⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 iheeo_car.asp

📁 易和阳光购物商城 v1.3 | 功能简介 增加了防注入文件
💻 ASP
📖 第 1 页 / 共 3 页
字号:
                        <tr>
                          <td width="20%"><input type="checkbox" name="fapiao" value="1">
                    是否要发票?
                      <input name="dingdan" type="hidden" value=<%=trim(dingdan)%>>
                      <input name="userzhenshiname" type="hidden" value=<%=trim(request("userzhenshiname"))%>>
                      <input name="shousex" type="hidden" value=<%=trim(request("shousex"))%>>
                      <input name="useremail" type="hidden" value=<%=trim(request("useremail"))%>>
                      <input name="shouhuodizhi" type="hidden" value=<%=trim(request("shouhuodizhi"))%>>
                      <input name="youbian" type="hidden" value=<%=trim(request("youbian"))%>>
                      <input name="usertel" type="hidden" value=<%=trim(request("usertel"))%>>
                      <input name="songhuofangshi" type="hidden" value=<%=trim(request("songhuofangshi"))%>>
                      <input name="zhifufangshi" type="hidden" value=<%=trim(request("zhifufangshi"))%>>
                      <input name="feiyong" type="hidden" value=<%=feiyong%>>
                      <input name="zongji" type="hidden" value=<%=zongji%>>
                      <input name="money" type="hidden" value=<%=zongji+feiyong%>>
                      <input name=userid type=hidden value="<%=request("userid")%>" >
					  <input name="bjxbookname" type="hidden" value=<%=bjxbookname%>>
                          </td>
                          <td width="60%"><input class="wenbenkuang" type="text" name="liuyan" size="35" maxlength="30">
                    您对此订单的特殊说明(30字内) </td>
                          <td width="20%" align="center" height="60"><input class="go-wenbenkuang" type="button" name="Submit22" value="上一步" onClick="javascript:history.go(-1)">
                              <input class="go-wenbenkuang" type="submit" name="Submit42" value="完成订单">
                          </td>
                        </tr>
                    </table></td>
                  </tr>
                </form>
            </table></td>
          </tr>
        </table>
        <%
case "ok"
'/////////////////////////////////////////////////
function HTMLEncode2(fString)
	fString = Replace(fString, CHR(13), "")
	fString = Replace(fString, CHR(10) & CHR(10), "</P><P>")
	fString = Replace(fString, CHR(10), "<BR>")
	HTMLEncode2 = fString
end function

'修改用户的送货信息
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from bjx_User where username='"&username&"'",conn,1,3
rs("userzhenshiname")=trim(request("userzhenshiname"))
rs("sex")=trim(request("shousex"))
rs("useremail")=trim(request("useremail"))
rs("shouhuodizhi")=trim(request("shouhuodizhi"))
rs("youbian")=trim(request("youbian"))
rs("usertel")=trim(request("usertel"))
rs("songhuofangshi")=trim(request("songhuofangshi"))
rs("zhifufangshi")=trim(request("zhifufangshi"))
rs.update
rs.close
set rs=nothing

