_name = "../uploads/image";
					if($_FILES["image"]["name"][$k]!='')
					{
						$fsize = $_FILES["image"]["size"][$k];               
						if($fsize > FILESIZE)
						{
							return 7; //##### file is greater then 15 MB
						}     
							
						$filename = explode(".",$_FILES["image"]["name"][$k]);
						$file_ext =  strtolower(end($filename));
						$imgname = substr($_FILES["image"]["name"][$k],0,-(strlen($file_ext)+1));
						$filename = str_replace(" ","_",$imgname);               
						$allExtarray = array("jpg","jpeg","png");
								
						if(!in_array($file_ext,$allExtarray))
						{                
							return 8; //##### file extension not accepted
						}
						//echo "oooookkkkkkkkkkkk"; exit;
						$snap_shot = time().'_'.$filename.'.'.$file_ext;
								
						if(!file_exists($dir_name))
						{
							$flag = mkdir($dir_name, 0777,true);                    
						}
						if(file_exists($dir_name."/".$snap_shot))
						{                    
							@unlink($dir_name."/".$snap_shot);
						}
						//echo "snap_shot"; exit;
						$movefile=move_uploaded_file($_FILES["image"]["tmp_name"][$k],$dir_name."/".$snap_shot);
	
						$resp=mysqli_query($this->myconn, "insert into image set category='".$category."',image='".$snap_shot."', created_on='".$timeNdate1."'");
					}
					elseif(($snap_shot='')&&($_REQUEST['image'.$k]=''))
					{
						continue;
					}
				}
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		//*************** ADD AND UPDATE Tender ***************//
		function addTender()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['name']) and !empty($_REQUEST['name']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$name = mysqli_real_escape_string($_REQUEST['name']);
				
				$imagequery ='';
				$dir_name = "../uploads/pdf";
	
				if($_FILES["image"]["name"]!='')
				{
					$fsize = $_FILES["image"]["size"];
					if($fsize > FILESIZE)
					{
						return 7; //##### file is greater then 15 MB
					}                 
					$filename = explode(".",$_FILES["image"]["name"]);
					$file_ext =  strtolower(end($filename));
					$imgname = substr($_FILES["image"]["name"],0,-(strlen($file_ext)+1));
					$filename = str_replace(" ","_",$imgname);
					
					//################CHECK EXTENTION FOR IMAGE ######################//                
					$allExtarray = array("pdf","docx","doc","png","jpg","jpeg");
					
					if(!in_array($file_ext,$allExtarray))
					{
						return 8; //##### file extension not accepted
					}      
					$profile_image = time().'_'.$filename.'.'.$file_ext;
					if(!file_exists($dir_name))
					{
						$flag = mkdir($dir_name, 0777,true);                    
					}
					if(file_exists($dir_name."/".$profile_image))
					{                    
						@unlink($dir_name."/".$profile_image);
					}
					$movefile=move_uploaded_file($_FILES["image"]["tmp_name"],$dir_name."/".$profile_image);
					if($movefile)
					{
						$imagequery = ",image='".$profile_image."'";
					}
				}
				
				//echo "insert into aurobindo_time_table set name = '".$name."' $imagequery, created_on='".$timeNdate1."'";	exit;
				$sql = "insert into tender set name = '".$name."' $imagequery, created_on='".$timeNdate1."'";
				
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		function updateTender()
		{ 
			if(isset($_REQUEST['tender_title'],$_REQUEST['id']) and !empty($_REQUEST['tender_title']) and !empty($_REQUEST['id']))
			{
				$id = $_REQUEST['id'];
				$admin = $_SESSION['admin']['user_id'];
				$title = mysqli_real_escape_string($this->myconn, $_REQUEST['tender_title']);                   
				
				$sql = "update tender set name='".$title."' where id='".$id."'"; 
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true){
					return 5; //#####  ADDED SUCCESS
				}else{
					return 1; //##### FAILED SQL ERROR
				}
			}else{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}

