<%if request("cmd")="" then%>
<%'防止SQL注入
Function ReqNum ( StrName )
ReqNum = Request ( StrName )
if Not isNumeric ( ReqNum ) then
Response.Write "参数必须为数字型!"
Response.End
End if
End Function
Function ReqStr ( StrName )
ReqStr = Replace ( Request(StrName), "'", "''" )
End Function
sql="select * from feedback order by id DESC "
set rs=server.createobject("adodb.recordset")
rs.open sql,conn,1,3
IF Not rs.eof Then
proCount=rs.recordcount
rs.PageSize=20 '定义显示数目
if not IsEmpty(Request("ToPage")) then
ToPage=CInt(Request("ToPage"))
if ToPage>rs.PageCount then
rs.AbsolutePage=rs.PageCount
intCurPage=rs.PageCount
elseif ToPage<=0 then
rs.AbsolutePage=1
intCurPage=1
else
rs.AbsolutePage=ToPage
intCurPage=ToPage
end if
else
rs.AbsolutePage=1
intCurPage=1
end if
intCurPage=CInt(intCurPage)
For i = 1 to rs.PageSize
if rs.EOF then
Exit For
end if
%>
" target="_blank"><%=rs("name")%> 于 <%=FormatDateTime(rs("time"),2)%> 提交的留言:<%if Request("faq")="admin" then%> 管理操作: " onClick="return confirm('\n请确认要删除【<%=rs("name")%>】的留言吗?\n\n点击“取消”按钮可以终止本次操作。\n\n警告:本操作执行后数据不可恢复!\n\n')">删除 / ">回复
<%end if%>
<%if rs("huifu")<>"" or rs("huifu")<>null then%>
<%=rs("all")%>
回复:<%=rs("huifu")%>
<%else%>
<%end if%>
<%
rs.MoveNext
next
%>
<%
else
%>
目前还没有人留言。
<%
end if
rs.close
set rs=nothing
%>
<%elseif request("cmd")="hui" then
set rs=server.createobject("adodb.recordset")
id=Request.QueryString("id")
if id="" or id=null then
Il ""
Response.End()
end if
sql="select * from feedback where id="&id
set rs = conn.execute(sql)
%>
<%end if%>