File Manager
Back to List
| Current Directory: ~/
Editing: add_file_progress_student.asp.bak
Full path: C:\ict\ICT\add_file_progress_student.asp.bak
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#include file="chk_permission.asp"--> <!--#include file="inc_cache_control.asp"--> <!--#include file="inc_access_control.asp"--> <!--#include file="chk_login.asp"--> <% '***************************************************************** 'session("tb_name")="student" 'id_stu=request("id_stu") Response.write "nnnn" %> <% '***************************************************************** if session("tb_preview") <> 1 and session("tb_edit")<>1 or session("id_stu1") = id_stu then '���Է��� �����㹰ҹ ��� ����Ңͧ�������ͧ pern=session("username") per="2" tb="thesis" sqlnc="select * from tb_permission where id_staff='"&pern&"' and tb_edit='"&per&"' and tb_name='"&tb&"'" set orsnc=server.createobject("adodb.recordset") orsnc.open sqlnc,conn,1,3 'if not orsnc.eof then %> <html> <meta http-equiv="Content-Type" content="text/html; charset=windows-874"></HEAD> <body> <% id_activity=session("id_activity") id_stufile=session("id_stufile") id_thesis=session("id_thesis") response.write id_activity date_mo=now username=session("username") savefile=session("savefile") doc_name=session("doc_name") 'Dim fs 'set fs=Server.CreateObject("Scripting.FileSystemObject") 'Response.Write(fs.GetExtensionName(server.mappath("fileprogress/"&savefile&"")) sqlcheck="select * from thesis_report_file2 order by id_file" set orscheck=server.createobject("adodb.recordset") orscheck.open sqlcheck,conn,1,3 if not orscheck.eof then orscheck.movelast num=orscheck("id_file") num=num+1 else num=1 end if ''�ջѭ������ͧ���ʡ�� ��䧴� ''...................... chf=id_stufile&""&id_activity&""&num getFileExt = Mid(savefile, InstrRev(savefile, ".") + 1) chf=chf+"."+getfileext dim fs1,p1 set fs1=Server.CreateObject("Scripting.FileSystemObject") p1=fs1.getfilename(savefile) If Len(p1)>50 Then p1=Left(p1,45)+"...." End if 'set fs1=Nothing dim fso set fso=createobject("scripting.filesystemobject") fso.movefile server.mappath("fileprogress/"&savefile&""), server.mappath("fileprogress/"&chf&"") Response.write "bbb"&id_activity response.write (server.mappath("upload/"&chf&"")) '...................... sqlupload="insert into thesis_report_file2(id_activity,id_file,file_name,date_create,id_status,id_stu,doc_name) values('"&id_activity&"','"&num&"','"&chf&"','"&date_mo&"',1,'"&username&"','"&p1&"')" set orsupload = Server.CreateObject("adodb.recordset") response.write sqlupload orsupload.open sqlupload,conn,1,3 'response.write "aaa"&chf ' 'Response.Write("FileExt = " & mySmartUpload.Files("savefile").FileExt & "aaaaa<BR>ccccccccccccccccccccccccccccccccc") %> Upload Complete... <form name="form7" class="form-horizontal" style="padding:10px;" method="post" action="upload_thesis_progress_student_form.asp"> <%'���ʶҹС�����������ǻ������� disable ����ѧ������� enable 'If ors_r("id_status")="0" then 'Response.write id_thesis %> <input type="hidden" name="id" value=<%=id_thesis%>> <input type="hidden" name="id_stu" value=<%=id_stu%>> <input type="hidden" name="id_activity" value=<%=id_activity%>> <!--<input name="submit" type="submit" id="submit" value="submit">--> </form> <!--<input type="submit" name="Del" value="Del"> <meta http-equiv="refresh" content ="0;url=upload_thesis_progress_student_form.asp?id=<%=id%>">--> <script language='javascript'> document.form7.submit(); </script> </body> </html> <% 'else '���Է� 'response.write "<tr><td colspan=3><center>�س������Է����� �س���ѵԹ��" 'response.write "<meta http-equiv=refresh content =4;url=javascript:history.back();>" '���Է� end if '���Է� %>