File Manager
Back to List
|
Up to Parent Directory
| Current Directory: ~/univForm
Editing: univForm/add.asp.bak
Full path: C:\ict\ICT\univForm\add.asp.bak
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <% q1=request.form("q1") q2=request.form("q2") q3=request.form("q3") q4=request.form("q4") q5=request.form("q5") q6=request.form("q6") q7=request.form("q7") q8=request.form("q8") q9=request.form("q9") q10=request.form("q10") q11=request.form("q11") q12=request.form("q12") q13=request.form("q13") q14=request.form("q14") q15=request.form("q15") q16=request.form("q16") q17=request.form("q17") q18=request.form("q18") q19=request.form("q19") q20=request.form("q20") q21=request.form("q21") sex1=request.form("sex") year1=request.form("year1") faculty=request.form("faculty") emaill=request.form("emaill") univ=request.form("univ") uo=request.form("uo") fo=request.form("fo") datemo=now sqlcheck="select * from euniv order by id" set orscheck=server.createobject("adodb.recordset") orscheck.open sqlcheck,conn,1,3 If orscheck.eof Then id=1 Else orscheck.movelast id=orscheck("id")+1 session("ide")=id End if sqldata="insert into elderly(id,q1,q2,q3,q4,q5,q6,q7,q8,q9,q10,q11,q12,q13,q14,q15,q16,q17,q18,q19,q20,q21,datemo,sex1,year1,faculty,emaill,univ,fo,uo) values("&id&",'"&q1&"','"&q2&"','"&q3&"','"&q4&"','"&q5&"','"&q6&"','"&q7&"','"&q8&"','"&q9&"','"&q10&"','"&q11&"','"&q12&"','"&q13&"','"&q14&"','"&q15&"','"&q16&"','"&q17&"','"&q18&"','"&q19&"','"&q20&"','"&q21&"','"&datemo&"','"&sex1&"','"&year1&"','"&faculty&"','"&emaill&"','"&univ&"','"&fo&"','"&uo&"')" set orsdata=server.createobject("adodb.recordset") 'if orscheck.eof then orsdata.open sqldata,conn,1,3 'response.write sqldata 'Response.write "<br>5555"&q22 'a=request.form("id_staff").count 'i=1 'if a>0 then 'do while i<=a '-------------- ' id_staff=request.form("id_staff")(i) 'sqldata="insert into staffletter(username,id_staff,datecreate,id_level,id_letter,statusread) values('"&usercreate&"','"&id_staff&"','"&dcreate&"',"&i&",'"&id_letter&"','0')" ' response.write sqldata ' set orsdata = Server.CreateObject("adodb.recordset") ' sqlcheck="select * from staffletter where id_staff='"&id_staff&"' and id_letter='"&id&"'" ' set orscheck=server.createobject("adodb.recordset") ' orscheck.open sqlcheck,conn,1,3 ' if orscheck.eof then ' orsdata.open sqldata,conn,1,3 ' end if '------------- 'response.write request.form("id_staff")(i)&" checkbox value<br>" 'i=i+1 'loop 'end if %> <SCRIPT LANGUAGE="JavaScript"> <% 'response.write "alert('�ѹ�֡���������º����');" %> </SCRIPT> <% response.write "<meta http-equiv='refresh' content ='0;url=detail.asp'>" 'else %> <SCRIPT LANGUAGE="JavaScript"> <% 'response.write"alert('�ѹ�֡�����ū��++ ��ҹ��ѹ�֡�����Ź�������');" 'response.write "window.location.href='indexletterin.asp';" %> --> </SCRIPT> <% 'response.write "�����ū�� "&id_letter 'response.write "<meta http-equiv='refresh' content ='7;url=detail_letterin.asp?id="&id_letter&"'>" 'end if %><% 'else %> <SCRIPT LANGUAGE="JavaScript"> <% ' response.write "window.location.href='index.html';" %> --> </SCRIPT>