-
1 # 使用者3416890448769
-
2 # 使用者3416890448769
login.asp:
coon.asp:
connstr = "DBQ=" + server.mappathuser.mdb") + ";DRIVER={Microsoft Access Driver (*.mdb)}"
Set conn=Server.createobject("ADODB.CONNECTION")
conn.Open connstr
%>
外加after_login.asp登入驗證頁面:
Dim UserName,PassWord
UserName=replace(trim(Request.Form("Username")),""","‘")
PassWord=replace(trim(Request.Form("PassWord")),""","‘")
If UserName="" or PassWord="" Then
Response.Write ("")
Response.end
End If
if Instr(UserName,">")>0 or Instr(UserName,"0 or Instr(UserName,"=")>0 or Instr(UserName,"%")>0 or Instr(UserName,chr(32))>0 or Instr(UserName,"?")>0 or Instr(UserName,"&")>0 or Instr(UserName,";")>0 or Instr(UserName,",")>0 or Instr(UserName,""")>0 or Instr(UserName,chr(34))>0 or Instr(UserName,chr(9))>0 or Instr(UserName," ")>0 or Instr(UserName,"$")>0 then
Response.Write ("")
Response.end
else
UserName=Trim(UserName)
end if
set rs=server.createobject("adodb.recordset")
sql="select * from [user] where UserName=""&UserName&"""
rs.open sql,conn,1,3
if rs.eof then
Response.Write ("")
Response.end
else
if rs("PassWord")PassWord then
rs.close
set rs=nothing
Response.Write ("")
Response.end
else
session("UserName")=UserName"登入成功傳遞一個session值以便以後呼叫使用者相關
session.timeout=300
end if
end if
rs.close
set rs=nothing
CloseDatabase
%>
回覆列表
login.asp:
coon.asp:
connstr = "DBQ=" + server.mappathuser.mdb") + ";DRIVER={Microsoft Access Driver (*.mdb)}"
Set conn=Server.createobject("ADODB.CONNECTION")
conn.Open connstr
%>
外加after_login.asp登入驗證頁面:
Dim UserName,PassWord
UserName=replace(trim(Request.Form("Username")),""","‘")
PassWord=replace(trim(Request.Form("PassWord")),""","‘")
If UserName="" or PassWord="" Then
Response.Write ("")
Response.end
End If
if Instr(UserName,">")>0 or Instr(UserName,"0 or Instr(UserName,"=")>0 or Instr(UserName,"%")>0 or Instr(UserName,chr(32))>0 or Instr(UserName,"?")>0 or Instr(UserName,"&")>0 or Instr(UserName,";")>0 or Instr(UserName,",")>0 or Instr(UserName,""")>0 or Instr(UserName,chr(34))>0 or Instr(UserName,chr(9))>0 or Instr(UserName," ")>0 or Instr(UserName,"$")>0 then
Response.Write ("")
Response.end
else
UserName=Trim(UserName)
end if
set rs=server.createobject("adodb.recordset")
sql="select * from [user] where UserName=""&UserName&"""
rs.open sql,conn,1,3
if rs.eof then
Response.Write ("")
Response.end
else
if rs("PassWord")PassWord then
rs.close
set rs=nothing
Response.Write ("")
Response.end
else
session("UserName")=UserName"登入成功傳遞一個session值以便以後呼叫使用者相關
session.timeout=300
end if
end if
rs.close
set rs=nothing
CloseDatabase
%>