File Manager
Back to List
| Current Directory: ~/
Editing: qe_add.asp
Full path: C:\ict\ICT\qe_add.asp
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <!--#include file="chk_login.asp"--> <% pern=session("username") per="2" tb="qe" sqlnc="select * from tb_permission where id_staff='"&pern&"' and tb_edit='"&per&"' and tb_name='"&tb&"'" set orsnc=server.createobject("adodb.recordset") orsnc.open sqlnc,conn,1,3 if not orsnc.eof then qe_year=request.form("qe_year") qe_yearedu=request.form("qe_yearedu") qe_semeter=request.form("qe_semeter") qe_type_test=request.form("qe_type_test") qe_datetime=now qe_course=request.form("qe_course") qe_month=request.form("qe_month") qe_day=request.form("qe_day") qe_status="1" qe_score=request.form("qe_score") if qe_day=1 then qe_day="01" elseif qe_day=2 then qe_day="02" elseif qe_day=3 then qe_day="03" elseif qe_day=4 then qe_day="04" elseif qe_day=5 then qe_day="05" elseif qe_day=6 then qe_day="06" elseif qe_day=7 then qe_day="07" elseif qe_day=8 then qe_day="08" elseif qe_day=9 then qe_day="09" end if if qe_month=1 then qe_month="01" elseif qe_month=2 then qe_month="02" elseif qe_month=3 then qe_month="03" elseif qe_month=4 then qe_month="04" elseif qe_month=5 then qe_month="05" elseif qe_month=6 then qe_month="06" elseif qe_month=7 then qe_month="07" elseif qe_month=8 then qe_month="08" elseif qe_month=9 then qe_month="09" end if qe_date=qe_year+qe_month+qe_day user_add=session("username") year_edu=qe_yearedu+qe_semeter 'sqlch= "select * from qe_schedule where qe_semeter='"&qe_semeter&"' and qe_year='"&qe_year&"'" ' set orsch=server.createobject("adodb.recordset") ' orsch.open sqlch,conn,1,3 ' if orsch.eof then sqlcount= "select * from qe_schedule" set orscount=server.createobject("adodb.recordset") orscount.open sqlcount,conn,1,3 if orscount.eof then id=1 else orscount.movelast id=int(orscount("qe_schedule"))+1 end if response.write "1-" sqldata="insert into qe_schedule(qe_schedule,qe_year_edu,qe_semeter,qe_schedule_status,year_edu) values("&id&",'"&qe_yearedu&"','"&qe_semeter&"',1,'"&year_edu&"')" sqlco="select * from qe " set orsco=server.createobject("adodb.recordset") orsco.open sqlco,conn,1,3 if not orsco.eof then orsco.movelast qe_id=orsco("qe_id")+1 else qe_id=1 end if set orsdata = Server.CreateObject("adodb.recordset") sqlcheck="select * from qe_schedule where qe_semeter='"&qe_semeter&"' and qe_year_edu='"&qe_yearedu&"'" set orscheck=server.createobject("adodb.recordset") orscheck.open sqlcheck,conn,1,3 ' ��Ǩ�ͺ��� �չ���Դ�ͺ������ѧ if orscheck.eof then '�ѧ����ºѹ�֡ � qe_schedule ������ѹ�֡㹵��ҧ QE ���� orsdata.open sqldata,conn,1,3 response.write "2-" sqlqe1="insert into qe (qe_id,qe_num,user_add,qe_datetime,qe_status,qe_day,qe_month,qe_year,qe_date,qe_course,qe_schedule,qe_score) values("&qe_id&",1,'"&user_add&"','"&qe_datetime&"','"&qe_status&"','"&qe_day&"','"&qe_month&"','"&qe_year&"','"&qe_date&"','"&qe_course&"','"&id&"','"&qe_score&"')" set orsqe1=server.createobject("adodb.recordset") orsqe1.open sqlqe1,conn,1,3 response.write sqlqe1&"��3" %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "window.location.href='qe_schedule.asp?id="&qe_semeter&"&id2="&qe_yearedu&"';" %> </SCRIPT> <% else '�ºѹ�֡������� qe_schedule ���� response.write "3-" '�������������� ��Ǩ�ͺ��� 㹡���ͺ���駹�� ������Ԫҹ�������ѧ sqlqec="select * from qe where qe_schedule='"&orscheck("qe_schedule")&"' and qe_course='"&qe_course&"' order by qe_num " set orsqec=server.createobject("adodb.recordset") orsqec.open sqlqec,conn,1,3 if orsqec.eof then '��������� qe �ѧ������ͺ�Ԫҹ�����������С���ͺ��������� sqlqe="insert into qe (qe_id,qe_num,user_add,qe_datetime,qe_status,qe_day,qe_month,qe_year,qe_date,qe_course,qe_schedule,qe_score) values("&qe_id&",1,'"&user_add&"','"&qe_datetime&"','"&qe_status&"','"&qe_day&"','"&qe_month&"','"&qe_year&"','"&qe_date&"','"&qe_course&"','"&orscheck("qe_schedule")&"','"&qe_score&"')" set orsqe=server.createobject("adodb.recordset") orsqe.open sqlqe,conn,1,3 response.write sqlqe&"��2-" else orsqec.movelast qe_num=int(orsqec("qe_num"))+1 sqlqe="insert into qe (qe_id,qe_num,user_add,qe_datetime,qe_status,qe_day,qe_month,qe_year,qe_date,qe_course,qe_schedule,qe_score) values("&qe_id&",'"&qe_num&"','"&user_add&"','"&qe_datetime&"','"&qe_status&"','"&qe_day&"','"&qe_month&"','"&qe_year&"','"&qe_date&"','"&qe_course&"','"&orscheck("qe_schedule")&"','"&qe_score&"')" set orsqe=server.createobject("adodb.recordset") orsqe.open sqlqe,conn,1,3 response.write sqlqe&"��2-" end if response.write sqlqec '����ͧ��������� �դú���� %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "alert('���駷���ͺ�١���ҧ���Ǥ�');" response.write "window.location.href='qe_schedule.asp?id="&qe_semeter&"&id2="&qe_yearedu&"';" %> </SCRIPT> <% ' response.write sqlqe end if response.write "4-" else %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "window.location.href='index.html';" %> --> </SCRIPT> <% response.write "5" end if %>