File Manager
Back to List
| Current Directory: ~/
Editing: add_letter.asp
Full path: C:\ict\ICT\add_letter.asp
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <!--#include file="chk_login.asp"--> <% pern=session("username") per="2" tb="letterin" sqlnc="select * from tb_permission where id_staff='"&pern&"' and tb_edit='"&per&"' and tb_name='"&tb&"'" set orsnc=server.createobject("adodb.recordset") orsnc.open sqlnc,conn,1,3 if not orsnc.eof then %> <% id_typeletin=request.form("id_typeletin") id_letter=request.form("id_letter") id_sent=request.form("id_sent") 'dletter=request.form("dletter") 'mletter=request.form("mletter") 'yletter=request.form("yletter") 'mreceive=request.form("mreceive") 'yreceive=request.form("yreceive") 'dreceive=request.form("dreceive") originletter=request.form("originletter") titleletter=request.form("titleletter") toname=request.form("toname") id_itletter=request.form("id_itletter") directorcommand=request.form("directorcommand") id_categorylet=request.form("id_cate") statusletter="1" dued=request.form("dued") If dued="" Then dued="0" End if 'duey=request.form("duey") 'duemonth=request.form("duemonth") 'duedate=request.form("duedate") date0=request.form("date0") If date0="" Then date0="00000000" End if duedate=left(date0,2) duemonth=mid(date0,4,2) duey=right(date0,4) if duedate=1 then duedate="01" elseif duedate=2 then duedate="02" elseif duedate=3 then duedate="03" elseif duedate=4 then duedate="04" elseif duedate=5 then duedate="05" elseif duedate=6 then duedate="06" elseif duedate=7 then duedate="07" elseif duedate=8 then duedate="08" elseif duedate=9 then duedate="09" end if if duemonth=1 then duemonth="01" elseif duemonth=2 then duemonth="02" elseif duemonth=3 then duemonth="03" elseif duemonth=4 then duemonth="04" elseif duemonth=5 then duemonth="05" elseif duemonth=6 then duemonth="06" elseif duemonth=7 then duemonth="07" elseif duemonth=8 then duemonth="08" elseif duemonth=9 then mduemonth="09" end if date2=request.form("date2") dreceive=left(date2,2) mreceive=mid(date2,4,2) yreceive=right(date2,4) if dreceive=1 then dreceive="01" elseif dreceive=2 then dreceive="02" elseif dreceive=3 then dreceive="03" elseif dreceive=4 then dreceive="04" elseif dreceive=5 then dreceive="05" elseif dreceive=6 then dreceive="06" elseif dreceive=7 then dreceive="07" elseif dreceive=8 then dreceive="08" elseif dreceive=9 then dreceive="09" end if if mreceive=1 then mreceive="01" elseif mreceive=2 then mreceive="02" elseif mreceive=3 then mreceive="03" elseif mreceive=4 then mreceive="04" elseif mreceive=5 then mreceive="05" elseif mreceive=6 then mreceive="06" elseif mreceive=7 then mreceive="07" elseif mreceive=8 then mreceive="08" elseif mreceive=9 then mreceive="09" end If date1=request.form("date1") dletter=left(date1,2) mletter=mid(date1,4,2) yletter=right(date1,4) if fy="" then fy=0 end if if dletter=01 then dletter="1" elseif dletter=02 then dletter="2" elseif dletter=03 then dletter="3" elseif dletter=04 then dletter="4" elseif dletter=05 then dletter="5" elseif dletter=06 then dletter="6" elseif dletter=07 then dletter="7" elseif dletter=08 then dletter="8" elseif dletter=09 then dletter="9" end if if mletter=01 then mletter="1" elseif mletter=02 then mletter="2" elseif mletter=03 then mletter="3" elseif mletter=04 then mletter="4" elseif mletter=05 then mletter="5" elseif mletter=06 then mletter="6" elseif mletter=07 then mletter="7" elseif mletter=08 then mletter="8" elseif mletter=09 then mletter="9" end If dued1=duey&""&duemonth&""&duedate dbreceive=yreceive&""&mreceive&""&dreceive dcreate=now 'y=year(now()) y=2020 y=543+y y2=right(yreceive,2) id=len(id_letter) if id = 1 then preid="000" elseif id=2 then preid="00" elseif id=3 then preid="0" end if id_letter=y2&""&preid&""&id_letter usercreate=session("username") sqldata="insert into letterin(id_letter,id_sent,dletter,mletter,yletter,mreceive,yreceive,dreceive,originletter,titleletter,toname,statusletter,dcreate,usercreate,id_typeletin,hitc,dbreceive,id_itletter,directorcommand,dued,duey,duemonth,duedate,dued1,id_categorylet) values('"&id_letter&"','"&id_sent&"',"&dletter&","&mletter&","&yletter&","&mreceive&","&yreceive&","&dreceive&",'"&originletter&"','"&titleletter&"','"&toname&"','"&statusletter&"','"&dcreate&"','"&usercreate&"',"&id_typeletin&",0,"&dbreceive&",'"&id_itletter&"','"&directorcommand&"','"&dued&"','"&duey&"','"&duemonth&"','"&duedate&"','"&dued1&"','"&id_categorylet&"')" set orsdata=server.createobject("adodb.recordset") sqlcheck="select * from letterin where id_letter='"&id_letter&"'" set orscheck=server.createobject("adodb.recordset") orscheck.open sqlcheck,conn,1,3 if orscheck.eof then orsdata.open sqldata,conn,1,3 response.write sqldata a=request.form("id_staff").count i=1 if a>0 then do while i<=a '-------------- id_staff=request.form("id_staff")(i) sqldata="insert into staffletter(username,id_staff,datecreate,id_level,id_letter,statusread) values('"&usercreate&"','"&id_staff&"','"&dcreate&"',"&i&",'"&id_letter&"','0')" response.write sqldata set orsdata = Server.CreateObject("adodb.recordset") sqlcheck="select * from staffletter where id_staff='"&id_staff&"' and id_letter='"&id&"'" set orscheck=server.createobject("adodb.recordset") orscheck.open sqlcheck,conn,1,3 if orscheck.eof then orsdata.open sqldata,conn,1,3 end if '------------- response.write request.form("id_staff")(i)&" checkbox value<br>" i=i+1 loop end if %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "alert('�ѹ�֡���������º����');" %> </SCRIPT> <% response.write "<meta http-equiv='refresh' content ='0;url=detail_letterin.asp?id="&id_letter&"'>" else %> <SCRIPT LANGUAGE="JavaScript"> <% 'response.write"alert('�ѹ�֡�����ū��++ ��ҹ��ѹ�֡�����Ź�������');" 'response.write "window.location.href='indexletterin.asp';" %> --> </SCRIPT> <% response.write "�����ū�� "&id_letter response.write "<meta http-equiv='refresh' content ='7;url=detail_letterin.asp?id="&id_letter&"'>" end if %><% else %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "window.location.href='index.html';" %> --> </SCRIPT> <% end if %>