replace
string query = "insert into diaryDB(Title , Description , Date , pic) values (@name , @description ,@date , @p)";
SqlCommand comm = new SqlCommand(query, con);
SqlParameter p1 = new SqlParameter("Title", name);
SqlParameter p2 = new SqlParameter("Description", description);
SqlParameter p3 = new SqlParameter("Date", date);
SqlParameter p4 = new SqlParameter("pic", p);
comm.Parameters.Add(p1);
comm.Parameters.Add(p2);
comm.Parameters.Add(p3);
comm.Parameters.Add(p4)
with
string query = "insert into diaryDB([Title] , [Description] , [Date] , pic) values (@name , @description ,@date , @p)";
SqlCommand comm = new SqlCommand(query, con);
comm.Parameters.AddWithValue("@name", name);
comm.Parameters.AddWithValue("@description", description);
comm.Parameters.AddWithValue("@date", DateTime.Now.ToString("dd/MM/YYYY"));
comm.Parameters.AddWithValue("@p", p);