Devi fare il replace dell'apice:
codice:
<%
Dim path, objCon, objRs, strSql2
path = "database.mdb"
Set objCon = Server.CreateObject("ADODB.Connection")
objCon.Open "DRIVER={Microsoft Access Driver (*.mdb)};DBQ=" & server.MapPath(path)
Set objRs = Server.CreateObject("ADODB.Recordset")
strSql2 = "SELECT username, email FROM utenti where username ='" & replace(request.form("username"), "'", "''") & "' or email ='" & replace(request.form("email"), "'", "''") & "'"
objRs.Open strSql2, objCon
if not objRs.EOF then
response.redirect("utko.asp")
objRs.Close
end if
%>