下面是向数据库写数据的代码:
==========================================
<!--#include file="admin/database/dbcon.asp"-->
<%
Function Str_filter(InString)
NewStr=Replace(InString,"'","''")
NewStr=Replace(NewStr,"<","<")
NewStr=Replace(NewStr,">",">")
NewStr=Replace(NewStr,"chr(60)","<")
NewStr=Replace(NewStr,"chr(37)",">")
NewStr=Replace(NewStr,"""",""")
NewStr=Replace(NewStr,";",";;")
NewStr=Replace(NewStr,"--","-")
NewStr=Replace(NewStr,"/*"," ")
NewStr=Replace(NewStr,"%"," ")
NewStr=Replace(NewStr,"chr(13)","<br/>")
Str_filter=NewStr
End Function
%>
<%
dim lyname,lyqq,lywebsite,lycontent,lyicon
lyname=Str_filter(request.Form("lyname"))
lyqq=Str_filter(request.Form("lyqq"))
if not isnumeric(lyqq) then
response.Write("<script language='javascript'>alert('您的QQ号中存在非法字符!');history.back();</script>")
end if
if lyqq="" then lyqq=383355421
lywebsite=Str_filter(request.Form("lywebsite"))
if lywebsite="" then lywebsite="暂无主页"
lycontent=Str_filter(request.Form("lycontent"))
lyicon=request.Form("icon")
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from ly",con,1,3,1
rs.addnew
rs("lyname")=lyname
rs("lyqq")=lyqq
rs("lywebsite")=lywebsite
rs("lycontent")=lycontent
rs("lyicon")=lyicon
rs.update
rs.close
set rs=nothing
con.close
set con=nothing
response.Redirect("showmessage.asp")
%>