<%
dim startime,endtime,db,squery,sURL,allquery
squery=lcase(Request.ServerVariables("QUERY_STRING"))
sURL=lcase(Request.ServerVariables("HTTP_HOST"))
allquery=squery+sURL
if InStr(allquery,"%20")<>0 or InStr(allquery,"%27")<>0 or InStr(allquery,"'")<>0 or InStr(allquery,"%a1a1")<>0 or InStr(allquery,"%24")<>0 or InStr(allquery,"$")<>0 or InStr(allquery,"%3b")<>0 or InStr(allquery,";")<>0 or InStr(allquery,":")<>0 or InStr(allquery,"%%")<>0 or InStr(allquery,"%3c")<>0 or InStr(allquery,"<")<>0 or InStr(allquery,">")<>0 or InStr(allquery,"--")<>0 or InStr(allquery,"sp_")<>0 or InStr(allquery,"xp_")<>0 or InStr(allquery,"exec")<>0 or InStr(allquery,"\")<>0 or InStr(allquery,"delete")<>0 or InStr(allquery,"dir")<>0 or InStr(allquery,"exe")<>0 or InStr(allquery,"select")<>0 or InStr(allquery,"Update")<>0 or InStr(allquery,"cmd")<>0 or InStr(allquery,"*")<>0 or InStr(allquery,",")<>0 or InStr(allquery,"^")<>0 or InStr(allquery,"(")<>0 or InStr(allquery,")")<>0 or InStr(allquery,"+")<>0 or InStr(allquery,"copy")<>0 or InStr(allquery,"format")<>0 or not(isnumeric(request("id"))) or not(isnumeric(request("xlbid"))) or not(isnumeric(request("page"))) then
response.Write("")
Response.write "参数错误"
response.Redirect("index.shtml")
Response.End
end if
startime=timer()
'更改数据库名字
dim conn
dim connstr,sysfilename
dim dbfile ,Password,Username,LocalName
sysfilename=""
dbfile = "ccwl001"
Password = "ccwl001aa"
Username = "ccwl001"
LocalName = "222.73.247.124"
set conn=Server.CreateObject("adodb.Connection")
Conn.Open "PROVIDER=SQLOLEDB.1;Data Source="&LocalName&";Initial Catalog="&dbfile&";Persist Security Info=True;User ID="&Username&";Password="&Password&";Connect Timeout=30"
function CloseDatabase
Conn.close
Set conn = Nothing
End Function
%>