% option explicit %> <% if request("username")<>"" and request("userpassword")<>"" then dim name dim pwd dim sql dim rs name=request.form("username") pwd=request.form("userpassword") if instr(name,"'")<>0 or instr(pwd,"'")<>0 then response.redirect "login.asp" response.end end if set rs = server.createobject("adodb.recordset") sql="select * from users where name='" & name & "' and pwd='" & pwd & "'" rs.open sql,conn,1,1 if err.number <> 0 then response.write "数据库操作失败:"&err.description response.end else if not rs.eof and not rs.bof then session("purview")=rs("purview") session("name")=rs("name") response.redirect "/xinwen1/admin/index.asp" end if end if rs.close set rs=nothing end if %>