% option explicit Private edit,id,admin Dim MyConn, RS,RS1 %> <% if (Request.Form("username") <> "" and Request.Form("password") <> "") then edit = true Set MyConn = Server.CreateObject("ADODB.Connection") on error resume next MyConn.Open(session("connectionstring")) if Err.Number <> 0 then Err.Clear Response.write("DataBase Connection Error") Response.end end if on error goto 0 Set RS = MyConn.Execute("select id from clients where uname = '"&Request.Form("username")&"' and pass = '"&Request.Form("password")&"' and verified = 'yes'") if not RS.Bof and not RS.Eof then id = RS(0) end if elseif (Request.Cookies("wmadm") = "ok9" and Request.QueryString("id") <> "") then edit = true admin = true Set MyConn = Server.CreateObject("ADODB.Connection") on error resume next MyConn.Open(session("connectionstring")) if Err.Number <> 0 then Err.Clear Response.write("DataBase Connection Error") Response.end end if on error goto 0 id = Request.QueryString("id") Set RS = MyConn.Execute("select * from clients where id = -1") end if if edit then if (not RS.Bof and not RS.Eof) or admin then Set RS = MyConn.Execute("select name,url,street,town,postcode,telephone,fax,email,contactname,theposition,businesstype,suppliersof,caseclosure,preferredquantity,preferredlocationaldistribution,marketsandservices,specialistboxproducts,specialistmarkets,services,description,id,verified,printtype,county,country from clients where id = "&id) %>