Set conn = CreateObject("ADODB.Connection")
conn.Open "Provider=SQLNCLI;Server=127.0.0.1;Database=XXX;Uid=sa;Pwd=sa;"
Admin = Trim(Request.Form("Admin"))
Pass = Md5(Trim(Request.Form("Pass")))
sql = "SELECT * FROM AdminData WHERE Name=? AND Pass=?"
Set cmd = CreateObject("ADODB.Command")
Set cmd.ActiveConnection = conn
cmd.CommandText = sql
cmd.CommandType = 1
cmd.Prepared = True
Set prm = cmd.CreateParameter("Name", 200, 1, 50, Admin)
cmd.Parameters.Append prm
Set prm = cmd.CreateParameter("Pass", 200, 1, 50, Pass)
cmd.Parameters.Append prm
Set rs = CreateObject("ADODB.RecordSet")
rs.CursorLocation = 3
rs.Open cmd, , 1, 3
If rs.BOF And rs.EOF Then
rs.close
Set rs = Nothing
conn.Open "Provider=SQLNCLI;Server=127.0.0.1;Database=XXX;Uid=sa;Pwd=sa;"
Admin = Trim(Request.Form("Admin"))
Pass = Md5(Trim(Request.Form("Pass")))
sql = "SELECT * FROM AdminData WHERE Name=? AND Pass=?"
Set cmd = CreateObject("ADODB.Command")
Set cmd.ActiveConnection = conn
cmd.CommandText = sql
cmd.CommandType = 1
cmd.Prepared = True
Set prm = cmd.CreateParameter("Name", 200, 1, 50, Admin)
cmd.Parameters.Append prm
Set prm = cmd.CreateParameter("Pass", 200, 1, 50, Pass)
cmd.Parameters.Append prm
Set rs = CreateObject("ADODB.RecordSet")
rs.CursorLocation = 3
rs.Open cmd, , 1, 3
If rs.BOF And rs.EOF Then
rs.close
Set rs = Nothing