File Manager
Back to List
| Current Directory: ~/
Editing: add_attachname.asp.bak
Full path: C:\ict\ICT\add_attachname.asp.bak
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <!--#include file="chk_login.asp"--> <% pern=session("username") per="2" tb="letterin" sqlnc="select * from tb_permission where id_staff='"&pern&"' and tb_edit='"&per&"' and tb_name='"&tb&"'" set orsnc=server.createobject("adodb.recordset") orsnc.open sqlnc,conn,1,3 if not orsnc.eof then %> <% id_letter=session("id_l") attach_name=request.form("attach_name") statusletter="1" dcreate=now usercreate=session("username") sqldata="insert into attachletter(id_letter,attach_name) values('"&id_letter&"','"&attach_name&"')" set orsdata=server.createobject("adodb.recordset") 'sqlcheck="select * from attachletter where id_letter='"&id_letter&"'" 'set orscheck=server.createobject("adodb.recordset") 'orscheck.open sqlcheck,conn,1,3 'if orscheck.eof then orsdata.open sqldata,conn,1,3 response.write sqldata %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "alert('�ѹ�֡���������º����');" %> </SCRIPT> <% response.write "<meta http-equiv='refresh' content ='0;url=detail_letterin.asp?id="&id_letter&"'>" 'else %> <SCRIPT LANGUAGE="JavaScript"> <% 'response.write"alert('�ѹ�֡�����ū��++ ��ҹ��ѹ�֡�����Ź�������');" 'response.write "window.location.href='indexletterin.asp';" %> --> </SCRIPT> <% 'response.write "�����ū�� " 'response.write "<meta http-equiv='refresh' content ='7;url=index.asp'>" 'end if %><% else %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "window.location.href='index.html';" %> --> </SCRIPT> <% end if %>