%
dim rs,sql
dim qs,errc,iii
qs=request.servervariables("query_string")
dim nothis(18)
nothis(0)="net user"
nothis(1)="xp_cmdshell"
nothis(2)="/add"
nothis(3)="exec%20master.dbo.xp_cmdshell"
nothis(4)="net localgroup administrators"
nothis(5)="select"
nothis(6)="count"
nothis(7)="asc"
nothis(8)="char"
nothis(9)="mid"
nothis(10)="'"
nothis(11)=":"
nothis(12)=""""
nothis(13)="insert"
nothis(14)="delete"
nothis(15)="drop"
nothis(16)="truncate"
nothis(17)="from"
nothis(18)="%"
errc=false
for iii= 0 to ubound(nothis)
if instr(qs,nothis(iii))<>0 then
errc=true
end if
next
if errc then
Response.Write("对不起,非法URL地址请求!")
response.end
end if
%>
<%
set rs=server.CreateObject("adodb.recordset")
sql="select top 1 * from news where img<>''and hot=1 order by newsid desc"
rs.open sql,conn,1,1
if rs.eof or rs.bof then
%>
暂时没有图片
<%
else
'do while not (rs.eof or rs.bof)
if len(month(rs("dt")))<2 then
mydate=year(rs("dt"))&"0"&month(rs("dt"))
else
mydate=year(rs("dt"))&month(rs("dt"))
end if
%>
<%
set rs=server.CreateObject("adodb.recordset")
sql="select top 3 * from news where hot=5 order by newsid desc"
rs.open sql,conn,1,1
do while not (rs.eof or rs.bof)
'dt=rs("dt")
if len(month(rs("dt")))<2 then
mydate=year(rs("dt"))&"0"&month(rs("dt"))
else
mydate=year(rs("dt"))&month(rs("dt"))
end if
%>
<%
set rs=server.CreateObject("adodb.recordset")
sql="select top 8 * from news where bClassid=5 and classid=19 and hot<>5 order by newsid desc"
rs.open sql,conn,1,1
do while not (rs.eof or rs.bof)
dim mydate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
mydate=year(rs("dt"))&"0"&month(rs("dt"))
else
mydate=year(rs("dt"))&month(rs("dt"))
end if
dim olddate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
olddate=year(rs("dt"))&"-"&"0"&month(rs("dt"))
else
olddate=year(rs("dt"))&"-"&month(rs("dt"))
end if
dim newdate
'dt=rs("dt")
if len(DAY(rs("dt")))<2 then
newdate=olddate&"-"&"0"&DAY(rs("dt"))
else
newdate=olddate&"-"&DAY(rs("dt"))
end if
%>
<%
set rs=server.CreateObject("adodb.recordset")
sql="select top 7 * from news where bClassid=7 and classid=22 order by newsid desc"
rs.open sql,conn,1,1
do while not (rs.eof or rs.bof)
'dt=rs("dt")
if len(month(rs("dt")))<2 then
mydate=year(rs("dt"))&"0"&month(rs("dt"))
else
mydate=year(rs("dt"))&month(rs("dt"))
end if
%>
<%
set rs=server.CreateObject("adodb.recordset")
sql="select top 8 * from news where bClassid=11 and classid=34 order by newsid desc"
rs.open sql,conn,1,1
do while not (rs.eof or rs.bof)
'dim mydate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
mydate=year(rs("dt"))&"0"&month(rs("dt"))
else
mydate=year(rs("dt"))&month(rs("dt"))
end if
'dim olddate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
olddate=year(rs("dt"))&"-"&"0"&month(rs("dt"))
else
olddate=year(rs("dt"))&"-"&month(rs("dt"))
end if
'dim newdate
'dt=rs("dt")
if len(DAY(rs("dt")))<2 then
newdate=olddate&"-"&"0"&DAY(rs("dt"))
else
newdate=olddate&"-"&DAY(rs("dt"))
end if
%>
<%
set rs=server.CreateObject("adodb.recordset")
sql="select top 8 * from news where bClassid=6 and classid=20 order by newsid desc"
rs.open sql,conn,1,1
do while not (rs.eof or rs.bof)
'dim mydate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
mydate=year(rs("dt"))&"0"&month(rs("dt"))
else
mydate=year(rs("dt"))&month(rs("dt"))
end if
'dim olddate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
olddate=year(rs("dt"))&"-"&"0"&month(rs("dt"))
else
olddate=year(rs("dt"))&"-"&month(rs("dt"))
end if
' dim newdate
'dt=rs("dt")
if len(DAY(rs("dt")))<2 then
newdate=olddate&"-"&"0"&DAY(rs("dt"))
else
newdate=olddate&"-"&DAY(rs("dt"))
end if
%>
<%
set rs=server.CreateObject("adodb.recordset")
sql="select top 8 * from news where bClassid=12 and classid=35 order by newsid desc"
rs.open sql,conn,1,1
do while not (rs.eof or rs.bof)
'dim mydate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
mydate=year(rs("dt"))&"0"&month(rs("dt"))
else
mydate=year(rs("dt"))&month(rs("dt"))
end if
'dim olddate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
olddate=year(rs("dt"))&"-"&"0"&month(rs("dt"))
else
olddate=year(rs("dt"))&"-"&month(rs("dt"))
end if
' dim newdate
'dt=rs("dt")
if len(DAY(rs("dt")))<2 then
newdate=olddate&"-"&"0"&DAY(rs("dt"))
else
newdate=olddate&"-"&DAY(rs("dt"))
end if
%>
<%
if len(rs("title"))>12 then
response.write left(rs("title"),12)&".."
else
response.write (rs("title"))
end if
%>
<%=newdate%>
<%
set rs=server.CreateObject("adodb.recordset")
sql="select top 8 * from news where bClassid=9 order by newsid desc"
rs.open sql,conn,1,1
do while not (rs.eof or rs.bof)
'dim mydate
'dt=rs("dt")
if len(month(rs("dt")))<2 then
mydate=year(rs("dt"))&"0"&month(rs("dt"))
else
mydate=year(rs("dt"))&month(rs("dt"))
end if
%>