<% hap=0 for each name in Request.Form hap = hap + INSTR(1, Request.Form(name), "fuck",1) hap = hap + INSTR(1, Request.Form(name), "shit", 1) hap = hap + INSTR(1, Request.Form(name), "penis", 1) hap = hap + INSTR(1, Request.Form(name), "wank", 1) hap = hap + INSTR(1, Request.Form(name), "cunt", 1) hap = hap + INSTR(1, Request.Form(name), "bollock", 1) hap = hap + INSTR(1, Request.Form(name), "bastard", 1) hap = hap + INSTR(1, Request.Form(name), "pussy", 1) Next If hap > 0 Then Response.write "Thanks for your message, but we don't allow language like that!" Response.write "" Response.end End If %>
Message Added

Topic Listing

  <% comments = Request.Form("comments") name = Request.Form("name") email = Request.Form("email") If email="" then email="Not disclosed" subject = Request.Form("subject") name = REPLACE(name, "'", "'") email = REPLACE(email, "'", "'") subject = REPLACE(subject, "'", "'") comments = REPLACE(comments, "'", "'") name=REPLACE(name, "", " ") subject=REPLACE(subject, "", " ") email=REPLACE(email, "", " ") comments=REPLACE(comments, "", "") comments=REPLACE(comments, "<%", "") comments=REPLACE(comments, Chr(13), "
") if emotions=1 then %> <% end if Tp=Request.Form("TypeofPost") Select case Tp Case "New" MessageID="1" MessageNo=1 MyCols="[MessageID]" MyVals="'" & MessageID &"'" MySql="INSERT INTO threads (" & MyCols & ") VALUES (" & MyVals & ")" my_Conn.Execute MySql MySql="SELECT Max(threadID) AS themax FROM threads" Set RS = Server.CreateObject("ADODB.Recordset") RS.Open MySql, my_Conn threadID = RS("themax") Case "Reply" MySql="SELECT Max(MessageNo) AS themax FROM Messages Where ThreadID=" & Request.Form("ThreadID") Set RS = Server.CreateObject("ADODB.Recordset") RS.Open MySql, my_Conn MessageNo = RS("themax") + 1 MessageID=Request.Form("PrevID") & "." & MessageNo threadID=Request.Form("ThreadID") End Select RS.close %> <% MyCols="[MessageID],[ThreadID],[MessageNo], [Message],[Poster], [Posted], [Subject], [Email], [IP Address]" MyVals="'" & MessageID &"'," MyVals=MyVals & threadID &"," MyVals=MyVals & MessageNo & "," MyVals=MyVals & "'"&comments&"'," MyVals=MyVals & "'"&name&"'," subtime=Now MyVals=MyVals & "'"&subtime&"'," MyVals=MyVals & "'"&subject&"'," MyVals=MyVals & "'"&email&"'," MyVals=MyVals & "'"& request.servervariables("REMOTE_ADDR") & "'" MySql="INSERT INTO Messages (" & MyCols & ") VALUES (" & MyVals & ")" my_Conn.Execute MySql my_Conn.close Set my_Conn = Nothing %>

Thank you - your contribution has been added to the forum.

">Click here to return to the Message Board Topic Listing



 
 

  Copyright 2001. Band Marketing Today