%@ Language=VBScript %>
<% Option Explicit %>
<%
dim str,val ' ÇØÇÇÁ¤´åÄÄ Ãß°¡ 2008-05-27
function sqlCheck(str)
val=UCASE(str)
if instr(val, ";") <> 0 Or _
instr(val, "'") <> 0 Or _
instr(val, "--") <> 0 Or _
instr(val, "/*") <> 0 Or _
instr(val, "*/") <> 0 Or _
instr(val, "XP_") <> 0 Or _
instr(val, "DECLARE") <> 0 Or _
instr(val, "SELECT") <> 0 Or _
instr(val, "UPDATE") <> 0 Or _
instr(val, "DELETE") <> 0 Or _
instr(val, "INSERT") <> 0 Or _
instr(val, "SHUTDOWN") <> 0 Or _
instr(val, "DROP") <> 0 then
' response.write "¿À·ù¹ß»ý"
response.Write("")
response.End
Else
sqlCheck=str
end if
end function
'Dim idx : idx=sqlCheck(request("idx"))
Dim NewGetTable , GetSeq
Dim GetPage, GetSearchPart, GetSearchStr
NewGetTable = "noticesofBoard1"
GetSeq = sqlCheck(request("seq"))
GetPage = sqlCheck(request("page"))
GetSearchPart = sqlCheck(request("SearchPart"))
GetSearchStr = sqlCheck(request("SearchStr"))
'³»¿ë Ãâ·Â
Sql = "select BD_SEQ, BD_THREAD , BD_DEPTH , BD_NAME, BD_EMAIL ,BD_SUBJECT, BD_CONTENT,BD_URL, BD_PASSWD , BD_INPUTDATE, BD_IP, BD_READCOUNT ,BD_STATE from "
Sql = Sql & NewGetTable & " where BD_seq = " & GetSeq
Set Rs = Con.Execute(Sql)
Dim GetBD_SEQ : GetBD_SEQ = Rs(0)
Dim GetBD_THREAD : GetBD_THREAD = Rs(1)
Dim GetBD_DEPTH : GetBD_DEPTH = Rs(2)
Dim GetBD_NAME : GetBD_NAME = Rs(3)
Dim GetBD_EMAIL : GetBD_EMAIL = Rs(4)
Dim GetBD_SUBJECT : GetBD_SUBJECT = Rs(5)
Dim GetBD_CONTENT : GetBD_CONTENT = Rs(6)
Dim GetBD_URL : GetBD_URL = Rs(7)
Dim GetBD_BD_PASSWORD : GetBD_BD_PASSWORD = Rs(8)
Dim GetBD_BD_INPUTDATE: GetBD_BD_INPUTDATE = Rs(9)
Dim GetBD_BD_IP : GetBD_BD_IP = Rs(10)
GetBD_BD_IP = left(GetBD_BD_IP,10) & "..."
Dim GetBD_READCOUNT : GetBD_READCOUNT = Rs(11)
Dim GetBS_STATE : GetBS_STATE = Rs(12)
Rs.close
'ÆÄÀÏ Á¤º¸ Ãâ·Â
Sql = "select FILE_SEQ , FILE_BD_SEQ, FILE_BD_TABLE , FILE_NAME , FILE_SIZE from "& NewGetTable &"_pds"
Sql = Sql & " where FILE_BD_SEQ = " & GetBD_SEQ & " and FILE_BD_TABLE = '" & NewGetTable & "'"
Set Rs = Con.Execute(Sql)
Dim GetFILE_NAME , GetFILE_SIZE , GetFileImage
if not (Rs.BOF or Rs.EOF) then
GetFILE_NAME = ""&Rs(3)
GetFILE_SIZE = Rs(4)
GetFileImage = "
)+".gif) | "
Else
GetFILE_NAME = " ÆÄÀÏÀÌ ¾ø½À´Ï´Ù!"
GetFILE_SIZE = " no"
GetFileImage = " "
end if
Rs.close
Sql = "update " & NewGetTable & " set BD_READCOUNT = BD_READCOUNT + 1 where BD_SEQ = " & GetSeq
Con.Execute(Sql)
%>
PLM Best Practice Conference 2008 > PLM Community > °øÁö»çÇ×
 |
 |
 |
ÇöÀçÀ§Ä¡ : HOME >PLM Community > °øÁö»çÇ× |
|
|
|
Á¦¸ñ : <%= GetBD_SUBJECT %> |
³¯Â¥ : <%= GetBD_BD_INPUTDATE %> |
Á¶È¸ : <%= GetBD_READCOUNT %> |
|
<%= GetBD_CONTENT %> |
|
<%if session("admin") = "administrator" then%>
<% end if%>
<%if session("admin") = "administrator" then%>
<% else %>
<% end if%> |
 |
|
|
|