		//*************** ADD AND UPDATE Cut off list ***************//
		function addCutoff()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['name']) and !empty($_REQUEST['name']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$year = mysqli_real_escape_string($this->myconn, $_REQUEST['year']);
				$name = mysqli_real_escape_string($this->myconn, $_REQUEST['name']);
				
				$imagequery ='';
				$dir_name = "../uploads/pdf";
	
				if($_FILES["image"]["name"]!='')
				{
					$fsize = $_FILES["image"]["size"];
					if($fsize > FILESIZE)
					{
						return 7; //##### file is greater then 15 MB
					}                 
					$filename = explode(".",$_FILES["image"]["name"]);
					$file_ext =  strtolower(end($filename));
					$imgname = substr($_FILES["image"]["name"],0,-(strlen($file_ext)+1));
					$filename = str_replace(" ","_",$imgname);
					
					//################CHECK EXTENTION FOR IMAGE ######################//                
					$allExtarray = array("pdf","docx","doc","png","jpg","jpeg");
					
					if(!in_array($file_ext,$allExtarray))
					{
						return 8; //##### file extension not accepted
					}      
					$profile_image = time().'_'.$filename.'.'.$file_ext;
					if(!file_exists($dir_name))
					{
						$flag = mkdir($dir_name, 0777,true);                    
					}
					if(file_exists($dir_name."/".$profile_image))
					{                    
						@unlink($dir_name."/".$profile_image);
					}
					$movefile=move_uploaded_file($_FILES["image"]["tmp_name"],$dir_name."/".$profile_image);
					if($movefile)
					{
						$imagequery = ",image='".$profile_image."'";
					}
				}
				
				//echo "insert into aurobindo_time_table set name = '".$name."' $imagequery, status='1', created_on='".$timeNdate1."'";	exit;
				$sql = "insert into cutoff set year='".$year."', name='".$name."' $imagequery, status='1', created_on='".$timeNdate1."'";
				
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		function updateCutoff()
		{ 
			if(isset($_REQUEST['cutoff_title'],$_REQUEST['id']) and !empty($_REQUEST['cutoff_title']) and !empty($_REQUEST['id']))
			{
				$id = $_REQUEST['id'];
				$admin = $_SESSION['admin']['user_id'];
				$title = mysqli_real_escape_string($this->myconn, $_REQUEST['cutoff_title']);
				
				$sql = "update cutoff set name='".$title."' where id='".$id."'"; 
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true){
					return 5; //#####  ADDED SUCCESS
				}else{
					return 1; //##### FAILED SQL ERROR
				}
			}else{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}

		//*************** ADD Video ***************//
		function addVideo()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['name']) and !empty($_REQUEST['name']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$name = mysqli_real_escape_string($this->myconn, $_REQUEST['name']);
				$url = mysqli_real_escape_string($this->myconn, $_REQUEST['url']);
				
				//echo "insert into aurobindo_video set video_title = '".$name."', url = '".$url."', created_on='".$timeNdate1."'";	exit;
				$sql = "insert into video set video_title = '".$name."', url = '".$url."', created_on='".$timeNdate1."'";
				
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		function updateVideo()
		{ 
			if(isset($_REQUEST['video_title'],$_REQUEST['id']) and !empty($_REQUEST['video_title']) and !empty($_REQUEST['id']))
			{
				$id = $_REQUEST['id'];
				$admin = $_SESSION['admin']['user_id'];
				$title = mysqli_real_escape_string($this->myconn, $_REQUEST['video_title']);                   
				$url = mysqli_real_escape_string($this->myconn, $_REQUEST['url']);                   
				
				$sql = "update video set video_title='".$title."', url='".$url."' where id='".$id."'"; 
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true){
					return 5; //#####  ADDED SUCCESS
				}else{
					return 1; //##### FAILED SQL ERROR
				}
			}else{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}

		//*************** ADD Time Table ***************//
		function addTimeTable()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['name']) and !empty($_REQUEST['name']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$name = mysqli_real_escape_string($this->myconn, $_REQUEST['name']);
				