if session("xiadan")<>minute(now) then
'再判断库存
'未写

dim shijian,dingdan,zongji,feiyong
shijian=now()
money=trim(request("money"))
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from BJX_action where username='"&username&"' and zhuangtai=7",conn,1,3
if request.Cookies("bjx")("username")<>"" then
dingdan=trim(request("dingdan"))
else
dingdan=username
end if
do while not rs.eof
'得到价格,减库存
set rs2=server.CreateObject("adodb.recordset")
rs2.open "select * from BJX_goods where bookid="&rs("bookid"),conn,1,3
if request.Cookies("bjx")("reglx")="2" then 
danjia=rs2("vipjia")
else
danjia=rs2("huiyuanjia")
end if
rs2("chengjiaocount")=rs2("chengjiaocount")+rs("bookcount")
rs2("kucun")=rs2("kucun")-rs("bookcount")
rs2.update
rs2.close
set rs2=nothing
'rs.addnew
'rs("username")=trim(request.cookies("bookshop")("username"))
'rs("bookid")=rs2("bookid")
rs("actiondate")=shijian
'rs("bookcount")=CInt(Request("Godbook"&rs2("bookid")))
if request("zhifufangshi")=71 then    '送货上门或预存款支付,直接改为订单完成(已收到款)
rs("zhuangtai")=3
else
rs("zhuangtai")=1
end if
rs("dingdan")=dingdan
rs("youbian")=int(request("youbian"))
rs("shouhuoname")=trim(request("userzhenshiname"))
rs("shouhuodizhi")=trim(request("shouhuodizhi"))
rs("zhifufangshi")=int(request("zhifufangshi"))
rs("songhuofangshi")=int(request("songhuofangshi"))
rs("shousex")=int(request("shousex"))
rs("liuyan")=HTMLEncode2(trim(request("liuyan")))
rs("userzhenshiname")=trim(request("userzhenshiname"))
rs("useremail")=trim(request("useremail"))
rs("usertel")=trim(request("usertel"))
rs("userid")=request("userid")
'新增
if request("fapiao")<>1 then 
fapiao=0
else
fapiao=1
end if
rs("fapiao")=fapiao
rs("feiyong")=request("feiyong")
rs("danjia")=danjia
rs.update
'rs.close
'set rs=nothing
'conn.execute "delete from BJX_action where username='"&request.cookies("bookshop")("username")&"' and bookid in ("&bookid&") and zhuangtai=6"
rs.movenext
loop
rs.close
set rs=nothing
'再改奖品
z_jifen=0
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from BJX_action_jp where username='"&username&"' and zhuangtai=7",conn,1,3
do while not rs.eof
rs("actiondate")=shijian
rs("zhuangtai")=5
rs("dingdan")=dingdan
rs("userid")=request("userid")
z_jifen=z_jifen+rs("jifen")
rs.update
rs.movenext
loop
rs.close
set rs=nothing
'减去积分
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from bjx_User where username='"&username&"'",conn,1,3
rs("jifen")=rs("jifen")-z_jifen
'如果是在线支付,要扣预存款
if request("zhifufangshi")=71 then 
rs("yucun")=rs("yucun")-request("feiyong")-request("zongji")
end if
rs.update
rs.close
set rs=nothing

