<%@ Language=VBScript %> <% Option Explicit %> <% dim hp_local hp_local = "conference_news" dim str,val ' 해피정닷컴 추가 2008-05-27 function sqlCheck(str) val=UCASE(str) if instr(val, ";") <> 0 Or _ instr(val, "'") <> 0 Or _ instr(val, "--") <> 0 Or _ instr(val, "/*") <> 0 Or _ instr(val, "*/") <> 0 Or _ instr(val, "XP_") <> 0 Or _ instr(val, "DECLARE") <> 0 Or _ instr(val, "SELECT") <> 0 Or _ instr(val, "UPDATE") <> 0 Or _ instr(val, "DELETE") <> 0 Or _ instr(val, "INSERT") <> 0 Or _ instr(val, "SHUTDOWN") <> 0 Or _ instr(val, "DROP") <> 0 then ' response.write "오류발생" response.Write("") response.End Else sqlCheck=str end if end function 'Dim idx : idx=sqlCheck(request("idx")) Dim NewGetTable , GetSeq Dim GetPage, GetSearchPart, GetSearchStr NewGetTable = "mechBoard" GetSeq = sqlCheck(request("seq")) GetPage = sqlCheck(request("page")) GetSearchPart = sqlCheck(request("SearchPart")) GetSearchStr = sqlCheck(request("SearchStr")) '내용 출력 Sql = "select BD_SEQ, BD_THREAD , BD_DEPTH , BD_NAME, BD_EMAIL ,BD_SUBJECT, BD_CONTENT,BD_URL, BD_PASSWD , BD_INPUTDATE, BD_IP, BD_READCOUNT ,BD_STATE from " Sql = Sql & NewGetTable & " where BD_seq = " & GetSeq Set Rs = Con.Execute(Sql) Dim GetBD_SEQ : GetBD_SEQ = Rs(0) Dim GetBD_THREAD : GetBD_THREAD = Rs(1) Dim GetBD_DEPTH : GetBD_DEPTH = Rs(2) Dim GetBD_NAME : GetBD_NAME = Rs(3) Dim GetBD_EMAIL : GetBD_EMAIL = Rs(4) Dim GetBD_SUBJECT : GetBD_SUBJECT = Rs(5) Dim GetBD_CONTENT : GetBD_CONTENT = Rs(6) Dim GetBD_URL : GetBD_URL = Rs(7) Dim GetBD_BD_PASSWORD : GetBD_BD_PASSWORD = Rs(8) Dim GetBD_BD_INPUTDATE: GetBD_BD_INPUTDATE = Rs(9) Dim GetBD_BD_IP : GetBD_BD_IP = Rs(10) GetBD_BD_IP = left(GetBD_BD_IP,10) & "..." Dim GetBD_READCOUNT : GetBD_READCOUNT = Rs(11) Dim GetBS_STATE : GetBS_STATE = Rs(12) Rs.close '파일 정보 출력 Sql = "select FILE_SEQ , FILE_BD_SEQ, FILE_BD_TABLE , FILE_NAME , FILE_SIZE from "& NewGetTable &"_pds" Sql = Sql & " where FILE_BD_SEQ = " & GetBD_SEQ & " and FILE_BD_TABLE = '" & NewGetTable & "'" Set Rs = Con.Execute(Sql) Dim GetFILE_NAME , GetFILE_SIZE , GetFileImage if not (Rs.BOF or Rs.EOF) then GetFILE_NAME = ""&Rs(3) GetFILE_SIZE = Rs(4) GetFileImage = "" Else GetFILE_NAME = " 파일이 없습니다!" GetFILE_SIZE = " no" GetFileImage = " " end if Rs.close Sql = "update " & NewGetTable & " set BD_READCOUNT = BD_READCOUNT + 1 where BD_SEQ = " & GetSeq Con.Execute(Sql) %> <% dim hp_title %> <%=hp_title%> > CAD/CAM Conference > 관련기사
제목 : <%= GetBD_SUBJECT %>
날짜 : <%= GetBD_BD_INPUTDATE %> 조회 : <%= GetBD_READCOUNT %>
<%= GetBD_CONTENT %>
작성자 <%= GetBD_NAME %> 메일 <%= GetBD_EMAIL %>
URL <%= GetBD_URL %> 첨부파일 <%= GetFILE_NAME %> (<%= GetFILE_SIZE %> KByte)
<%if session("admin") = "administrator" then%> <% end if%> <%if session("admin") = "administrator" then%> <% else %> <% end if%>