%
'
'****************************************************************
'
'
'
'
'
'
'
'
'
'
'
'
'
'
'****************************************************************************
classname=Request.Querystring("classname")
if instr(classname,"'") or instr(classname,"select") or instr(classname,"in") or instr(classname,"from") or instr(classname,"len") or instr(classname,"where") or instr(classname,"or") or instr(classname,"and") then
Response.Write("")
Response.End
end if
key=Request("key")
if len(key)=0 then
if classname="" or isnull(classname) then
sql="select * from imgbook order by ID desc"
else
sql="select * from imgbook where classname='"&classname&"' order by ID desc"
end if
url="index.asp?classname=" & classname
else
sql="select * from imgbook where title like '%"&key&"%' and classname='"&classname&"' order by ID desc"
url="index.asp?classname=" & classname &"&key=" & key
end if
%>