📄 checkuser.asp
字号:
<%@ LANGUAGE = VBScript.Encode %>
<%
dim sq
sq="'|exec|=|>|<|;|insert|select|delete|update|count|*|&|chr|mid|master|truncate|char|declare"
SQL_inj = split(sq,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.QueryString(SQL_Get),Sql_Inj(Sql_DATA))>0 Then
%>
<Script Language=JavaScript>
alert('您的输入含有非法字符!');
history.back(-1)
</Script>
<%
Response.end
end if
next
Next
End If
If Request.Form<>"" Then
For Each Sql_Post In Request.Form
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.Form(Sql_Post),Sql_Inj(Sql_DATA))>0 Then
%>
<Script Language=JavaScript>
alert('输入含有非法字符!');
history.back(-1)
</Script>
<%
Response.end
end if
next
next
end if
%>
<!-- #include file="include/adovbs.inc" -->
<!-- #include file="include/dataconn.asp" -->
<!-- #include file="CalcCount.asp" -->
<%
name = trim(request("txtname"))
password = trim(request("txtpassword"))
if instr(name,"'")>0 then
%>
<SCRIPT language=JavaScript>alert('您的输入含有非法字符。');
<%
response.write"location.href='default.asp'</SCRIPT>"
response.End
end if
if instr(password,"'")>0 then
%>
<SCRIPT language=JavaScript>alert('您的输入含有非法字符。');
<%
response.write"location.href='default.asp'</SCRIPT>"
response.End
end if
verifycode=trim(Request.Form("verifycode"))
verifycode2=trim(Request.Form("verifycode2"))
if verifycode<>verifycode2 then
%>
<SCRIPT language=JavaScript>alert('您输入的验证码不正确。');
<%
response.write"location.href='gl.asp'</SCRIPT>"
else
session("verifycode")=""
set rs = server.CreateObject("adodb.recordset")
sql = "select * from adminuser where username = '" & name & "' and password = '" & password & "'"
'Response.Write sql
'Response.End
rs.Open sql,conn
'Response.Write rs.RecordCount
'Response.End
if rs.RecordCount >0 then
session("UserName") = rs("UserName")
set paramrs = server.CreateObject("adodb.recordset")
sql = "select * from Setting_other"
paramrs.Open sql,conn
if paramrs.RecordCount >0 then
while not paramrs.eof
FuncName=paramrs("FuncName")
session(FuncName)=paramrs("FuncValue")
paramrs.movenext
wend
end if
Response.Redirect "main.htm"
else%>
<script language="javascript">
alert("◆≡≡≡系 统 提 示≡≡≡◆\n\n用户或者密码错误,请检查!");
history.back();
</script>
<%
'Response.Redirect "gl.htm"
end if
end if
%>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -