% Option Explicit %>
<%
Dim DBC,conn
Set DBC = new databaseclass
Set Conn = DBC.openconnection()
Dim I,RsConfigObj
Set RsConfigObj = Conn.Execute("Select SiteName,UserConfer,Copyright,isEmail,isChange,IsShop from FS_Config")
Set DBC = Nothing
%>
<%
If Request.Form("action")="add" then
If Replace(Replace(Replace(request.form("Title"),"'",""),"\",""),"/","")="" or request.form("Content")="" then
Response.Write("")
Response.End
End if
If Replace(Replace(Replace(request.form("Author"),"'",""),"\",""),"/","")="" or request.form("addr")="" then
Response.Write("")
Response.End
End if
Dim Rs,Sql1,ClassID
Set Rs = server.createobject(G_FS_RS)
Sql1 = "select * from FS_Contribution1 where 1=0"
Rs.open sql1,conn,1,3
Rs.addnew
Rs("ContID") = GetRandomID18()
Rs("Title")=NoCSSHackInput(Replace(Replace(Replace(request.form("Title"),"'",""),"\",""),"/",""))
If Replace(request.form("SubTitle"),"'","")<>"" then
Rs("SubTitle")=NoCSSHackInput(Replace(request.form("SubTitle"),"'",""))
End if
Rs("Content")=NoCSSHackContent(Request.Form("Content"))
Rs("AddTime")=Now()
Rs("KeyWords")=NoCSSHackInput(Replace(request.form("KeyWords"),"'",""))
Rs("Author")=NoCSSHackInput(Replace(Request.Form("Author"),"'",""))
Rs("email")=NoCSSHackInput(Replace(Request.Form("email"),"'",""))
Rs("danwei")=NoCSSHackInput(Replace(Request.Form("danwei"),"'",""))
Rs("addr")=NoCSSHackInput(Replace(Request.Form("addr"),"'",""))
Rs("phone")=NoCSSHackInput(Replace(Request.Form("phone"),"'",""))
Rs.update
Response.Write("")
Response.End
Rs.close()
Set rs=nothing
End If
%>