⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 iheeo_car.asp

📁 易和阳光购物商城 v1.3 | 功能简介 增加了防注入文件
💻 ASP
📖 第 1 页 / 共 3 页
字号:
  if(document.shouhuoxx.youbian.value.length!=6) {
	document.shouhuoxx.youbian.focus();
    alert("对不起,请正确填写邮编!");
	return false;
  } 
    if(checkspace(document.shouhuoxx.usertel.value)) {
	document.shouhuoxx.usertel.focus();
    alert("对不起,请留下您的电话!");
	return false;
  }
    if(checkspace(document.shouhuoxx.songhuofangshi.value)) {
	document.shouhuoxx.songhuofangshi.focus();
    alert("对不起,请选择送货方式!");
	return false;
  }
    if(checkspace(document.shouhuoxx.zhifufangshi.value)) {
	document.shouhuoxx.zhifufangshi.focus();
    alert("对不起,请选择支付方式!");
	return false;
  }
  if(document.shouhuoxx.useremail.value.length!=0)
  {
    if (document.shouhuoxx.useremail.value.charAt(0)=="." ||        
         document.shouhuoxx.useremail.value.charAt(0)=="@"||       
         document.shouhuoxx.useremail.value.indexOf('@', 0) == -1 || 
         document.shouhuoxx.useremail.value.indexOf('.', 0) == -1 || 
         document.shouhuoxx.useremail.value.lastIndexOf("@")==document.shouhuoxx.useremail.value.length-1 || 
         document.shouhuoxx.useremail.value.lastIndexOf(".")==document.shouhuoxx.useremail.value.length-1)
     {
      alert("Email地址格式不正确!");
      document.shouhuoxx.useremail.focus();
      return false;
      }
   }
 else
  {
   alert("Email不能为空!");
   document.shouhuoxx.useremail.focus();
   return false;
   }
   
}
//-->
        </script>
        <%
rs.close
set rs=nothing
'/////////////////////////////////////////
case "shop2"
shijian=now()
dingdan=year(shijian)&month(shijian)&day(shijian)&hour(shijian)&minute(shijian)&second(shijian)
%>
        <table width="970" align="center" border="0" cellspacing="0" cellpadding="0" class="table-zuoyou" bordercolor="#CCCCCC">
          <tr>
            <td class="table-shangxia" background="images/class_bg.jpg" height=50> <img src="images/ring02.gif" width="23" height="15" align="absmiddle"> <a href=index.asp><%=webname%></a> >> 提交定单</td>
          </tr>
        </table>
        <table width="970" align="center" border="0" cellspacing="0" cellpadding="0" class="table-zuoyou" bordercolor="#CCCCCC">
          <tr>
            <td bgColor=#ffffff height=1></TD>
          </tr>
          <tr bgcolor="#ffffff">
            <td bgColor="#f1f1f1" height="30" align="center">请正确填写定单以便收货|订单号:<%= dingdan%> </td>
          </tr>
          <tr>
            <td bgColor=#cccccc height=1></TD>
          </tr>
          <tr>
            <td bgColor=#f1f1f1 height=3></TD>
          </tr>
          <tr>
            <td><table width="100%" border="0" align="center" cellpadding="0" cellspacing="0">
                <tr bgcolor="#ffffff">
                  <td align="center" valign="top" height=50 colspan=2><%set rs=server.CreateObject("adodb.recordset")
rs.open "select bjx_action.actionid,bjx_action.bookid,bjx_action.bookcount,bjx_action.zonger,BJX_goods.bookname,bjx_action.shjiaid,BJX_goods.anclassid,BJX_goods.banci,BJX_goods.shichangjia,BJX_goods.huiyuanjia,BJX_goods.vipjia from BJX_goods inner join  bjx_action on BJX_goods.bookid=bjx_action.bookid where bjx_action.username='"&username&"' and bjx_action.zhuangtai=7 order by BJX_goods.shjiaid",conn,1,1 
%>
                      <br>
                      <table width=95% border=0 align=center cellpadding=2 cellspacing=1 bgcolor=#cccccc>
                        <tr align=center bgcolor=#f1f1f1>
                          <td width=35%>商品名称</td>
                          <td width=20%>市 场 价</td>
                          <td width=15%><%if request.Cookies("bjx")("reglx")="2" then %>VIP<%else%>会员<%end if%>价格</td>
                          <td width=15%>数 量</td>
                          <td width=15%>总 价</td>
                        </tr>
                        <%shuliang=rs.recordcount
jianshu=0
zongji=0
fudongjia=0
bjxbookname=""
do while not rs.eof
bjxbookname=bjxbookname&"|"&rs("bookname")
%>
                        <tr align="center" bgcolor=#ffffff>
                          <td height="30" align="left"> <a target="_blank" href="product.asp?Iheeoid=<%=rs("bookid")%>"><%=rs("bookname")%></a>
                              <input name=bookid2 type=hidden value="<%=rs("bookid")%>">
                              <input name=actionid2 type=hidden value="<%=rs("actionid")%>">
                          </td>
                          <td><s><%=rs("shichangjia")%></s>元</td>
                          <td><%
	if request.Cookies("bjx")("reglx")="2" then 
	response.write rs("vipjia")
	else
	response.write rs("huiyuanjia")
	end if%>
                  元</td>
                          <td><%=rs("bookcount")%></td>
                          <td><%=rs("zonger")%> 元</td>
                        </tr>
                        <%
jianshu=jianshu+rs("bookcount")
zongji=zongji+rs("zonger")
'算每件商品的浮动价
firstshjid=rs("shjiaid")
rs.movenext
if not rs.eof then
nextshjid=rs("shjiaid")
end if