				$imagequery ='';
				$dir_name = "../uploads/pdf";
	
				if($_FILES["image"]["name"]!='')
				{
					$fsize = $_FILES["image"]["size"];
					if($fsize > FILESIZE)
					{
						return 7; //##### file is greater then 15 MB
					}                 
					$filename = explode(".",$_FILES["image"]["name"]);
					$file_ext =  strtolower(end($filename));
					$imgname = substr($_FILES["image"]["name"],0,-(strlen($file_ext)+1));
					$filename = str_replace(" ","_",$imgname);
					
					//################CHECK EXTENTION FOR IMAGE ######################//                
					$allExtarray = array("pdf","docx","doc","png","jpg","jpeg");
					
					if(!in_array($file_ext,$allExtarray))
					{
						return 8; //##### file extension not accepted
					}      
					$profile_image = time().'_'.$filename.'.'.$file_ext;
					if(!file_exists($dir_name))
					{
						$flag = mkdir($dir_name, 0777,true);                    
					}
					if(file_exists($dir_name."/".$profile_image))
					{                    
						@unlink($dir_name."/".$profile_image);
					}
					$movefile=move_uploaded_file($_FILES["image"]["tmp_name"],$dir_name."/".$profile_image);
					if($movefile)
					{
						$imagequery = ",image='".$profile_image."'";
					}
				}
				
				//echo "insert into aurobindo_time_table set name = '".$name."' $imagequery, created_on='".$timeNdate1."'";	exit;
				$sql = "insert into time_table set name = '".$name."' $imagequery, created_on='".$timeNdate1."'";
				
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		function updateTime()
		{ 
			if(isset($_REQUEST['time_title'],$_REQUEST['id']) and !empty($_REQUEST['time_title']) and !empty($_REQUEST['id']))
			{
				$id = $_REQUEST['id'];
				$admin = $_SESSION['admin']['user_id'];
				$title = mysqli_real_escape_string($this->myconn, $_REQUEST['time_title']);                   
				
				$sql = "update time_table set name='".$title."' where id='".$id."'"; 
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true){
					return 5; //#####  ADDED SUCCESS
				}else{
					return 1; //##### FAILED SQL ERROR
				}
			}else{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		//*************** ADD Acedemic Calendar ***************//
		function addAcademicCalendar()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['name']) and !empty($_REQUEST['name']))
			{
				$admin = $_SESSION['admin']['user_id'];
				$name = mysqli_real_escape_string($this->myconn, $_REQUEST['name']);
				
				$imagequery ='';
				$dir_name = "../uploads/pdf";
	
				if($_FILES["image"]["name"]!='')
				{
					$fsize = $_FILES["image"]["size"];
					if($fsize > FILESIZE)
					{
						return 7; //##### file is greater then 15 MB
					}                 
					$filename = explode(".",$_FILES["image"]["name"]);
					$file_ext =  strtolower(end($filename));
					$imgname = substr($_FILES["image"]["name"],0,-(strlen($file_ext)+1));
					$filename = str_replace(" ","_",$imgname);
					
					//################CHECK EXTENTION FOR IMAGE ######################//                
					$allExtarray = array("pdf","docx","doc","png","jpg","jpeg");
					
					if(!in_array($file_ext,$allExtarray))
					{
						return 8; //##### file extension not accepted
					}      
					$profile_image = time().'_'.$filename.'.'.$file_ext;
					if(!file_exists($dir_name))
					{
						$flag = mkdir($dir_name, 0777,true);                    
					}
					if(file_exists($dir_name."/".$profile_image))
					{                    
						@unlink($dir_name."/".$profile_image);
					}
					$movefile=move_uploaded_file($_FILES["image"]["tmp_name"],$dir_name."/".$profile_image);
					if($movefile)
					{
						$imagequery = ",image='".$profile_image."'";
					}
				}
				
				//echo "insert into aurobindo_academic set name = '".$name."' $imagequery, created_on='".$timeNdate1."'";	exit;
				$sql = "insert into academic set name = '".$name."' $imagequery, created_on='".$timeNdate1."'";
				
