% ' '**************************************************************** ' ' ' ' ' ' ' ' ' ' 。 ' ' ' ' '**************************************************************************** classname=Request.Querystring("classname") if instr(classname,"'") or instr(classname,"select") or instr(classname,"in") or instr(classname,"from") or instr(classname,"len") or instr(classname,"where") or instr(classname,"or") or instr(classname,"and") then Response.Write("") Response.End end if key=Request("key") if len(key)=0 then if classname="" or isnull(classname) then sql="select * from imgbook order by ID desc" else sql="select * from imgbook where classname='"&classname&"' order by ID desc" end if url="index.asp?classname=" & classname else sql="select * from imgbook where title like '%"&key&"%' and classname='"&classname&"' order by ID desc" url="index.asp?classname=" & classname &"&key=" & key end if %>
| |
|
|
| 版权所有:上海欧丹仪器电子有限公司 |