⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 iheeo_car.asp

📁 易和阳光购物商城 v1.3 | 功能简介 增加了防注入文件
💻 ASP
📖 第 1 页 / 共 3 页
字号:
<!--#include file="Include/Iheeo_Conn.asp"-->
<!--#include file="Include/Iheeo_config.asp"-->
<%
if request.Cookies("bjx")("username")<>"" then
username=trim(request.Cookies("bjx")("username"))
else
username=request.Cookies("bjx")("dingdanusername")
end if%>
<html><head><title><%=webname%>--我要下订单</title>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<link href="images/css.css" rel="stylesheet" type="text/css">
</head>
<body leftmargin="0" topmargin="0" marginwidth="0" marginheight="0">
<!--#include file="Include/Iheeo_head.asp"-->
<TABLE cellSpacing=0 cellPadding=0 width=970 align=center border=0>
  <TBODY>
    <TR>
      <TD class=b vAlign=top align=left>
<%dim bookid,action,i
action=request("action")
set rs=server.CreateObject("adodb.recordset")
rs.open "select count(*) as rec_count from BJX_action where username='"&username&"' and zhuangtai=7",conn,1,1
if rs("rec_count")=0 then
response.write "<script language=javascript>alert('对不起,您购物车没有商品,请在购物后,再去“结算中心”!');window.close();</script>"
response.End
end if
rs.close
set rs=nothing
//////////////////////////////////
select case action
case ""
set rs=server.CreateObject("adodb.recordset")
rs.open "select bjx_action.actionid,bjx_action.bookid,bjx_action.bookcount,bjx_action.zonger,BJX_goods.bookname,bjx_action.shjiaid,BJX_goods.shichangjia,BJX_goods.huiyuanjia,BJX_goods.vipjia from BJX_goods inner join  bjx_action on BJX_goods.bookid=bjx_action.bookid where bjx_action.username='"&username&"' and bjx_action.zhuangtai=7",conn,1,1 
%>
        <table width="970" align="center" border="0" cellspacing="0" cellpadding="0" class="table-zuoyou" bordercolor="#CCCCCC">
          <tr>
            <td class="table-shangxia" background="images/class_bg.jpg" height=50> <img src="images/ring02.gif" width="23" height="15" align="absmiddle"> <a href=index.asp><%=webname%></a> >> 下定单 <font color="#FF6633"><b>(在最后结算前您还可以修改购物车内容)</b></font></td>
          </tr>
        </table>
        <table width="970" align="center" border="0" cellspacing="0" cellpadding="0" class="table-zuoyou" bordercolor="#CCCCCC">
          <tr>
            <td bgColor=#ffffff colSpan=5 height=1></TD>
          </tr>
          <form name='form1' method='post' action=Iheeo_car.asp?action=shop1>
            <tr bgcolor="#f1f1f1" align="center">
              <td width=25% height="30">商品名称 </td>
              <td width=15%>市场价</td>
              <td width=15%>单价
                  <%if request.Cookies("bjx")("reglx")="2" then %>
        (VIP)
        <%else%>
        (会员)
        <%end if%>
              </td>
              <td width=15%>数量</td>
              <td width=10%>总价</td>
            </tr>
            <tr>
              <td bgColor=#cccccc colSpan=5 height=1></TD>
            </tr>
            <tr>
              <td bgColor=#f1f1f1 colSpan=5 height=3></TD>
            </tr>
            <%shuliang=rs.recordcount
jianshu=0
zongji=0
do while not rs.eof%>
            <tr bgcolor="#ffffff">
              <td height="30" width="25%" class="table-xia"> <a target="_blank" href="product.asp?Iheeoid=<%=rs("bookid")%>"><%=rs("bookname")%></a>
                  <input name=bookid type=hidden value="<%=rs("bookid")%>">
                  <input name=actionid type=hidden value="<%=rs("actionid")%>">
              </td>
              <td align="center" class="table-xia"><%=rs("shichangjia")%></td>
              <td align="center" class="table-xia"><%
	if request.Cookies("bjx")("reglx")="2" then 
	response.write rs("vipjia")
	else
	response.write rs("huiyuanjia")
	end if%>
        元</td>
              <td align="center" class="table-xia"><%=rs("bookcount")%></td>
              <td align="center" class="table-xia"><%=rs("zonger")%> 元</td>
            </tr>
            <%
jianshu=jianshu+rs("bookcount")
zongji=zongji+rs("zonger")
rs.movenext
loop
rs.close
set rs=nothing%>
            <tr bgcolor=#ffffff align=center>
