File Manager
Back to List
| Current Directory: ~/
Editing: all_letterin.asp.bak
Full path: C:\ict\ICT\all_letterin.asp.bak
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<%response.cachecontrol="private"%> <!--#INCLUDE FILE="ConnectDB.asp"--> <!--#include file="chk_login.asp"--> <% pern=session("username") per="2" tb="letterin" sqlnc="select * from tb_permission where id_staff='"&pern&"' and tb_edit='"&per&"' and tb_name='"&tb&"'" set orsnc=server.createobject("adodb.recordset") orsnc.open sqlnc,conn,1,3 'if not orsnc.eof then %> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html><!-- InstanceBegin template="/Templates/ICT.dwt" codeOutsideHTMLIsLocked="false" --> <head> <!-- InstanceBeginEditable name="doctitle" --> <title>�к����ʹ�����͡�ú�����</title> <!-- InstanceEndEditable --> <meta http-equiv="Content-Type" content="text/html; charset=windows-874"> <!-- InstanceBeginEditable name="head" --> <style type="text/css"> <!-- .style1 {color: #ccff33} --> </style> <!-- InstanceEndEditable --> <link href="bsri2006.css" rel="stylesheet" type="text/css"> <link href="image/favicon.ico" rel="shortcut icon" type="image/x-icon"> </head> <body leftmargin="0" topmargin="0" marginwidth="0" marginheight="0"> <table width="100%" border="0"> <tr> <td colspan="2"><div align="right"><img src="Image/head1.gif" width="800" height="61"></div></td> </tr> <tr> <td colspan="2" background="Image/bghead1.gif"><div align="right"><font size="2" face="MS Sans Serif, Tahoma, sans-serif"><strong>| <a href="http://www.swu.ac.th" target=_blank>SWU</a> | <a href="http://bsri.swu.ac.th" target=_blank>BSRI</a> |<a href="chaPW.asp"><strong>Change Password</strong></a>|<a href="log_out.asp">Log Out </a></strong></font>|</div></td> </tr> <tr> <td width="20%" align="left" valign="top" bgcolor="#FFCCCC"><!-- InstanceBeginEditable name="EditRegion5" --><!--#include file="chk_menu.asp"--><!-- InstanceEndEditable --></td> <td width="77%" align="left" valign="top"><!-- InstanceBeginEditable name="EditRegion3" --> <div align="center"> <p><strong>˹ѧ������ʶҺѹ�Ԩ�¾ĵԡ�����ʵ��<br> <% if not orsnc.eof then response.write "[<a href=indexletterin.asp>����˹ѧ������</a>]" end if%> [<a href="all_letterin.asp">˹ѧ��ͷ�����</a>][<a href="searchletter.asp">����˹ѧ���</a>][<a href="letterin_staff.asp">˹ѧ��������ºؤ��</a>][<a href="letterin_dued.asp">˹ѧ�������ա�˹���</a>]</strong></p> <p> <% ' �֧�����Ũҡ�ҹ������ yletter=year(now)+543 'Response.write yletter set rs=server.createobject("adodb.recordset") 'sql = "Select * From letterin where id_typeletin=3 Order By dbreceive Desc" 'sql = "Select * From letterin where statusletter=1 Order By dbreceive asc" sql = "Select * From letterin where statusletter=1 and yletter='"&yletter&"' Order By id_letter desc" 'sql = "Select * From letterin where statusletter=1 Order By yreceive desc, id_letter Desc" rs.Open sql, conn, 1, 3 ' �ӡ����˹�� pageno = 1 If Request.QueryString("pageno") <> "" Then pageno = Request.QueryString("pageno") End If On Error Resume Next rs.pagesize=25 totalpage = rs.PageCount If pageno < 1 or Cint(pageno) > Cint(totalpage) Then pageno = 1 End if rs.AbsolutePage = pageno %> <table width="100%" border="0" cellspacing="0" cellpadding="0"> <br> </p> <tr> <td bgcolor="#669900"><div align="center" class="style1">�Ţ�ӴѺ˹ѧ����Ѻ</div></td> <td bgcolor="#669900"><div align="center" class="style1">�Ţ���</div></td> <td bgcolor="#669900"><div align="center" class="style1">ŧ�ѹ���</div></td> <td bgcolor="#669900"><div align="center" class="style1">�ҡ</div></td> <td bgcolor="#669900"><div align="center" class="style1">�֧</div></td> <td bgcolor="#669900"><div align="center" class="style1" >����ͧ</div></td> <!-- <td bgcolor="#669900"><div align="center" class="style1">ʶҹ�</div></td>--> <!-- <td bgcolor="#669900"><div align="center" class="style1">��觷�����Ҵ���</div></td> --> <td bgcolor="#669900" width="15%"><div align="center" class="style1" >���������Ǣ�ͧ</div></td> </tr> <% i=1 ' �ӡ���ʴ��� For a=1 to rs.PageSize If rs.EOF Then Exit For ' Response.Write rs("id_letter")&"<br>" ii=i mod 2 if ii=0 then bgc="#ccffcc" else bgc="#ffffff" end if %> <tr bgcolor=<%=bgc%> > <%response.write "<td>" response.write "[<a href=detail_letterin.asp?id="&rs("id_letter")&">"&rs("id_letter")&"</a>]</td>" %> <td> <% i=i+1 response.write rs("id_sent")&"</td>" response.write "<td>" response.write rs("dletter")&"/"&rs("mletter")&"/"&rs("yletter")&"[˹ѧ���]<br>" response.write rs("dreceive")&"/"&rs("mreceive")&"/"&rs("yreceive")&"[�Ѻ]</td>" response.write "<td>" response.write rs("originletter")&"</td>" filename=rs("filename") filename2=rs("filename2") response.write "<td>" response.write rs("toname") response.write "<td>" response.write rs("titleletter") If rs("filename")="" Or IsNull(filename) Then 'Response.write "bb" else response.write "<br>[<a href=countletin.asp?id="&rs("id_letter")&"&t2=1 target=_blank>"&rs("filename")&"</a>][��:"&rs("hitc")&" ����]" ' response.write "<br>[<a href=countletin.asp?id="&rs("id_letter")&"&t2=1 target=_blank>File1</a>][��:"&rs("hitc")&" ����]" End If If rs("filename2")="" Or IsNull(filename2) Then else response.write "<br>[<a href=countletin.asp?id="&rs("id_letter")&"&t2=2 target=_blank>"&rs("filename2")&"</a>]</td>" ' response.write "<br>[<a href=countletin.asp?id="&rs("id_letter")&"&t2=2 target=_blank>File2"&rs("filename2")&"</a>]</td>" End if response.write "</td>" 'response.write rs("statusletter")&"</td>" idl=rs("id_letter") ' response.write "<td>" 'set ors=server.createobject("adodb.recordset") 'osql = "Select * From attachletter where id_letter='"&idl&"' Order By attach_name Desc" 'ors.Open osql, conn, 1, 3 'response.write osql 'if not ors.eof then 'ors.movefirst 'do while not ors.eof 'response.write "-"&ors("attach_name")&"<br>" 'response.write "<br>aa" ' ors.MoveNext ' loop ' end if ' response.write "</td>" response.write "<td>" set ors1=server.CreateObject("adodb.recordset") osql1 = "Select * From staffletter where id_letter='"&idl&"' Order By id_staff Desc" ors1.Open osql1, conn, 1, 3 'response.write osql1 b=2 c=0 if not ors1.eof then ors1.movefirst do while not ors1.eof idaaa=ors1("id_letter") c=c+1 sqls="select * from lecturer where id_lecturer='"&ors1("id_staff")&"'" set orss=server.createobject("adodb.recordset") orss.open sqls,conn,1,3 if statusread=0 then response.write "<img src=Image/close.gif />" else response.write "<img src=Image/open.gif />" end if if not orss.eof then response.write orss("name_lec")&" "&orss("sur_lec")&"<br>" else sqlst="select * from staff where id_staff='"&ors1("id_staff")&"'" set orsst=server.createobject("adodb.recordset") orsst.open sqlst,conn,1,3 if not orsst.eof then response.write orsst("name_st")&" "&orsst("sur_st")&"<br>" end if end if statusread=ors1("statusread") ors1.MoveNext if c=2 then '����ʴ������ 2 ���� ����Թ ���͡ response.write "[<a href=detail_letterin.asp?id="&rs("id_letter")&">more..</a>]" exit do end if loop end if response.write "</td>" response.write "</tr>" 'Response.write "<tr><td bgcolor=#ffccff>"&rs("dued1") If rs("dued1")>0 then Response.write "<tr><td bgcolor=#ffccff>��˹��� <td bgcolor=#ffccff>"&rs("duedate")&"/"&rs("duemonth")&"/"&rs("duey")&"</td>" %> <td colspan="5" bgcolor="#ffccff" valign="top"><%=rs("dued_detail")%> <input type="hidden" name="id" value=<%=rs("id_letter")%>> <% End if rs.MoveNext Next response.write "</table>" ' �ӡ���ʴ��Ţ˹�� If pageno <> 1 and pageno <> 2 Then Response.Write "[<a href='all_letterin.asp'>˹���á</a>] " End If if pageno <> 1 Then Response.Write "[<a href='all_letterin.asp?pageno="&pageno-1&"'>��˹��</a>] " End if For b =1 To totalpage If b = Cint(pageno) Then Response.Write "<b> ["&b&"] </b>" Else Response.Write "<a href='all_letterin.asp?pageno="&b&"'>"&b&"</a>" End If If b <> totalpage Then Response.Write " | " End If Next If Cint(pageno) <> totalpage Then Response.Write " [<a href='all_letterin.asp?pageno="&pageno+1&"'>�Ѵ�</a>]" End If If Cint(pageno) <> totalpage Then Response.Write " [<a href='all_letterin.asp?pageno="&totalpage&"'>˹���ش����</a>]" End If %> </p> <p></p> <p></p> </div> <!-- InstanceEndEditable --></td> </tr> <tr> <td colspan="2" background="Image/bghead1.gif">Contact Admin:: wassanaw@swu.ac.th tel.02-649-5000 ext 17600</td> </tr> </table> </body> <!-- InstanceEnd --></html> <% 'else 'response.write "No Permission" 'response.write "<a href=index_academic.asp>Return</a>" 'end if %>