loop
rs.close
set rs=nothing
zongji=formatnumber(zongji,2)
%>
                        <tr bgcolor=#ffffff>
                          <td height=30 colspan=5 align=center>货款总计:<font color=red><%=zongji%></font> 元</td>
                        </tr>
                        <%set Godbook=server.CreateObject("adodb.recordset")
Godbook.open "select * from BJX_action_jp where username='"&username&"' and zhuangtai=7",conn,1,1
if Godbook.recordcount>0 then%>
                        <tr>
                          <td colspan=5 bgcolor=#ffffff><table width="95%" border="0" cellspacing="1" cellpadding="1" bgcolor="#cccccc" align="center">
                              <tr bgcolor="#ffffff">
                                <td colspan="2" align="center">您已选择的奖品清单</td>
                              </tr>
                              <tr align="center" bgcolor="#f1f1f1">
                                <td>奖品名称</td>
                                <td>使用积分</td>
                              </tr>
                              <%
while not Godbook.eof%>
                              <tr bgcolor="#ffffff">
                                <td align="center"><%
	set Godbook1=server.CreateObject("adodb.recordset")
	Godbook1.open "select * from BJX_jiangpin where bookid="&Godbook("bookid"),conn,1,1
	if Godbook1.recordcount=1 then
	response.write "<font color=blue>"&Godbook1("bookname")&"</font>"
	end if
	Godbook1.close
	set Godbook1=nothing%>
                                </td>
                                <td align="center"><%=Godbook("jifen")%></td>
                              </tr>
                              <%Godbook.movenext
                              wend%>
                          </table></td>
                        </tr>
                        <%end if
Godbook.close
set Godbook=nothing%>
                      </table>
                      <br>
                  </td>
                </tr>
                <tr bgcolor="#ffffff">
                  <td width="50%" align="center" valign="top"><table width="90%" border="0" cellpadding="2" cellspacing="1" bgcolor="#CCCCCC">
                      <tr>
                        <td colspan="2" height="24" bgcolor="#f1f1f1" align="center">您的订单信息</td>
                      </tr>
                      <tr bgcolor="ffffff">
                        <td width="30%" align="center">姓名:</td>
                        <td width="70%" style="PADDING-LEFT: 20px"><%=request("userzhenshiname")%></td>
                      </tr>
                      <tr bgcolor="ffffff">
                        <td align="center">邮编:</td>
                        <td style="PADDING-LEFT: 20px"><%=request("youbian")%></td>
                      </tr>
                      <tr bgcolor="ffffff">
                        <td align="center">地址:</td>
                        <td style="PADDING-LEFT: 20px"><%=request("shouhuodizhi")%></td>
                      </tr>
                      <tr bgcolor="ffffff">
                        <td align="center">电话:</td>
                        <td style="PADDING-LEFT: 20px"><%=request("usertel")%></td>
                      </tr>
                      <tr bgcolor="ffffff">
                        <td align="center">邮箱:</td>
                        <td style="PADDING-LEFT: 20px"><%=request("useremail")%></td>
                      </tr>
                      <tr bgcolor="ffffff">
                        <td align="center">送货:</td>
                        <td style="PADDING-LEFT: 20px"><%
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from Iheeo_Delivery where SongKey="&request("songhuofangshi"),conn,1,1
if rs.eof and rs.bof then
response.write "方式已经被删除"
else
response.write rs("SongName")
end if
rs.close
set rs=nothing%>
                        </td>
                      </tr>
                      <tr bgcolor="ffffff">
                        <td align="center">支付:</td>
                        <td style="PADDING-LEFT: 20px"><%
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from Iheeo_Pay where PayKey="&request("zhifufangshi"),conn,1,1
if rs.eof and rs.bof then
response.write "方式已经被删除"
else
response.write rs("PayName")

end if
rs.close
set rs=nothing%>
                        </td>
                      </tr>
                  </table></td>
                  <td width="50%" align="center" valign="top"><table width="90%" border="0" cellpadding="2" cellspacing="1" bgcolor="#CCCCCC">
                      <tr>
                        <td colspan="2" height="24" bgcolor="#f1f1f1" align="center">送货费计算</td>
                      </tr>
                      <%
'计算费用
'先取出参数
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from Iheeo_Delivery where SongKey="&request("songhuofangshi"),conn,1,1
SongFei=rs("SongFei")
	
	feiyong=SongFei
		if request("zhifufangshi")=71 then
          '得到预存款
          set rs2=server.CreateObject("adodb.recordset")
          rs2.Open "select yucun from bjx_User where username='"&username&"'",conn,1,1
          yucunkuan=rs2("yucun")
          rs2.close
          set rs2=nothing
	  if yucunkuan<feiyong+zongji then
	  	response.write "<script language=javascript>alert('您的预存款不足,请更换支付方式!');history.go(-1);</script>"
	end if
	end if%>
                      <tr>
                        <td style="PADDING-right: 20px" align="right" bgcolor="ffffff">商品总价:<%=zongji%> 元<br>您的送货费用计:<%=feiyong%> 元</td>
                      </tr>
                      <tr>
                        <td style="PADDING-right: 20px" align="right" bgcolor="ffffff"><font color=red>您的订单总金额: <%=FormatNumber((feiyong+zongji),2)%> 元</font></td>
                      </tr>
                      <tr>
                        <td style="PADDING-right: 20px" align="right" bgcolor="ffffff"><a target="_blank" href="help.asp?action=feiyong">查看送货费用说明</a></td>
                      </tr></table></td>
                </tr>
                <form name="shouhuoxx2" method="post" action="iheeo_car.asp?action=ok">
                  <tr bgcolor="#ffffff" align="center">
                    <td colspan="2"><table width="95%" border="0" cellspacing="0" cellpadding="2">

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -