asp.netÖеĵݹéÑ»·ÎÊÌ⣡¼±
asp.netÖеĵݹéÑ»·ÎÊÌ⣡¼±
string newstr = "";
public string showtreenume_danye(int tids, string tbname, string objurl, int steeps)
{
string sql_danye = "select tname,id,tn from " + tbname + " where tn=" + tids + " order by px asc";
fx_DataReader dr_danye = new fx_DataReader(sql_danye);
while (dr_danye.Read())
{
if (tids == 0)
{
newstr = newstr + "a.add(" + (Convert.ToInt32(dr_danye["id"]) + Convert.ToInt32(steeps)) + ",0,'" + dr_danye["tname"] + "','" + objurl + dr_danye["id"] + "');\n";
}
else
{
newstr = newstr + "a.add(" + (Convert.ToInt32(dr_danye["id"]) + Convert.ToInt32(steeps)) + "," + (Convert.ToInt32(dr_danye["tn"]) + Convert.ToInt32(steeps)) + ",'" + dr_danye["tname"] + "','" + objurl + dr_
Ïà¹ØÎÊ´ð£º
aspÏÂÃæ£¬µ±Òª¸ù¾Ý²»Í¬µÄȨÏÞÏÔʾһЩ¹¦Äܰ´Å¥µÄ»°»áд³É
<%
if ȨÏÞ=1 then
%>
<input type="submit" name="Submit" value="Ìá½»" />
<%
end i ......
RT¡£ºÜ¶àµØÖ·¶¼´ò²»¿ª»ò²»ÄÜÏÂÔØÁË
ÓÐ×ÊÔ´µÄÅóÓѸø¸öµØÖ·¡£¡£Ö»ÒªÏÂÔØºóÊÇÎÒÏëÒªµÄÄÚÈÝ 50·ÖÏ×ÉÏ!
лл!
ɳ·¢ÎÒÏÈ×ø!
°ï¶¥
°ï¶¥
ûÌý˵¹ýŶ
JF
ºÃÏñ19ûÓе쬲»È«¡£
ºÃ¶à¼¯¶¼²»ÄÜÏ¡£¡£
......
°ÑÒµÎñ²ãµÄ¶¼Ð´ÔÚdllÎļþÖÐÁË£¬ÏÖÔÚÏëÒªÐ޸쬴ó¼Ò¶¼ÓÃʲô¹¤¾ß´ò¿ª£¿
ÓÃvisual studio×Ô´øµÄ ildasm¿ÉÒÔÂð£¿
ÆÚ´ý¸ßÊÖ
LZºÃÀ÷º¦
Ó÷´±àÒëÈí¼þ
ÎÒÓÃReflectorÖ»ÄÜ¿´£¬²»Äܸİ¡£¿
ÓÐÃ ......
ÔÚµ¯³ö¿òÖеã»÷Ò»¸ö°´Å¥£¬Ôõôµ÷תµ½ÁíÒ»¸öä¯ÀÀÆ÷£¬²¢ÇÒÔÚ¸Ãä¯ÀÀÆ÷´ò¿ªÁ½¸öÒ³Ãæ
ÄãµÄÒâ˼Ӧ¸ÃÊÇ
response.write("<script>alert('È·ÈÏ'); window.location.href('xxxx.aspx'); </script>"); ......