ÌÔÌØAsp Cms5.5(Sp2)°æÃâ·ÑÏÂÔØ
ÏÂÔØµØÖ·£º/download/rar/tot-cms-5.5(sp2).rar
꿅᣼http://www.totcms.com/html/200910-30/20091030001212.htm
¸üÐÂ˵Ã÷£º
1¡¢Ôö¼ÓÁË×Ô¶¨Ò庯Êý¹¦ÄÜ£¬Ö»Òª¹ÜÀíÔ±ÊìϤSQL²éѯ£¬¾Í¿ÉÒÔʹÓÃÆÕͨSQLÓï·¨²éѯÊý¾Ý¿âÉú³Éǰ̨¾²Ì¬HTM¼Ç¼¡£
2¡¢ÎÄÕÂÌí¼Ó²ÉÈ¡Á½¼¶Ä¿Â¼±£´æ£¬²»ÊÇʹÓÃÔÀ´µÄÈý²ãĿ¼·½Ê½¡£
3¡¢½â¾öÐ޸ıêǩʱ·ÖÀ಻ÄÜÏÔʾÔÀ´·ÖÀàµÄÎÊÌâ¡£
4¡¢ÐÞ¸ÄwapÊÖ»ú·ÃÎÊʱÂÒÂëµÄÎÊÌâ
5¡¢ÐÞ¸ÄÉú³ÉSiteMapÔÚÌá½»µ½Google³ö´íµÄÎÊÌâ
6¡¢ÐÞ¸ÄĬÈÏ2009Ä£°åÖеÄ·¾¶ÎªÏà¶Ô·¾¶£¬·½±ã¹ÜÀíÔ±×ªÒÆ×ª»»ÓòÃû¡£
7¡¢Ð޸ĻñÈ¡×ÓÀ¸Ä¿±êÇ©Éú³ÉHTM´úÂëÖÐA±ê¼ÇµÄ´íÎóÓï·¨¡£
¸½£º×Ô¶¨Ò庯Êý˵Ã÷
·×Ô¶¨Ò庯Êý˵Ã÷
Ìí¼Óº¯Êý£º
Ìí¼Ó×Ô¶¨Ò庯Êýʱ£¬ÐèҪעÒ⓺¯ÊýÃû×Ö”Ö»ÄÜʹÓÃÓ¢ÎÄ×Öĸ»òÊý×Ö¡£
º¯ÊýÄÚÈÝÊÇÖ¸ÒªÖ´ÐвéѯµÄSQLÓï¾ä£¬¿ÉÒÔÔÚ±àдµÄʱºò£¬Ê¹ÓÓ²âÊÔSql”°´Å¥²âÊÔ²éѯµÄ·´Ó³½á¹û¼¯¡£
Ìí¼Ó±êÇ©£º
¼ÙÈçÎÒÃÇÌí¼ÓÁËÒ»¸ö×Ô¶¨Ò庯Êý£¬ÆäÖУº
º¯ÊýÃû£ºTot_Func
º¯ÊýÄÚÈÝ£ºSELECT TOP 10 id,pagepath,title from news ORDER BY id DESC
ÄÇôÎÒÃÇ¿ÉÒÔÉè¼ÆÒÔϱêÇ©£º
<ul>
$Sub[Tot_Func]$
<li>$1<a href="$2">$3</a></li>
$End$
</ul>
±êǩ˵Ã÷£º
$Sub[Tot_Func]$´ú±íº¯ÊýÖ´ÐпªÊ¼£¬ÆäÖеÄTot_FuncΪÎÒÃǺǫ́Ìí¼ÓµÄº¯ÊýÃû³Æ
ÆäÖеÄ$1£¬$2£¬$3·Ö±ð´ú±íÎÒÃÇÌí¼Óº¯ÊýʱµÄº¯ÊýÄÚÈÝ(Ò²¾ÍÊÇSql²éѯÓï¾ä)Öзµ»ØµÄ×ֶΡ£$1´ú±íµÚÒ»¸ö×Ö¶ÎÒ²¾ÍÊÇid,$2´ú±íµÚ¶þ¸ö×Ö¶Îpagepath,$3´ú±íµÚÈý¸ö×Ö¶Îtitle
$End$´ú±íº¯ÊýÖ´ÐнáÊø
http://www.totcms.com
Ïà¹ØÎĵµ£º
<%
if Request.QueryString("pageNo")="" then
PageNo=1
elseif IsNumeric(Request.QueryString("pageNo"))=false then
PageNo=1
else
PageNo=clng(Request.QueryString("pageNo"))
end if
´ò¿ªÊý¾Ý±í..²»Ð´Á˹þ.
set rs=server.CreateObject("adodb.recordset")
sql="............"
rs.open sql, ......
ASPµ÷Óô洢¹ý³ÌµÄ·½·¨£º
---- ¡¡¡¡µ÷Óô洢¹ý³ÌµÄ·½·¨ÐèҪʹÓÃADOµÄCommand¶ÔÏó¡£Command¶ÔÏóÊǶÔÒ»¸öÊý¾ÝÔ´ÔËÐÐÌØ¶¨ÃüÁîµÄ¶¨Ò壨ÀýÈ磬һ¸öSQL²éѯ»òÒ»¸öSQL´æ´¢¹ý³Ì£©¡£ÏÂÃæÒÔMS SQL SERVER6.5Ϊºǫ́Êý¾Ý¿â£¬½éÉÜASPµ÷Óô洢¹ý³ÌµÄ·½·¨¡£
---- ¡ ......
public void Gridview_BindNoRecords(GridView gridView, DataTable dt) // gridView£¬°ó¶¨Êý¾ÝÔ´DT
{
int a = dt.Rows.Count;
if (dt.Rows.Count == 0)
& ......
<%
Dim Fy_Url,Fy_a,Fy_x,Fy_Cs(),Fy_Cl,Fy_Ts,Fy_Zx
'---¶¨Ò岿·Ý Í·------
Fy_Cl = 1 '´¦Àí·½Ê½£º1=ÌáʾÐÅÏ¢,2=תÏòÒ³Ãæ,3=ÏÈÌáʾÔÙתÏò
Fy_Zx = "Error.Asp" '³ö´íʱתÏòµÄÒ³Ãæ
'---¶¨Ò岿·Ý β------
On Error Resume Next
Fy_Url=Request.ServerVariables("QUER ......
ÏÖÔڱȽÏÁ÷ÐеÄSQL×¢È빤¾ßµÄ¹¤×÷·½Ê½ÊÇͨ¹ýGETºÍPOSTÀ´Íê³É¾ßÌåµÄ×¢Èë¡£ÎÒÃÇ¿ÉÒÔ½«×¢ÈëʱËùÓõ½µÄÒ»ÇзûºÅ¹ýÂ˵ô¡£ÄÇôÎÒÃÇ¿ÉÒÔͨ¹ý¼òµ¥µÄÅжÏÓï¾äÀ´´ïµ½Ä¿µÄ¡£ÎÒÃÇÏÈÀ´¹ýÂËGET°É¡£
´úÂëÈçÏ£º
dim sql_injdata SQL_inj SQL_Get
SQL_injdata = "’|and|exec|insert|select|delete|update|count|*|%|chr|mid|mast ......