File Manager
Back to List
| Current Directory: ~/
Editing: addlet_file.asp
Full path: C:\ict\ICT\addlet_file.asp
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <!--#include file="chk_login.asp"--> <% pern=session("username") if pern<>"" then %> <% idl=session("idl") t2=session("t2") response.write idl&"++" strMessage = Request("msg") '...................... If t2="1" then sqlch="select id_letter,filename from letterin where id_letter='"&idl&"'" Else sqlch="select id_letter,filename2 from letterin where id_letter='"&idl&"'" End if set orsch=server.createobject("adodb.recordset") orsch.open sqlch,conn,1,3 'If orsch.eof then chf=idl+t2+".pdf" idl2=idl+"-"+t2 '�Ӣ������������� If t2="2" Then tc=orsch("filename2") Else tc=orsch("filename") End if if tc=chf then '��á��������ͧ cfile �դ���� 0 dim fs,f set fs=server.createobject("scripting.filesystemobject") 'set f=fs.getfile(server.mappath("command/"&id&".pdf") set f=fs.getfile ("d:\wwwroot\ict\letinup\"&idl2&".pdf") f.delete set f=nothing set fs=nothing end if dim fso cfile="in-"&idl2 set fso=createobject("scripting.filesystemobject") fso.movefile server.mappath("letinup/"&strMessage&""), server.mappath("letinup/"&cfile&".pdf") 'response.write (server.mappath("command/00Final.pdf")) cfile=cfile+".pdf" '...................... date_mo=now username=session("username") 'sqldata="update letterin set filename='"&strMessage&"' where id_letter='"&idl&"'" If t2="1"then sqldata="update letterin set filename='"&cfile&"' where id_letter='"&idl&"'" Else sqldata="update letterin set filename2='"&cfile&"' where id_letter='"&idl&"'" End if response.write sqldata set orsdata=server.createobject("adodb.recordset") orsdata.open sqldata,conn,1,3 response.write "<meta http-equiv='refresh' content ='0;url=detail_letterin.asp?id="&idl&"'>" 'End if 'Response.Redirect ("detail_letterin.asp?id="&id) else %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "window.location.href='indexletterin.asp';" %> --> </SCRIPT> <% end if %>