%@LANGUAGE="VBSCRIPT"%> <% path=request.servervariables("appl_physical_path") set objcon1=server.createObject("ADODB.Connection") objcon1.open "dsn=adstechsql","ads","adspassword" 'MM_objConnection_STRING = "dsn=adstechsql;uid=ads;password=" Dim objRS__MMColParam objRS__MMColParam = "1" if (Request.QueryString("pid") <> "") then objRS__MMColParam = Request.QueryString("pid") objRS__MMColParam = stripQuotes(objRS__MMColParam) objRS__MMColParam = killChars(objRS__MMColParam) end if %> <% pid=request.queryString("pid") pid = stripQuotes(pid) pid = killChars(pid) set objRS = Server.CreateObject("ADODB.Recordset") objRS.ActiveConnection = objcon1 objRS.Source = "SELECT * FROM dbo.product WHERE product_id = '" + Replace(objRS__MMColParam, "'", "''") + "'" objRS.CursorType = 0 objRS.CursorLocation = 2 objRS.LockType = 3 objRS.Open() objRS_numRows = 0 %> <% set objbullet = Server.CreateObject("ADODB.Recordset") objbullet.ActiveConnection = objcon1 objbullet.Source = "SELECT * FROM dbo.bullet" objbullet.CursorType = 0 objbullet.CursorLocation = 2 objbullet.LockType = 3 objbullet.Open() objbullet_numRows = 0 %> <% Dim objacc__MMColParam objacc__MMColParam = "1" if (Request.QueryString("pid") <> "") then objacc__MMColParam = Request.QueryString("pid") objacc__MMColParam = stripQuotes(objacc__MMColParam) objacc__MMColParam = killChars(objacc__MMColParam) end if %> <% set objacc = Server.CreateObject("ADODB.Recordset") objacc.ActiveConnection = objcon1 objacc.Source = "SELECT * FROM dbo.accessories WHERE product_id = '" + Replace(objacc__MMColParam, "'", "''") + "'" objacc.CursorType = 0 objacc.CursorLocation = 2 objacc.LockType = 3 objacc.Open() objacc_numRows = 0 %> <% Dim objupgrades__MMColParam objupgrades__MMColParam = "1" if (Request.QueryString("pid") <> "") then objupgrades__MMColParam = Request.QueryString("pid") objupgrades__MMColParam = stripQuotes(objupgrades__MMColParam) objupgrades__MMColParam = killChars(objupgrades__MMColParam) end if %> <% set objupgrades = Server.CreateObject("ADODB.Recordset") objupgrades.ActiveConnection = objcon1 objupgrades.Source = "SELECT * FROM dbo.upgrades WHERE product_id = '" + Replace(objupgrades__MMColParam, "'", "''") + "'" objupgrades.CursorType = 0 objupgrades.CursorLocation = 2 objupgrades.LockType = 3 objupgrades.Open() objupgrades_numRows = 0 %>