              <td height=30 colspan=5> 您的购物车里有商品:<%=shuliang%> 件 总数量:<%=jianshu%> 件 共计:<font color=red><%=zongji%></font> 元 您有预存款:<%
if request.Cookies("bjx")("yucun")<>"" then
response.write request.Cookies("bjx")("yucun")&" 元"
else
response.write "0 元"
end if%></td>
            </tr>
            <tr bgcolor=#ffffff align=center>
              <td height=40 colspan=5><input class="go-wenbenkuang" type="button" name="Submit" value="修改购物车" onClick="this.form.action='buy.asp?action=show';this.form.submit()">
                  <input class="go-wenbenkuang" type="submit" name="Submit3" value="确认订单 下一步">
              </td>
            </tr>
            <%set Godbook=server.CreateObject("adodb.recordset")
	Godbook.open "select * from BJX_action_jp where username='"&username&"' and zhuangtai=7",conn,1,1
	if Godbook.recordcount>0 then%>
            <tr bgcolor="#ffffff">
              <td colspan=5><table width="95%" border="0" cellspacing="1" cellpadding="1" bgcolor="#cccccc" align="center">
                  <tr bgcolor="#ffffff">
                    <td colspan="2" align="center" height="30">您已选择的奖品清单</td>
                  </tr>
                  <tr bgcolor="#cccccc" align="center">
                    <td height="30"><b><font color="#ffffff">奖品名称</font></b></td>
                    <td height="30"><b><font color="#ffffff">使用积分</font></b></td>
                  </tr>
                  <%while not Godbook.eof%>
                  <tr bgcolor="#ffffff">
                    <td>
					<%
	set Godbook1=server.CreateObject("adodb.recordset")
	Godbook1.open "select * from BJX_jiangpin where bookid="&Godbook("bookid"),conn,1,1
	if Godbook1.recordcount=1 then
	response.write "<font color=blue>"&Godbook1("bookname")&"</font>"
	end if
	Godbook1.close
	set Godbook1=nothing%>
                    </td>
                    <td align="center"><%=Godbook("jifen")%></td>
                  </tr>
                  <%Godbook.movenext
wend%>
              </table></td>
            </tr>
            <%end if
Godbook.close
set Godbook=nothing%>
          </form>
        </table>
        <%
/////////////////////////////////////////
case "shop1"
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from bjx_User where username='"&username&"'",conn,1,1
userid=rs("userid")
%>
        <table width="970" align="center" border="0" cellspacing="0" cellpadding="0" class="table-zuoyou" bordercolor="#CCCCCC">
          <tr>
            <td class="table-shangxia" background="images/class_bg.jpg" height=50> <img src="images/ring02.gif" width="23" height="15" align="absmiddle"> <a href=index.asp><%=webname%></a> >> 填写收货信息</td>
          </tr>
        </table>
        <table width="970" align="center" border="0" cellspacing="0" cellpadding="0" class="table-zuoyou" bordercolor="#CCCCCC">
          <tr>
            <td bgColor=#ffffff colSpan=2 height=1></TD>
          </tr>
          <tr bgcolor="#ffffff">
            <td bgColor="#f1f1f1" colspan="2" height="30" align="center">请正确填写以下收货信息</td>
          </tr>
          <tr>
            <td bgColor=#cccccc colSpan=2 height=1></TD>
          </tr>
          <tr>
            <td bgColor=#f1f1f1 colSpan=2 height=3></TD>
          </tr>
          <form name="shouhuoxx" method="post" action="Iheeo_car.asp?action=shop2" onsubmit="ssxx">
            <tr bgcolor="#ffffff">
              <td width="30%" height="30" align="right" class="table-xia">收货人真实姓名:</td>
              <td width="70%" height="30" style="PADDING-LEFT: 20px" class="table-xia"><input name=userid type=hidden value="<%=userid%>">
                  <input name="userzhenshiname" class="wenbenkuang" type="text" id="userzhenshiname" size="16" value=<%=trim(rs("userzhenshiname"))%>>
        性别:
        <select class="wenbenkuang" name="shousex" id="shousex">
          <option value=1 <%if rs("sex")="1" then%>selected<%end if%>>男</option>
          <option value=2 <%if rs("sex")="0" then%>selected<%end if%>>女</option>
          <option value=0 <%if rs("sex")="2" then%>selected<%end if%>>保密</option>