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true)
				{
					return 5; //#####  ADDED SUCCESS
				}else
				{
					return 1; //##### FAILED SQL ERROR
				}
			}else
			{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
		
		function updateCalendar()
		{ 
			if(isset($_REQUEST['calendar_title'],$_REQUEST['id']) and !empty($_REQUEST['calendar_title']) and !empty($_REQUEST['id']))
			{
				$id = $_REQUEST['id'];
				$admin = $_SESSION['admin']['user_id'];
				$title = mysqli_real_escape_string($this->myconn, $_REQUEST['calendar_title']);                   
				
				$sql = "update academic set name='".$title."' where id='".$id."'"; 
				$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
				if($resp==true){
					return 5; //#####  ADDED SUCCESS
				}else{
					return 1; //##### FAILED SQL ERROR
				}
			}else{
				return 0;  //##### REQUIRED PARAMETER MISSING
			}
		}
	
		//*************** Update New Password ***************//
		function updatePassword()
		{
			$offset1=19800; //converting 5:30 hours to seconds.
			$dateFormat1="Y-m-d H:i:s";
			$timeNdate1=gmdate($dateFormat1, time()+$offset1);
			
			if(isset($_REQUEST['oldpassword']) and !empty($_REQUEST['oldpassword']))
			{
				$userid = $_SESSION['admin']['user_id'];
				$opwd = md5($_REQUEST['oldpassword']);
				$pwd = md5($_REQUEST['newpassword']);
				$chk_query = mysqli_query($this->myconn, "select id from user where id='".$userid."' and user_password='".$opwd."'");
				if(mysqli_num_rows($chk_query) < 1)
				{
					return $res=0;
				}else
				{
					$query = mysqli_query($this->myconn, "update user set user_password='".$pwd."' where id='1'");	
					if($query==true)
					{
						return $res=5;
					}else{
						return $res=1;
					}
				}
			}
		}

		
	
//*********************Update Alumni Registration form*************************//
	function updateAlumni()
	{
		$offset1=19800; //converting 5:30 hours to seconds.
		$dateFormat1="Y-m-d H:i:s";
		$timeNdate1=gmdate($dateFormat1, time()+$offset1);
		
		if(isset($_REQUEST['fname'], $_REQUEST['email']) and !empty($_REQUEST['fname']) and !empty($_REQUEST['email']))
		{
			$id = $_REQUEST['id'];
			$sname = $_REQUEST['sname'];
			$fname = mysqli_real_escape_string($this->myconn, $_REQUEST['fname']);
			$mname = mysqli_real_escape_string($this->myconn, $_REQUEST['mname']);
			$lname = mysqli_real_escape_string($this->myconn, $_REQUEST['lname']);
			$sex = $_REQUEST['sex'];
			$dob = $_REQUEST['dob'];	
			$course = $_REQUEST['course'];
			$passed = $_REQUEST['pass'];
			$address = $_REQUEST['address'];
			$city = $_REQUEST['city'];
			$state = $_REQUEST['country'];
			$zip = $_REQUEST['zip'];
			$phone = $_REQUEST['mobile'];
			$email = $_REQUEST['email'];
			$designation = $_REQUEST['designation'];
			$organiation = $_REQUEST['organiation'];
			$office = $_REQUEST['office'];
			
			$sql = "update aurobindo_alumni set sname='$sname',fname='$fname',mname='$mname',lname='$lname',sex='$sex',dob='$dob',course='$course',passout='$passed',address='$address',city='$city',country='$state',zip='$zip',mobile='$phone',email='$email',designation='$designation',organiation='$organiation',office='$office',created_on='$timeNdate1' where id='".$id."' ";
			
			$resp = mysqli_query($this->myconn, $sql) or die(mysqli_error($this->myconn));
			if($resp==true)
			{
				return 5; //#####  ADDED SUCCESS
			}else
			{
				return 1; //##### FAILED SQL ERROR
			}
		}else
		{
			return 0;  //##### REQUIRED PARAMETER MISSING
		}
	}
}
?>