Please never publish a script like that on the w-w-w, it allows an attacker to read arbitrary files from your hard disk (all those that are readable by the web server). (Consider photo=../../../../etc/security/limits.conf for example).
the below script, but it is not working
That's not an error description - in what way is it not working?