        </select>
              </td>
            </tr>
            <tr bgcolor="#ffffff">
              <td width="30%" height="30" align="right" class="table-xia">详细地址:</td>
              <td width="70%" height="30" style="PADDING-LEFT: 20px" class="table-xia"><input class="wenbenkuang" name="shouhuodizhi" type="text" id="shouhuodizhi" size="50" value=<%=trim(rs("shouhuodizhi"))%>>
              </td>
            </tr>
            <tr bgcolor="#ffffff">
              <td width="30%" height="30" align="right" class="table-xia">邮政编码:</td>
              <td width="70%" height="30" style="PADDING-LEFT: 20px" class="table-xia"><input class="wenbenkuang" name="youbian" type="text" id="youbian" size="16" value="<%=rs("youbian")%>" ONKEYPRESS="event.returnValue=IsDigit();"></td>
            </tr>
            <tr bgcolor="#ffffff">
              <td width="30%" height="30" align="right" class="table-xia">联系电话:</td>
              <td width="70%" height="30" style="PADDING-LEFT: 20px" class="table-xia"><input class="wenbenkuang" name="usertel" type="text" id="usertel" size="16" value=<%=trim(rs("usertel"))%>>
              </td>
            </tr>
            <tr bgcolor="#ffffff">
              <td width="30%" height="30" align="right" class="table-xia">电子邮件:</td>
              <td width="70%" height="30" style="PADDING-LEFT: 20px" class="table-xia"><input class="wenbenkuang" name="useremail" type="text" id="useremail" size="30" value=<%=trim(rs("useremail"))%>>
              </td>
            </tr>
            <tr bgcolor="#ffffff">
              <td width="30%" height="30" align="right" class="table-xia">送货方式:</td>
              <td width="70%" height="30" style="PADDING-LEFT: 20px" class="table-xia"><%set rs6=server.CreateObject("adodb.recordset")
rs6.open "select * FROM Iheeo_Delivery order by SongList",conn,1,1
%><select name="songhuofangshi" size=4 style="WIDTH: 180px">
        <%do while not rs6.eof%>
        <option value="<%=rs6("SongKey")%>" <%if int(rs("songhuofangshi"))=int(rs6("SongKey")) then response.Write "selected" %>><%=trim(rs6("SongName"))%></option><%rs6.movenext
loop
rs6.close
set rs6=nothing%></select></td>
            </tr>
            <tr bgcolor="#ffffff">
              <td width="30%" height="30" align="right" class="table-xia">支付方式:</td>
              <td width="70%" height="30" style="PADDING-LEFT: 20px" class="table-xia"><%set rs5=server.CreateObject("adodb.recordset")
rs5.open "select * FROM Iheeo_Pay order by PayList",conn,1,1
%><select name="zhifufangshi" size=8 style="WIDTH: 180px">
        <%do while not rs5.eof%>
        <option value="<%=rs5("PayKey")%>" <%if int(rs("zhifufangshi"))=int(rs5("PayKey")) then response.Write "selected" %>><%=trim(rs5("PayName"))%></option><%rs5.movenext
loop
rs5.close
set rs5=nothing%></select></td>
            </tr>
            <tr bgcolor="#ffffff">
              <td height="40" colspan="2" align=center><input class="go-wenbenkuang" type="button" name="Submit2" value="上一步" onclick="javascript:history.go(-1)">
                  <input class="go-wenbenkuang" type="submit" name="Submit4" value="确认收货信息 下一步" onclick='return ssxx();'>
              </td>
            </tr>
          </form>
        </table>
        <SCRIPT LANGUAGE="JavaScript">
<!--
function IsDigit()
{
  return ((event.keyCode >= 48) && (event.keyCode <= 57));
}
function checkspace(checkstr) {
  var str = '';
  for(i = 0; i < checkstr.length; i++) {
    str = str + ' ';
  }
  return (str == checkstr);
}

function ssxx()
{
   if(checkspace(document.shouhuoxx.userzhenshiname.value)) {
	document.shouhuoxx.userzhenshiname.focus();
    alert("对不起,请填写收货人姓名!");
	return false;
  }
  if(checkspace(document.shouhuoxx.shouhuodizhi.value)) {
	document.shouhuoxx.shouhuodizhi.focus();
    alert("对不起,请填写收货人详细收货地址!");
	return false;
  }
  if(checkspace(document.shouhuoxx.youbian.value)) {
	document.shouhuoxx.youbian.focus();
    alert("对不起,请填写邮编!");
	return false;
  }

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -