统计在线人数...

Loveyukis BLOG漏洞补丁!

[ 来源:不详 | 作者:neeao | 时间:2004-12-15 20:38:20 | 浏览:统计中... ]


来自:情感联盟
作者:还用说啊!当然是xiaolu了!^_^
下面是源码!替换原来的即可!

<!--#include file="commond.asp" -->
<!--#include file="include/function.asp" -->
<!--#include file="include/upfile.asp" -->
<%On Error Resume Next%>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<style type="text/css">
<!--
body {
  font-size: 12px;
  font-family: Tahoma, Verdana, "宋体";
}
table {
  font-family: Tahoma, Verdana, "宋体";
  color: #000000;
  font-size: 12px;
  word-break : break-all ;
}
a:link,a:visited {
  text-decoration: none;
  color: #003366;
  font-family: Tahoma, Verdana, "宋体";
}
a:hover {
  text-decoration: none;
  color:#FF0000;
  font-family: Tahoma, Verdana, "宋体";
}
textarea,input,object  {
  font-family: Tahoma, Verdana, "宋体";
  font-size: 12px;
  color: #000000;
  font-weight: normal;
  background-color: #FFFFFF
}
-->
</style>
</head>
<body leftmargin="0" topmargin="0" marginwidth="0" marginheight="0">
<table width="100%" border="0" cellspacing="0" cellpadding="0" bgcolor="#FFFFFF">
<tr><%
Server.ScriptTimeOut = 999
IF memStatus="SupAdmin" OR memStatus="Admin" Then
  IF Request.QueryString("action")="upload" Then
    Response.Write("<td>")
    Dim FSO,FSOIsOK
    FSOIsOK=1
    Set FSO=Server.createObject("Scripting.FileSystemObject")
    If Err<>0 Then
      Err.Clear
      FSOIsOK=0
    End If
    Dim D_Name,F_Name
    If FSOIsOK=1 Then
      D_Name="month_"&DateToStr(Now(),"ym")
      If FSO.FolderExists(Server.MapPath("attachments/"&D_Name))=False Then
        FSO.createFolder Server.MapPath("attachments/"&D_Name)
      End If
    Else
      D_Name="All_Files"
    End If
    Set FSO=Nothing
    Dim FileUP
    Set FileUP=New Upload_File
    FileUP.GetDate(-1)
    Dim F_File,F_Type
    Set F_File=FileUP.File("File")
    F_Name=Generator(1)&Year(now)&Month(now)&Day(now)&Hour(now)&Minute(now)&Second(now)&"."&F_File.FileExt
    F_Type=Ucase(F_File.FileExt)
    IF F_File.FileSize > Int(UP_FileSize) Then
      Response.Write("<a href='javascript:history.go(-1);'>文件大小超出,请返回重新上传</a>")
    ElseIF IsvalidFile(F_Type) = False Then
      Response.Write("<a href='javascript:history.go(-1);'>文件格式非法,请返回重新上传</a>")
    Else
      F_File.SaveToFile Server.MapPath("attachments/"&D_Name&"/"&F_Name)
      select Case F_Type
      Case "GIF"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "JPG"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "JPEG"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "PNG"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "SWF"
        Response.Write("<SCRIPT>parent.input.message.value+='\n[swf]attachments/"&D_Name&"/"&F_Name&"[/swf]'</SCRIPT>")
      Case "WMA"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "MP3"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "MIDI"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "AVI"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "WMV"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "RA"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case "RM"
        Response.Write("<SCRIPT>parent.input.message.value+='\n
'</SCRIPT>")
      Case "RMVB"
        Response.Write("<SCRIPT>parent.input.message.value+='\n
'</SCRIPT>")
      Case "MOV"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</SCRIPT>")
      Case Else
        Response.Write("<SCRIPT>parent.input.message.value+='\n点击下载此文件'</SCRIPT>")
      End select
      Response.Write("<a href='javascript:history.go(-1);'>文件上传成功,请返回继续上传</a>")
    End IF
    Set F_File=Nothing
    Set FileUP=Nothing
    Response.Write("</td>")
  Else
    Response.Write("<form enctype=""multipart/form-data"" method=""post"" action=""attachment.asp?action=upload""><td><input name=""File"" type=""File"" size=""50""> <input type=""Submit"" name=""Submit"" value="" 确定上传 ""></td></form>")
  End IF
Else
  Response.Write("对不起,你没有权限上传附件!")
End If%></tr></table></body>
nput.message.value+='\n
attachments/"&D_Name&"/"&F_Name&"
'</SCRIPT>")
      Case "SWF"
        Response.Write("<SCRIPT>parent.input.message.value+='\n'</

[1] [2]  下一页

共有0人参与评价,平均得分:0分
评论内容只代表网友观点,与本站立场无关! 查看完整内容
   

当前在线人数
QQ:748838 MSN:allen_xia#msn.com E-mail:allenxia666#126.com QQ群:站长联盟北方区-北京(28200145) 站长联盟南方区-上海(67713522)