易和阳光购物商城 v1.3 | 功能简介 增加了防注入文件

源代码在线查看: sctogw.asp

软件大小: 1074 K
上传用户: spy0207
关键词: 1.3 商城
下载地址: 免注册下载 普通下载 VIP

相关代码

				
				
								if request.Cookies("bjx")("username")="" then
				response.write "alert('对不起,您还没有登陆!');window.close();"
				response.End
				end if
				
				username=request.Cookies("bjx")("username")
				bookid=request("bookid")
				
				if bookid="" then
				response.write "alert('对不起,您没有选择商品!');window.close();"
				response.End
				end if
				
				Set rs_s=Server.CreateObject("Adodb.RecordSet")
				rs_s.Open "Select * from BJX_goods where bookid in ("&bookid&")",Conn,3,3
				while not rs_s.eof 
				
				if request.Cookies("bjx")("reglx")="2" then 
					danjia=rs_s("vipjia")
				else
					danjia=rs_s("huiyuanjia")
				end if
				kucun=rs_s("kucun")
				bookname=rs_s("bookname")
				if kucun				response.write "alert('你选购的商品“"&bookname&"”暂时缺货不能放到购物车里,请选购其它商品!');window.close();"
				response.end
				end if
				set rs=server.CreateObject("adodb.recordset")
				rs.open "select * from BJX_action where username='"&username&"' and bookid="&trim(rs_s("bookid"))&" and zhuangtai=7",conn,1,3
				
				if rs.recordcount=1 then
				'//修改数量
				if kucun				response.write "alert('你选购的商品“"&bookname&"”暂时缺货不能放到购物车里,请选购其它商品!');window.close();"
				response.end
				end if
				rs("zonger")=(rs("bookcount")+1)*danjia
				rs("bookcount")=rs("bookcount")+1
				rs.update
				rs.close
				set rs=nothing
				else
				'//添加购物
				rs.close
				set rs=server.CreateObject("adodb.recordset")
				rs.open "select * from BJX_action",conn,1,3
				rs.addnew
				rs("bookid")=trim(rs_s("bookid"))
				rs("username")=username
				rs("zhuangtai")=7
				rs("bookcount")=1
				rs("zonger")=danjia
				rs.update
				rs.close
				set rs=nothing
				end if
				rs_s.movenext
				wend
				rs_s.close
				set rs_s=nothing
				response.Redirect "buy.asp?action=show"
				%>
							

相关资源