Qsite.SiteConfig_Master()
%>
<%
dim action,id,dmname
id=request.QueryString("id")
action=request.querystring("action")
dbmname=trim(request("bmname"))
select case action
case "add"
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from lyy_bm",conn,1,3
rs.AddNew
rs("bmname")=dbmname
rs("link")=trim(request("link"))
rs.Update
rs.Close
set rs=nothing
case "edit"
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from lyy_bm where id="&id,conn,1,3
rs("bmname")=dbmname
rs("link")=trim(request("link"))
rs.Update
rs.Close
set rs=nothing
case "del"
conn.execute ("delete from lyy_bm where id="&id)
conn.close
set conn=nothing
response.Redirect "bm.asp"
end select
%>
<html>
<head>
<title>便民服务管理</title>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<link rel="stylesheet" href="style.css" type="text/css">
</head>
<body>
<table width="98%" border="0" align="center" cellpadding="0" cellspacing="1" bgcolor="#799AE1">
<tr>
<td height="20" bgcolor="#799AE1" align="center"><font color="#FFFFFF" style="font-size:14px">便 民 服 务 管 理</font></td>
</tr>
<tr>
<td bgcolor="#FFFFFF"> <br>
<table width="98%" border="0" align="center" cellpadding="1" cellspacing="1" bgcolor="#D6DFF7">
<tr align="center" bgcolor="#FFFFFF" height="20">
<td width="30">编号</td>
<td>网站名称</td>
<td>网址链接</td>
<td>管理操作</td>
</tr>
<%set rs=server.CreateObject("adodb.recordset")
rs.Open "select * from lyy_bm order by id",conn,1,1
dim follows
if rs.EOF and rs.BOF then
response.write"<tr bgcolor=#FFFFFF><td colspan='4'><p align='center'><font color='red'>暂无便民服务!</font></td></tr></table><br>"
follows=0
else
do while not rs.EOF
i=i+1
%>
<form name="form1" method="post" action="?action=edit&id=<%=int(rs("id"))%>">
<tr bgcolor="#FFFFFF" align="center">
<td><%=i%></td>
On Error Resume Next
Set Conn = Server.CreateObject("ADODB.Connection")
Conn.open ConnStr
If Err Then
err.Clear
Set Conn = Nothing
Response.Write "数据库连接出错,请检查连接字串。1"
Response.End
End If
End Sub
On Error Resume Next
Set Conn_C = Server.CreateObject("ADODB.Connection")
Conn_C.open ConnStr
If Err Then
err.Clear
Set Conn_C = Nothing
Response.Write "数据库连接出错,请检查连接字串。2"
Response.End
End If
End Sub
Sub F_Sql()
Dim Q_Post,Q_Get,Q_In,Q_Inf,i
'Q_In = "'|and|exec|insert|select|delete|update|count|*|chr|mid|master|truncate|char|declare"
Q_In = "'|exec|insert|select|delete|update|*|chr|truncate|declare"
Q_Inf = Split(Q_In , "|")
If Request.Form <> "" Then
For Each Q_Post In Request.Form
For i = 0 To Ubound(Q_Inf)
If InStr(LCase(Request.Form(Q_Post)) , Q_Inf(i)) <> 0 Then
Response.Write("请不要在参数中包含非法字符尝试注入")
Response.End()
End If
Next
Next
End If
If Request.QueryString <> "" Then
For Each Q_Get In Request.QueryString
For i = 0 To Ubound(Q_Inf)
If InStr(LCase(Request.QueryString(Q_Get)) , Q_Inf(i)) <> 0 Then
Response.Write("请不要在参数中包含非法字符尝试注入")
Response.End()
End If
Next
Next
End If