日期:2013-06-05  浏览次数:20730 次

发言的服务器端页面bbs.asp:

<%
dim flag
flag=0
name=REQUEST.FORM("name")
code=REQUEST.FORM("code")
insubject=request.form("subject")
incontent=REQUEST.FORM("content")
subject="'"&request.form("subject")&"'"
content="'"&REQUEST.FORM("content")&"'"
curdate=Date
curtime=Time
set conn = Server.CreateObject("ADODB.Connection")
DBPath = Server.MapPath("author.mdb")
conn.Open "driver={Microsoft Access Driver (*.mdb)};dbq=" & DBPath
set RS = Conn.Execute("SELECT * FROM author ")
do while not rs.eof
if rs("authorname")=name and rs("password")=code then
flag=1
Set fso = Server.CreateObject("Scripting.FileSystemObject")
Application.Lock
TxtPath = Server.MapPath("bbs.txt")
Set InStream = fso.OpenTextFile (txtpath, ,true)
number = Cstr(InStream.Readline+1)
Set OutStream = fso.CreateTextFile (txtpath)
OutStream.WriteLine number
If Request.QueryString("ID")="" Then
manswernum=number
Else
manswernum=Request.QueryString("ID")
End If
If Request.QueryString("topnum")="" Then
mtopnum=number
Else
mtopnum=Request.QueryString("topnum")
End If
Set OutStream = Nothing
application.unlock
inname="'"&name&"'"
Set connbbs = Server.CreateObject("ADODB.Connection")
DBPath = Server.MapPath("bbs.mdb")
connbbs.Open "driver={Microsoft Access Driver (*.mdb)};dbq=" & DBPath
Connbbs.Execute("INSERT INTO bbs(ID,authorname,subject,content,adddate,answernum,topnum,visitnum) Values("&number& ","&inname& ","&subject& "," &content& "," &curdate& " ,"&manswernum& "," &mtopnum& ",0)")

Connbbs.Close %>
<% =name %><p>
<% =insubject %><p><% =curdate & " " %><% =curtime & " 添加贴子 " %><p>
<% =incontent %><p><a href="disp.asp">返回论坛</a>
<%
exit do
response.flush
Else
rs.movenext
%>
<% End If
loop
RS.Close
Conn.Close %>
<%if flag=0 then%>
您的用户名或密码出错,请您<a href="bbs_add.htm">重输!</a>
<%end if%>