session("xiadan")=minute(now)
else
response.Write "<center>您不能重复提交!</center>"
response.End
end if
%>
        <table width="970" align="center" border="0" cellspacing="0" cellpadding="0" class="table-zuoyou" bordercolor="#CCCCCC">
          <tr>
            <td class="table-shangxia" background="images/class_bg.jpg" height=50> <img src="images/ring02.gif" width="23" height="15" align="absmiddle"> <a href=index.asp><%=webname%></a> >>定单提交成功</td>
          </tr>
        </table>
        <table width="970" align="center" border="0" cellspacing="0" cellpadding="0" class="table-zuoyou" bordercolor="#CCCCCC">
          <tr>
            <td bgColor=#ffffff height=1></TD>
          </tr>
          <tr bgcolor="#ffffff">
            <td bgColor="#f1f1f1" height="30" align="center">您的订单已经成功提交,我们会在第一时间进行处理,请记清您的订单号以备查询。</td>
          </tr>
          <tr>
            <td bgColor=#cccccc height=1></TD>
          </tr>
          <tr>
            <td bgColor=#f1f1f1 height=3></TD>
          </tr>
          <tr>
            <td height="30" bgcolor="ffffff" style="PADDING-LEFT: 100px">订单号:<font color=red><%=dingdan%></font></td>
          </tr>
		  <%if request.Cookies("bjx")("username")<>"" then%>
          <tr>
            <td height="30" bgcolor="ffffff" style="PADDING-LEFT: 100px">订单查询:您可通过“<a href="javascript:;" onclick="javascript:window.open('user.asp','','')">我的专区</a>”&gt;&gt;“<a href="javascript:;" onclick="javascript:window.open('user.asp?action=dindan','','')">我的订单</a>”查询您的订单状态。</td>
          </tr>
          <tr>
            <td height="60" bgcolor="ffffff" style="PADDING-LEFT: 100px">购物积分:请在收货后通过“<a href="javascript:;" onclick="javascript:window.open('user.asp','','')">我的专区</a>”&gt;&gt;“<a href="javascript:;" onclick="javascript:window.open('user.asp?action=dindan','','')">我的订单</a>”及时更改您的订单状态为“完成”<br>
			因为每笔订单的积分只有在订单完成后才能累计到您的购物积分中。 </td>
          </tr>
		  <%else%>
		  <tr>
            <td height="30" bgcolor="ffffff" style="PADDING-LEFT: 100px">订单查询:因为您不是我们的会员,所以您不能查询您的订单状态。</td>
          </tr>
		  <tr>
            <td height="30" bgcolor="ffffff" style="PADDING-LEFT: 100px">购物积分:因为您不是我们的会员,所以您不能获得积分奖励。 </td>
          </tr>
          <%
		  end if
		  if request("zhifufangshi")=90 then %>
          <tr>
            <td height="30" bgcolor="ffffff" style="PADDING-LEFT: 100px">您是通过预存款支付的,我们会尽快地给你发货的!</td>
          </tr>
          <%else
if request("zhifufangshi")=91 then %>
          <tr>
            <td height="30" bgcolor="ffffff" style="PADDING-LEFT: 100px">您是选择的“货到付款”,我们会尽快给您送货的!</td>
          </tr>
          <%else%>
          <tr>
            <td height="30" bgcolor="ffffff" style="PADDING-LEFT: 100px">请您在一周内依照您选择的支付方式进行汇款,汇款时请注明您的<font color="#FF0000">订单号</font>!</td>
          </tr>
          <tr>
            <td height="30" bgcolor="ffffff" align="center"><form name="onlinepay" action="pay.asp" method="post" target="_blank" >
<input type="hidden" name="orderid" value="<%=dingdan%>">
<input type="hidden" name="totalmoney" value="<%=money%>">
<input type="hidden" value=<%
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from Iheeo_Pay where PayKey="&request("zhifufangshi"),conn,1,1
response.write rs("PayKey")
rs.close
set rs=nothing%> name="PayKey"><input name="submit" type="image" src="image/pay/<%=trim(request("zhifufangshi"))%>.gif" border="0"></FORM></td>
          </tr>
          <%end if%>
          <%end if%><tr>
            <td height="30" bgcolor="ffffff" style='PADDING-LEFT: 100px' align="right"><a href="#" onClick=javascript:window.close()> 关闭窗口</a><font color="#999999"> 订单提交完成 创建时间:<%=shijian%>&nbsp;</font> </td>
          </tr>
        </table>
        <%
		response.Cookies("bjx")("dingdanusername")=""
		end select%></TD>
    </TR>
  </TBODY>
</TABLE>
<!--#include file="Include/Iheeo_service.asp"-->
<!--#include file="Include/Iheeo_foot.asp"-->
</body>
</html>
<script language=javascript>
<!--
function regInput(obj, reg, inputStr)
{
	var docSel	= document.selection.createRange()
	if (docSel.parentElement().tagName != "INPUT")	return false
	oSel = docSel.duplicate()
	oSel.text = ""
	var srcRange	= obj.createTextRange()
	oSel.setEndPoint("StartToStart", srcRange)
	var str = oSel.text + inputStr + srcRange.text.substr(oSel.text.length)
	return reg.test(str)
}
function checkspace(checkstr) {
  var str = '';
  for(i = 0; i < checkstr.length; i++) {
    str = str + ' ';
  }
  return (str == checkstr);
}
   //-->
</script>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -