File Manager
Back to List
| Current Directory: ~/
Editing: command_add_author.asp.bak
Full path: C:\ict\ICT\command_add_author.asp.bak
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <!--#include file="chk_login.asp"--> <% pern=session("username") per="2" tb="command" sqlnc="select * from tb_permission where id_staff='"&pern&"' and tb_edit='"&per&"' and tb_name='"&tb&"'" set orsnc=server.createobject("adodb.recordset") orsnc.open sqlnc,conn,1,3 if not orsnc.eof then cauthor=request.form("cauthor") response.write cauthor set orscr=server.createobject("adodb.recordset") sqlcr="select * from command_author order by cid_author asc" orscr.open sqlcr,Conn,1,3 a=0 if not orscr.eof then orscr.movelast a=orscr("cid_author") 'do while not orscr.eof a=a+1 'orscr.movenext 'loop else a=1 end if date_mo=now username=session("username") sqldata="insert into command_author(cid_author,username,cauthor,date_mo) values("&a&",'"&username&"','"&cauthor&"','"&date_mo&"')" 'response.write sqldata set orsdata = Server.CreateObject("adodb.recordset") ' sqlcheck="select * from other_lec where firstname='"&firstname&"' and lastname='"&lastname&"'" 'set orscheck=server.createobject("adodb.recordset") 'orscheck.open sqlcheck,conn,1,3 'if orscheck.eof then 'orsdata.open sqldata,conn,1,3 response.write sqldata %> <SCRIPT LANGUAGE="JavaScript"> <% response.write"alert('�ѹ�֡���������º��������');" %> </SCRIPT> <% response.write "<meta http-equiv='refresh' content ='0;url=command_add_author_form.asp'>" else %> <SCRIPT LANGUAGE="JavaScript"> <% response.write"alert('�ѹ�֡���������º��������');" response.write "window.location.href='command_add_author_form.asp';" %> </SCRIPT> <% end if %>