<%@LANGUAGE="JavaScript"%>
var strConnect="Provider=Microsoft.Jet.OLEDB.4.0; Data Source="
strConnect += Server.MapPath("\\GOP") + "\\datastores\\gop.mdb;"
<!-- METADATA TYPE="typelib"
FILE="C:\Program Files\Common Files\System\ado\msado15.dll" -->
<HTML>
<HEAD>
<TITLE>Administrator Page - Changing the Mailing List</TITLE>
</HEAD>
<BODY LINK="red" VLINK="red" ALINK="crimson">
<H2>Administrator Page</H2>
<H3>Changing a the Mailing List</H3>
<%
if (Request.Form("Delete") > "")
{
var sql="DELETE FROM Address WHERE ID = " + Request.Form("ID") + ";"
}
else
{
var firstName = new String(Request.Form("firstName"))
var lastName = new String(Request.Form("lastName"))
var Address = new String(Request.Form("Address"))
var City = new String(Request.Form("City"))
var myRegExp = /[']/g;
firstName = firstName.replace(myRegExp, ''');
lastName = lastName.replace(myRegExp, ''');
Address = Address.replace(myRegExp, ''');
City = City.replace(myRegExp, ''');
var sql="UPDATE Address SET firstName= '" + firstName + "' , lastName='"
sql += lastName + "' , Address='" + Address + "' , City='"
sql += City + "' , State='" + Request.Form("State") + "' , Zip='"
sql += Request.Form("Zip") + "' WHERE ID = " + Request.Form("ID") + ";"
}
var objConn=Server.CreateObject("ADODB.Connection");
objConn.Open(strConnect)
objConn.Execute(sql)
objConn.Close()
objConn = null;
Response.Write("The member has been updated in the database.")
Response.Write("<A HREF=\"../files/committee.asp\">")
Response.Write("Click here to see it.</A>")
%>
There's no link to see this one in action. I did that for security reasons. I just want to point out a few highlights.
[b]Danger in The Single Quote:[/b]
You'll notice that I replace single quote marks with the HTML encoded equivalent. I did that using the following code.
var myRegExp = /[']/g; firstName = firstName.replace(myRegExp, ''');The single quote is the only character you cannot input into a database using an ASP application. Everything else is fair game. DO NOT accept any text from users into your database without replacing all single quotes. To use an analogy, the single quote is like a key that opens up your entire database. Hackers will tear your application to shreds if you let someone input single quotes. [b]Execute( ):[/b] The only other thing I want to spend any time with is
机械节能产品生产企业官网模板...
大气智能家居家具装修装饰类企业通用网站模板...
礼品公司网站模板
宽屏简约大气婚纱摄影影楼模板...
蓝白WAP手机综合医院类整站源码(独立后台)...苏ICP备2024110244号-2 苏公网安备32050702011978号 增值电信业务经营许可证编号:苏B2-20251499 | Copyright 2018 - 2025 源码网商城 (www.ymwmall.com) 版权所有