File Manager
Back to List
|
Up to Parent Directory
| Current Directory: ~/ehealthy
Editing: ehealthy/add.asp.bak
Full path: C:\ict\ICT\ehealthy\add.asp.bak
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <% name=request.form("name") team=request.form("team") weights=request.form("weight") eights=request.form("height") bloodt=request.form("bloodt") bloodb=request.form("bloodb") emaill=request.form("emaill") sex=request.form("sex") status=request.form("status") status_o=request.form("status_o") province=request.form("province") age=request.form("age") edu=request.form("edu") duty=request.form("duty") duty_o=request.form("duty_o") income1=request.form("income") commu=request.form("commu") commu_o=request.form("commu_o") ncd1=request.form("ncd1") ncd2=request.form("ncd2") ncd3=request.form("ncd3") ncd4=request.form("ncd4") ncd5=request.form("ncd5") ncd6=request.form("ncd6") ncd7=request.form("ncd7") ncd8=request.form("ncd8") ncd9=request.form("ncd9") ncd10=request.form("ncd10") ncd11=request.form("ncd11") ncd12=request.form("ncd12") ncd13=request.form("ncd13") ncd_o=request.form("ncd_o") province=request.form("province") prov_o=request.form("prov_o") author=request.form("author") 'author=request("id") If author="" Then author="0" End if datemo=now sqlcheck="select * from ehealth order by id" set orscheck=server.createobject("adodb.recordset") orscheck.open sqlcheck,conn,1,3 If orscheck.eof Then id=1 Else orscheck.movelast id=orscheck("id")+1 session("ide")=id End If 'Response.write heights sqldata="insert into ehealth(id,ncd1,ncd2,ncd3,ncd4,ncd5,ncd6,ncd7,ncd8,ncd9,ncd10,ncd11,ncd12,sex,status,status_o,age,edu,duty,duty_o,income1,commu,commu_o,datemo,ncd_o,province,prov_o,emaill,author,name,team,weight,bloodt,bloodb,height) values("&id&",'"&ncd1&"','"&ncd2&"','"&ncd3&"','"&ncd4&"','"&ncd5&"','"&ncd6&"','"&ncd7&"','"&ncd8&"','"&ncd9&"','"&ncd10&"','"&ncd11&"','"&ncd12&"','"&sex&"','"&status&"','"&status_o&"','"&age&"','"&edu&"','"&duty&"','"&duty_o&"','"&income1&"','"&commu&"','"&commu_o&"','"&datemo&"','"&ncd_o&"','"&province&"','"&prov_o&"','"&emaill&"','"&author&"','"&name&"','"&team&"','"&weights&"','"&bloodt&"','"&bloodb&"','"&eights&"')" set orsdata=server.createobject("adodb.recordset") 'if orscheck.eof then ,'"&heights&"' orsdata.open sqldata,conn,1,3 'response.write sqldata 'Response.write "<br>5555"&q22 'a=request.form("id_staff").count 'i=1 'if a>0 then 'do while i<=a '-------------- ' id_staff=request.form("id_staff")(i) 'sqldata="insert into staffletter(username,id_staff,datecreate,id_level,id_letter,statusread) values('"&usercreate&"','"&id_staff&"','"&dcreate&"',"&i&",'"&id_letter&"','0')" ' response.write sqldata ' set orsdata = Server.CreateObject("adodb.recordset") ' sqlcheck="select * from staffletter where id_staff='"&id_staff&"' and id_letter='"&id&"'" ' set orscheck=server.createobject("adodb.recordset") ' orscheck.open sqlcheck,conn,1,3 ' if orscheck.eof then ' orsdata.open sqldata,conn,1,3 ' end if '------------- 'response.write request.form("id_staff")(i)&" checkbox value<br>" 'i=i+1 'loop 'end if %> <SCRIPT LANGUAGE="JavaScript"> <% 'response.write "alert('�ѹ�֡���������º����');" %> </SCRIPT> <% 'response.write "<meta http-equiv='refresh' content ='0;url=section2.asp'>" 'else %> <form action="section2.asp" method="post" name="form1"> <input type="hidden" name="id" value=<%=id%>> <script type="text/javascript"> document.form1.submit(); </script> </form> <SCRIPT LANGUAGE="JavaScript"> <% 'response.write"alert('�ѹ�֡�����ū��++ ��ҹ��ѹ�֡�����Ź�������');" 'response.write "window.location.href='indexletterin.asp';" %> --> </SCRIPT> <% 'response.write "�����ū�� "&id_letter 'response.write "<meta http-equiv='refresh' content ='7;url=detail_letterin.asp?id="&id_letter&"'>" 'end if %><% 'else %> <SCRIPT LANGUAGE="JavaScript"> <% ' response.write "window.location.href='index.html';" %> --> </SCRIPT>