| DBPath = Server.MapPath(“cmddb.mdb”) conn.Open “driver={Microsoft Access Driver (*.mdb)};dbq=” & DBPath |
| conn.open“shujiyuan” |
| If trim(Request. cookies ("uname"))="fqy" and Request.cookies("upwd") =”fqy#e3i5.com” then ……..more……… End if |
| if not (rs.BOF or rs.eof) then login="true" Session("username"&sessionID) = Username Session("password"& sessionID) = Password ‘Response.cookies(“username”)= Username ‘Response.cookies(“Password”)= Password |
| <% server_v1=Cstr(Request.ServerVariables("HTTP_REFERER")) server_v2=Cstr(Request.ServerVariables("SERVER_NAME")) if mid(server_v1,8,len(server_v2))<>server_v2 then response.write "<br><br><center>" response.write " " response.write "你提交的路径有误,禁止从站点外部提交数据请不要乱改参数!" response.write " " response.end end if %> ‘个人感觉上面的代码过滤不是很好,有一些外部提交竟然还能堂堂正正的进来,于是再写一个. ‘这个是过滤效果很好,建议使用. |
[1] [2] 下一页