⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 dingdan.asp

📁 易和阳光购物商城 v1.3 | 功能简介 增加了防注入文件
💻 ASP
📖 第 1 页 / 共 2 页
字号:
<!--#include file="Include/Iheeo_Conn.asp"-->
<!--#include file="Include/Iheeo_config.asp"-->
<%if request.Cookies("bjx")("username")="" then
response.write "<script language=javascript>alert('对不起,您还没有登陆!');history.go(-1);</script>"
response.End
end if%>
<html><head><title><%=webname%>--订单详细资料</title>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<link href="images/css.css" rel="stylesheet" type="text/css">
<body leftmargin="0" rightmargin="0" topmargin="0" marginwidth="0" marginheight="0">
<%dim dingdan
dingdan=request.QueryString("dan")
set rs=server.CreateObject("adodb.recordset")
rs.open "select BJX_goods.bookid,BJX_goods.shjiaid,BJX_goods.bookname,BJX_goods.shichangjia,BJX_goods.huiyuanjia,bjx_action.actiondate,bjx_action.shousex,bjx_action.danjia,bjx_action.feiyong,bjx_action.fapiao,bjx_action.userzhenshiname,bjx_action.shouhuoname,bjx_action.dingdan,bjx_action.youbian,bjx_action.liuyan,bjx_action.zhifufangshi,bjx_action.songhuofangshi,bjx_action.zhuangtai,bjx_action.zonger,bjx_action.useremail,bjx_action.usertel,bjx_action.shouhuodizhi,bjx_action.bookcount,bjx_action.star,bjx_action.pingjia from BJX_goods inner join bjx_action on BJX_goods.bookid=bjx_action.bookid where bjx_action.username='"&request.Cookies("bjx")("username")&"' and dingdan='"&dingdan&"' ",conn,1,1
if rs.eof and rs.bof then
response.write "<p align=center>此订单中有商品已被管理员删除,无法进行正确计算!<br>订单取消,请通知管理员或重新下订单!</p>"
response.End
end if
%>
<table width="760" border="0" align="center" cellpadding="0" cellspacing="0">
<tr> <td height="10"></td></tr>
<tr>
<td> 
<table width="100%" border="0" cellpadding="5" cellspacing="1" bgcolor="#cccccc" align="center">
                          <tr><td colspan="3"> <strong><font color="#ffffff">订购数量订单号为:<font color="#FF0000"><%=dingdan%></font>,详细资料如下:</font></strong></td>
                          </tr>
                          <tr bgcolor="#FFFFFF"> 
                            <td width="15%" align="right">订单状态:</td>
                            <td colspan="2"> 
                              <table width="98%" border="0" cellspacing="0" cellpadding="0" align="center">
                                <tr> 
                                  <form name="form1" method="post" action="savedingdan.asp?dan=<%=dingdan%>&action=save">
                                    <td> 
                                      <%zhuang()%>
                                      <br>
					<%if rs("zhuangtai")<>6 then %>
					<input class="go-wenbenkuang" name="submit" value="修改订单状态" type="submit">
                                      <%else
					response.write "<font color=red><b>订单工作流程全部完成</b></font>"
					end if%>
                                    </td>
                                  </form>
                                </tr>
                              </table>
                            </td>
                          </tr>
                          <tr bgcolor="#FFFFFF"> 
                            <td align="right">商品列表:</td>
                            <td colspan="2"> 
                              <table width="98%" border="0" align="center" cellpadding="5" cellspacing="1" bgcolor="#cccccc">
                                <tr align="center"> 
                                  <td><strong><font color="#ffffff">商品名称</font></strong></td>
                                  <td><strong><font color="#ffffff">订购数量</font></strong></td>
                                  <td><strong><font color="#ffffff">会员价格</font></strong></td>
                                  <td><strong><font color="#ffffff">金额小计</font></strong></td>
                                </tr>
                                <%zongji=0
		do while not rs.eof%>
                                <tr bgcolor="#FFFFFF"> 
                                  <td style='PADDING-LEFT: 5px' height="22"><a target="_blank" href=product.asp?Iheeoid=<%=rs("bookid")%> ><%=trim(rs("bookname"))%></a></td>
