File Manager
Back to List
| Current Directory: ~/
Editing: save_num_term_res.asp
Full path: C:\ict\ICT\save_num_term_res.asp
Permissions: rwx
Write test: File appears not directly writable
Current process identity: IIS APPPOOL\DefaultAppPool
<!--#INCLUDE FILE="ConnectDB.asp"--> <!--#include file="chk_login.asp"--> <% pern=session("username") per="2" tb="research" sqlnc="select * from tb_permission where id_staff='"&pern&"' and tb_edit='"&per&"' and tb_name='"&tb&"'" set orsnc=server.createobject("adodb.recordset") orsnc.open sqlnc,conn,1,3 if not orsnc.eof then %> <% id=request.form("id") num_term=request.form("num_term") d_fcontact=request.form("d_fcontact") m_fcontact=request.form("m_fcontact") y_fcontact=request.form("y_fcontact") d_real=request.form("d_real") m_real=request.form("m_real") y_real=request.form("y_real") amount=request.form("amount") id_num=request.form("id_num") date_mo=now username=session("username") sqlall="select * from numterm_res where id_contact='"&id&"' and no_amount='"&num_term&"'" set orsall=server.createobject("adodb.recordset") orsall.open sqlall,conn,1,3 if not orsall.eof then 'orsall.movelast 'id_num=orsall("id_num") 'num_res=orsall("num_res")+1 'else 'id_num="1" end if 'sqldata="insert into numterm_res(username,date_mo,id_contact,no_amount,d_fcontact,m_fcontact,y_fcontact,d_real,m_real,y_real,amount) values('"&username&"','"&date_mo&"','"&id&"','"&num_term&"','"&d_fcontact&"','"&m_fcontact&"','"&y_fcontact&"','"&d_real&"','"&m_real&"','"&y_real&"','"&amount&"')" sqldata="update numterm_res set amount='"&amount&"',d_fcontact='"&d_fcontact&"', m_fcontact='"&m_fcontact&"',y_fcontact='"&y_fcontact&"',d_real='"&d_real&"',m_real='"&m_real&"',y_real='"&y_real&"',no_amount='"&num_term&"' where id_num='"&id_num&"' and id_contact='"&id&"'" 'response.write sqldata&"<br>" set orsdata = Server.CreateObject("adodb.recordset") 'sqlcheck="select * from numterm_res where id_contact='"&id&"' and no_amount='"&num_term&"' and id_num='"&id_num&"'" 'set orscheck=server.createobject("adodb.recordset") 'orscheck.open sqlcheck,conn,1,3 ' response.write sqlcheck&"<br>" 'if orscheck.eof then orsdata.open sqldata,conn,1,3 'response.write sqldata&"<br>" %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "alert('�ѹ�֡�����Ź�����º��������');" response.write "window.location.href='num_term_res_form.asp?id="&id&"';" %> --> </SCRIPT> <% 'else %> <SCRIPT LANGUAGE="JavaScript"> <% 'response.write "alert('�ѹ�֡�����ū��++ ��ҹ��ѹ�֡�����Ź�������');" 'response.write "window.location.href='num_term_res_form.asp?id="&id&"';" %> --> </SCRIPT> <% ''response.write "�����ū�� " 'end if %> <% else %> <SCRIPT LANGUAGE="JavaScript"> <% response.write "window.location.href='index.html';" %> --> </SCRIPT> <% end if %>