%
'------------------sql zhuru
'-----------防注入代码----------------
'--------定义部份------------------
'Dim Fy_Post,Fy_Get,Fy_In,Fy_Inf,Fy_Xh,Fy_db,Fy_dbstr
'自定义需要过滤的字串,用 "|||" 分隔
Fy_In = "'|||;|||and|||exec|||insert|||select|||delete|||update|||count|||*|||%|||chr|||mid|||master|||truncate|||char|||declare"
'----------------------------------
Fy_Inf = split(Fy_In,"|||")
'--------POST部份------------------
If Request.Form<>"" Then
For Each Fy_Post In Request.Form
For Fy_Xh=0 To Ubound(Fy_Inf)
If Instr(LCase(Request.Form(Fy_Post)),Fy_Inf(Fy_Xh))<>0 Then
response.redirect "http://www.it168.com"
End If
Next
Next
End If
'----------------------------------
'--------GET部份-------------------
If Request.QueryString<>"" Then
For Each Fy_Get In Request.QueryString
For Fy_Xh=0 To Ubound(Fy_Inf)
If Instr(LCase(Request.QueryString(Fy_Get)),Fy_Inf(Fy_Xh))<>0 Then
response.redirect "http://www.it168.com"
End If
Next
Next
End If
''''''''''-----------sql end
%>
<%
adoconn15
keyword=replacestr(request("keyword"))
%>
<%
sqlstr= "select id,cname,cinstro,cinput_date from tbl_soft_sky where c2='1' and c3='1' and c5<>'' "
if keyword<>"" then
sqlstr=sqlstr &" and cname like '"& keyword &"' "
end if
sqlstr=sqlstr&" order by id desc"
udc_rs.open sqlstr,udc_conn,3
if udc_rs.eof then
response.write "没有演示软件。"
else
udc_rs.pagesize=10
icount=udc_rs.recordcount
pages=(udc_rs.pagesize+icount-1)\udc_rs.pagesize
page=request("page")
if page=0 then page=1
udc_rs.absolutepage=page
k=0
while not udc_rs.eof and k