% ACCOUNT=REQUEST.FORM("ACCOUNT") '身份證字號 password=REQUEST.FORM("password") '密碼 account=replace(account,"'","") account = Replace(account, "|" ,"|") account = Replace(account, "<" ,"") account = Replace(account, ">" ,"") account = Replace(account, "%" ,"") account = Replace(account, "-" ,"") password=replace(password,"'","") password = Replace(password, "|" ,"|") password = Replace(password, "<" ,"") password = Replace(password, ">" ,"") password = Replace(password, "%" ,"") password = Replace(password, "-" ,"") %> <% IF ACCOUNT <>"" or PASSWORD <>"" THEN ' 查詢是否有此組身份證字號 & 密碼 登入在會員資料庫內 Set conn = Server.CreateObject("ADODB.Connection") DBPath = Server.MapPath("../members/members.mdb") conn.Open "driver={Microsoft Access Driver (*.mdb)};dbq=" & DBPath Set rsfound = Server.CreateObject("ADODB.Recordset") SQLSTR = "select * from 會員資料 where 帳號='"& account &"' and 密碼='"& password &"' order by id" rsfound.Open SQLSTR, conn,1,3 IF rsfound.eof then ' 查無此人 rsfound.close set conn = nothing Response.write "" Else ' 資料正確 level=Rsfound("狀態") Select case level case "0" ' 停權 session.abandon ' 清除記憶體中的 session 資料 Response.write "" response.write "" " response.write "" response.write "" response.write "" response.write "
" response.write "