<% If Trim(Request.Form("fName")) = "" OR Trim(Request.Form("lName")) = "" OR Trim(Request.Form("middleSchool")) = "" OR Trim(Request.Form("highSchool")) = "" OR Trim(Request.Form("guardian")) = "" OR Trim(Request.Form("phone")) = "" OR Trim(Request.Form("email")) = "" Then response.redirect("index.htm") Else ' Store into an array --------------------------------------// ' it's a cheat patch but it fixes the sql injection issue for now... old school escaping the quote mark Dim fValues(7) fValues(0) = replace(request("fName"), "'", "''") fValues(1) = replace(request("lName"), "'", "''") fValues(2) = replace(request("middleSchool"), "'", "''") fValues(3) = replace(request("highSchool"), "'", "''") fValues(4) = replace(request("guardian"), "'", "''") fValues(5) = replace(request("phone"), "'", "''") fValues(6) = replace(request("email"), "'", "''") fValues(0) = trim(fValues(0)) fValues(1) = trim(fValues(1)) fValues(2) = trim(fValues(2)) fValues(3) = trim(fValues(3)) fValues(4) = trim(fValues(4)) fValues(5) = trim(fValues(5)) fValues(6) = trim(fValues(6)) dim strbody strbody="Thank you for submitting your request. The lottery drawing will take place on February 4, 2019." & vbNewLine & "
" strbody=strbody & "First Name" & ": " & fValues(0) & vbNewLine & "
" strbody=strbody & "Last Name" & ": " & fValues(1) & vbNewLine & "
" strbody=strbody & "Student's Current Middle School" & ": " & fValues(2) & vbNewLine & "
" strbody=strbody & "Student's Zoned High School" & ": " & fValues(3) & vbNewLine & "
" strbody=strbody & "Parent/Guardian" & ": " & fValues(4) & vbNewLine & "
" strbody=strbody & "Phone Number" & ": " & fValues(5) & vbNewLine & "
" strbody=strbody & "Email" & ": " & fValues(6) & vbNewLine & "
" Dim sch, cdoConfig, cdoMessage sch = "http://schemas.microsoft.com/cdo/configuration/" Set cdoMessage = CreateObject("CDO.Message") With cdoMessage .Configuration.Fields.Item ("http://schemas.microsoft.com/cdo/configuration/sendusing")=2 '# Name or IP of remote SMTP server #' .Configuration.Fields.Item ("http://schemas.microsoft.com/cdo/configuration/smtpserver")="10.215.2.132" '# Server port .Configuration.Fields.Item ("http://schemas.microsoft.com/cdo/configuration/smtpserverport")=25 .Configuration.Fields.Update '# Set .Configuration = cdoConfig .From = "admin@douglas.k12.ga.us" .CC = Trim(Request.Form("email")) .To = "Gary.Morris@douglas.k12.ga.us" .Subject = "CCI Cohort Registration" .HTMLBody = strBody .Send End With Set cdoMessage = Nothing Set cdoConfig = Nothing dim objConn, objRS, sConn set objConn = server.createObject("adodb.connection") sConn = "Provider=SQLOLEDB.1;Data Source=UTILITY7;Initial Catalog=OnlineCourseRequest;uid=OnLnCR;pwd=star@6Y;" objConn.connectionstring = sConn '- Open Connection Ojbect -' objConn.Open sql="INSERT INTO CCIReg (fName, lName, middleSchool,highSchool,guardian,phone, email)" sql=sql & " VALUES " sql=sql & "('" & fValues(0) & "'," sql=sql & "'" & fValues(1) & "'," sql=sql & "'" & fValues(2) & "'," sql=sql & "'" & fValues(3) & "'," sql=sql & "'" & fValues(4) & "'," sql=sql & "'" & fValues(5) & "'," sql=sql &"'"&fValues(6)&"')" ' response.Write SQL 'on error resume next ObjConn.Execute sql ObjConn.Close %> CCI Cohort Registration
Douglas County School System

CCI 9th Grade Cohort Registration

<% Response.Write "

" + strbody %>

<% End If %>