<%@ Language=VBScript %> <% Option Explicit %> <% dim str,val ' ÇØÇÇÁ¤´åÄÄ Ãß°¡ 2008-05-27 function sqlCheck(str) val=UCASE(str) if instr(val, ";") <> 0 Or _ instr(val, "'") <> 0 Or _ instr(val, "--") <> 0 Or _ instr(val, "/*") <> 0 Or _ instr(val, "*/") <> 0 Or _ instr(val, "XP_") <> 0 Or _ instr(val, "DECLARE") <> 0 Or _ instr(val, "SELECT") <> 0 Or _ instr(val, "UPDATE") <> 0 Or _ instr(val, "DELETE") <> 0 Or _ instr(val, "INSERT") <> 0 Or _ instr(val, "SHUTDOWN") <> 0 Or _ instr(val, "DROP") <> 0 then ' response.write "¿À·ù¹ß»ý" response.Write("") response.End Else sqlCheck=str end if end function 'Dim idx : idx=sqlCheck(request("idx")) Dim NewGetTable , GetSeq Dim GetPage, GetSearchPart, GetSearchStr NewGetTable = "noticesofBoard1" GetSeq = sqlCheck(request("seq")) GetPage = sqlCheck(request("page")) GetSearchPart = sqlCheck(request("SearchPart")) GetSearchStr = sqlCheck(request("SearchStr")) '³»¿ë Ãâ·Â Sql = "select BD_SEQ, BD_THREAD , BD_DEPTH , BD_NAME, BD_EMAIL ,BD_SUBJECT, BD_CONTENT,BD_URL, BD_PASSWD , BD_INPUTDATE, BD_IP, BD_READCOUNT ,BD_STATE from " Sql = Sql & NewGetTable & " where BD_seq = " & GetSeq Set Rs = Con.Execute(Sql) Dim GetBD_SEQ : GetBD_SEQ = Rs(0) Dim GetBD_THREAD : GetBD_THREAD = Rs(1) Dim GetBD_DEPTH : GetBD_DEPTH = Rs(2) Dim GetBD_NAME : GetBD_NAME = Rs(3) Dim GetBD_EMAIL : GetBD_EMAIL = Rs(4) Dim GetBD_SUBJECT : GetBD_SUBJECT = Rs(5) Dim GetBD_CONTENT : GetBD_CONTENT = Rs(6) Dim GetBD_URL : GetBD_URL = Rs(7) Dim GetBD_BD_PASSWORD : GetBD_BD_PASSWORD = Rs(8) Dim GetBD_BD_INPUTDATE: GetBD_BD_INPUTDATE = Rs(9) Dim GetBD_BD_IP : GetBD_BD_IP = Rs(10) GetBD_BD_IP = left(GetBD_BD_IP,10) & "..." Dim GetBD_READCOUNT : GetBD_READCOUNT = Rs(11) Dim GetBS_STATE : GetBS_STATE = Rs(12) Rs.close 'ÆÄÀÏ Á¤º¸ Ãâ·Â Sql = "select FILE_SEQ , FILE_BD_SEQ, FILE_BD_TABLE , FILE_NAME , FILE_SIZE from "& NewGetTable &"_pds" Sql = Sql & " where FILE_BD_SEQ = " & GetBD_SEQ & " and FILE_BD_TABLE = '" & NewGetTable & "'" Set Rs = Con.Execute(Sql) Dim GetFILE_NAME , GetFILE_SIZE , GetFileImage if not (Rs.BOF or Rs.EOF) then GetFILE_NAME = ""&Rs(3) GetFILE_SIZE = Rs(4) GetFileImage = "" Else GetFILE_NAME = " ÆÄÀÏÀÌ ¾ø½À´Ï´Ù!" GetFILE_SIZE = " no" GetFileImage = " " end if Rs.close Sql = "update " & NewGetTable & " set BD_READCOUNT = BD_READCOUNT + 1 where BD_SEQ = " & GetSeq Con.Execute(Sql) %> PLM Best Practice Conference 2008 > PLM Community > °øÁö»çÇ×
ÇöÀçÀ§Ä¡ : HOME >PLM Community > °øÁö»çÇ×
 
Á¦¸ñ : <%= GetBD_SUBJECT %>
³¯Â¥ : <%= GetBD_BD_INPUTDATE %> Á¶È¸ : <%= GetBD_READCOUNT %>
<%= GetBD_CONTENT %>
ÀÛ¼ºÀÚ <%= GetBD_NAME %> ¸ÞÀÏ <%= GetBD_EMAIL %>
URL <%= GetBD_URL %> ÷ºÎÆÄÀÏ <%= GetFILE_NAME %> (<%= GetFILE_SIZE %> KByte)
<%if session("admin") = "administrator" then%> <% end if%> <%if session("admin") = "administrator" then%> <% else %> <% end if%>