                                  <td height="22"> 
                                    <div align="center"><%=rs("bookcount")%></div>
                                  </td>
                                  <td height="22"> 
                                    <div align="center"><%=rs("danjia")&"元"%></div>
                                  </td>
                                  <td height="22"> 
                                    <div align="center"><%=rs("zonger")&"元"%></div>
                                  </td>
                                </tr>
		<%zongji=rs("zonger")+zongji
		feiyong=rs("feiyong")
		rs.movenext
		loop
		rs.movefirst%>
                                <tr bgcolor="#FFFFFF"> 
                                  <td colspan="4" height="22"> 
                                    <div align="right">订单总额:<%=zongji%>元+费用:<%=feiyong%>元  共计:<%=zongji+feiyong%>元 
                                      &nbsp;&nbsp;&nbsp;&nbsp;</div>
                                  </td>
                                </tr>
                              </table>
                            </td>
                          </tr>
                          <tr bgcolor="#FFFFFF"><form name="star" method="post" action="savedingdan.asp?dan=<%=dingdan%>&action=star">
<td align="right">订单评级:</td><td colspan="2"><input type="radio" name="star" value="1" <% If rs("star") = 1 Then Response.write "Checked" %>>☆
<input type="radio" name="star" value="2" <% If rs("star") = 2 Then Response.write "Checked" %>>☆☆
<input type="radio" name="star" value="3" <% If rs("star") = 3 Then Response.write "Checked" %>>☆☆☆
<input type="radio" name="star" value="4" <% If rs("star") = 4 Then Response.write "Checked" %>>☆☆☆☆
<input type="radio" name="star" value="5" <% If rs("star") = 5 Then Response.write "Checked" %>>☆☆☆☆☆<br><%if rs("zhuangtai")=5 then %>
					<input class="go-wenbenkuang" name="submit" value="给订单评级" type="submit"><%end if%></td></form>
                          </tr>
                          <tr bgcolor="#FFFFFF"><form name="pingjia" method="post" action="savedingdan.asp?dan=<%=dingdan%>&action=pingjia">
                            <td align="right">订单评价:</td>
                            <td colspan="2"><textarea name="pingjia" cols="70" rows="3" id="pingjia"><%=rs("pingjia")%></textarea><br><%if rs("zhuangtai")=5 then %>
					<input class="go-wenbenkuang" name="submit" value="给订单评价" type="submit"><%end if%></td></form>
                          </tr>
    <%set Godbook=server.CreateObject("adodb.recordset")
	Godbook.open "select * from BJX_action_jp where username='"&request.Cookies("bjx")("username")&"' and dingdan='"&dingdan&"'",conn,1,1
	if Godbook.recordcount>0 then%>
						  <tr bgcolor="#FFFFFF"> 
                            <td align="right">奖品列表:</td>
                            <td colspan="2"> 
                              <table width="98%" border="0" align="center" cellpadding="5" cellspacing="1" bgcolor="#cccccc">
                                <tr align="center"> 
                                  <td><strong><font color="#ffffff">奖品名称</font></strong></td>
                                  <td><strong><font color="#ffffff">所用积分</font></strong></td>
                                </tr>
        <%
	while not Godbook.eof%>
        <tr bgcolor="#FFFFFF"> 
	<td height="22"> 
	<%
	set Godbook1=server.CreateObject("adodb.recordset")
	Godbook1.open "select * from BJX_jiangpin where bookid="&Godbook("bookid"),conn,1,1
	if Godbook1.recordcount=1 then
	response.write Godbook1("bookname")
	end if
	Godbook1.close
	set Godbook1=nothing%>
	</td>
	<td align="center" height="22"><%=Godbook("jifen")%></td>
	</tr>
        <%
	Godbook.movenext
	wend%>
	</table>
	</td>
	</tr>
<%end if
Godbook.close
set Godbook=nothing%>
                          <tr bgcolor="#FFFFFF"> 
                            <td align="right">收货人姓名:</td>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -