File Manager
Back to List
| Current Directory: ~/
Editing: add_num_term_res.asp.bak
Full path: C:\ict\ICT\add_num_term_res.asp.bak
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <!--#include file="chk_login.asp"--> <% pern=session("username") per="2" tb="research" sqlnc="select * from tb_permission where id_staff='"&pern&"' and tb_edit='"&per&"' and tb_name='"&tb&"'" set orsnc=server.createobject("adodb.recordset") orsnc.open sqlnc,conn,1,3 if not orsnc.eof then id=request.form("id") num_term=request.form("num_term") d_fcontact=request.form("d_fcontact") m_fcontact=request.form("m_fcontact") y_fcontact=request.form("y_fcontact") d_real=request.form("d_real") m_real=request.form("m_real") y_real=request.form("y_real") amount=request.form("amount") date_mo=now username=session("username") sqlall="select * from numterm_res" set orsall=server.createobject("adodb.recordset") orsall.open sqlall,conn,1,3 'response.write sqlall 'if not orsall.eof then 'orsall.movelast 'num_res=orsall("id_num") 'response.write num_res 'num_res=num_res+1 'num_res=cint(orsall("id_num"))+1 'else 'num_res=1 'end if sqldata="insert into numterm_res(username,date_mo,id_contact,no_amount,d_fcontact,m_fcontact,y_fcontact,d_real,m_real,y_real,amount) values('"&username&"','"&date_mo&"','"&id&"','"&num_term&"','"&d_fcontact&"','"&m_fcontact&"','"&y_fcontact&"','"&d_real&"','"&m_real&"','"&y_real&"','"&amount&"')" response.write sqldata set orsdata = Server.CreateObject("adodb.recordset") sqlcheck="select * from numterm_res where id_contact='"&id&"' and no_amount='"&num_term&"'" set orscheck=server.createobject("adodb.recordset") orscheck.open sqlcheck,conn,1,3 if orscheck.eof then 'orsdata.open sqldata,conn,1,3 'response.write sqldata %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "alert('�ѹ�֡�����Ź�����º��������');" response.write "window.location.href='num_term_res_form.asp?id="&id&"';" %> --> </SCRIPT> <% else %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "alert('�ѹ�֡�����ū��++ ��ҹ��ѹ�֡�����Ź�������');" response.write "window.location.href='num_term_res_form.asp?id="&id&"';" %> --> </SCRIPT> <% end if %> <% else %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "window.location.href='index.html';" %> --> </SCRIPT> <% end if %>