<%
dim user,pwd
user=Replace(Request("username"),"'","''")
pwd=Replace(Request("password"),"'","''")
Set conn=Server.CreateObject("ADODB.Connection")
conn.Open("Provider=Microsoft.Jet.OLEDB.4.0;Data Source=" & Server.MapPath("database/design.mdb"))
Set rs=Server.CreateObject("ADODB.Recordset")
sql="select * from admin where user='" & user & "'"
rs.open sql,conn,1,1
If rs.recordcount =1 Then
if rs(2) = pwd then
session("user")= rs(1)
session("pwd")=rs(2)
Response.redirect"admin/admin.asp"
else
response.write "用户名或密码错误, 请返回重新输入!"
end if
end if
rs.close
set rs=nothing
conn.close
set conn=nothing
%>