28,406
社区成员
发帖
与我相关
我的任务
分享
<table border="0" align="center" cellpadding="0" cellspacing="0" class="l">
<!--DWLayoutTable-->
<tr>
<td align="center" valign="middle"><IMG src="../img.asp?src=<%=M("pic")%>" border=0 style="cursor:pointer;" onClick="zoom(this,'../img.asp?src=<%=M("pic")%>')" onload ='DrawImage(this)' /></td>
</tr>
<tr>
<td align="center" valign="middle"><a href="del.asp?id=<%=M("id")%>">ID:<%=M("id")%></a></td>
</tr>
</table>
<%@language=vbscript%>
<%if not session("checked")="yes" then
response.Redirect "login.asp"
else
%>
<%
Set conn = Server.CreateObject("ADODB.Connection")
connstr="Provider=SQLOLEDB;Data Source=(local);Initial Catalog=cristic;User ID=sa;Password=sa;"
conn.Open connstr
%>
<%
exec="delete from guest where id="&request.querystring("id")
conn.execute(exec)
conn.close
set conn=nothing
Response.Write("<script language=javascript>alert('恭喜您,删除成功!')</script>")
Response.Write("<script language=javascript>window.location.href='right.asp'</script>")
%>
<%end if%>
<%
'set conn=server.createobject("adodb.connection")
'conn.open "driver={microsoft access driver (*.mdb)};dbq="&server.mappath("../up/data/photo.mdb")
Set conn = Server.CreateObject("ADODB.Connection")
connstr="Provider=SQLOLEDB;Data Source=(local);Initial Catalog=金点子管理系统数据库;User ID=sa;Password=sa;"
conn.Open connstr
%>
<%
id=request.querystring("id")
set tmp=server.CreateObject("adodb.recordset")
tmp.open "select pic from guest where id='"&id&"'",conn
if not tmp.eof then
purl=tmp("pic")
FilePath=Server.MapPath("../up/upload/"& purl)
Dim fso
Set fso = CreateObject("Scripting.FileSystemObject")
IF fso.FileExists(FilePath) Then
fso.DeleteFile(FilePath)
End IF
Set fso = Nothing
end if
exec="delete from guest where id="&id
conn.execute(exec)
conn.close
set conn=nothing
Response.Write("<script language=javascript>alert('删除成功!')</script>")
Response.Write("<script language=javascript>window.location.href='right.asp'</script>")
%>
<%
session.CodePage=936
Response.Charset="gb2312"
SQL_injdata = "'|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
SQL_inj = split(SQL_Injdata,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.QueryString(SQL_Get),Sql_Inj(Sql_DATA))>0 Then
Response.Write "<Script Language=JavaScript>alert('请勿提交非法数据!');history.back(-1)</Script>"
Response.end
end if
next
Next
End If
If Request.Form<>"" Then
For Each Sql_Post In Request.Form
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.Form(Sql_Post),Sql_Inj(Sql_DATA))>0 Then
Response.Write "<Script Language=JavaScript>alert('请勿提交非法数据!');history.back(-1)</Script>"
Response.end
end if
next
next
end if
On Error Resume Next
dim conn
dim connstr
dim db
Set conn = Server.CreateObject("ADODB.Connection")
connstr="Provider=SQLOLEDB;Data Source=(local);Initial Catalog=金点子管理系统数据库;User ID=sa;Password=sa;"
conn.Open connstr
If Err Then
err.Clear
Set Conn = Nothing
Response.Write "fuck!"
Response.End
End If
%>
<%
id=request.querystring("id")
'***********************************************
'函数名:DeleteFile
'作 用:删除文件
'参 数:file ----文件路径
'***********************************************
Function DeleteFile(str)
dim fso
Set fso = CreateObject("scripting.filesystemobject")
if fso.FileExists(server.MapPath("../up/upload/"&str)) = true then
fso.DeleteFile server.MapPath("../up/upload/"&str)
end if
Set fso = nothing
End Function
set sql=server.CreateObject("adodb.recordset")
sql = "select * from guest where id = "&id&""
rs.open sql,conn,1,3
DeleteFile(rs("pic"))
rs.delete
rs.close
Response.Write("<script language=javascript>alert('恭喜您,删除成功!')</script>")
Response.Write("<script language=javascript>window.location.href='right.asp'</script>")
%>
'***********************************************
'函数名:DeleteFile
'作 用:删除文件
'参 数:file ----文件路径
'***********************************************
Function DeleteFile(str)
dim fso
Set fso = CreateObject("scripting.filesystemobject")
if fso.FileExists(server.MapPath(str)) = true then
fso.DeleteFile server.MapPath(str)
end if
Set fso = nothing
End Function
sql = "select * from guest where id = "&id&""
rs.open sql,conn,1,3
DeleteFile(rs("pic"))
rs.delete
rs.close
Response.Write("<script language=javascript>alert('恭喜您,删除成功!')</script>")
Response.Write("<script language=javascript>window.location.href='right.asp'</script>")