SQL×¢Èë¹¥»÷µÄÔÀí¼°Æä·À·¶´ëÊ©
ת£ºhttp://blog.csdn.net/flyfranker/archive/2009/01/08/3733764.aspx
ASP±à³ÌÃż÷ºÜµÍ£¬ÐÂÊÖºÜÈÝÒ×ÉÏ·¡£ÔÚÒ»¶Î²»³¤µÄʱ¼äÀÐÂÊÖÍùÍù¾ÍÒѾÄܹ»±à³ö¿´À´±È½ÏÍêÃÀµÄ¶¯Ì¬ÍøÕ¾£¬ÔÚ¹¦ÄÜÉÏ£¬ÀÏÊÖÄÜ×öµ½µÄ£¬ÐÂÊÖÒ²Äܹ»×öµ½¡£ÄÇôÐÂÊÖÓëÀÏÊÖ¾ÍÃ»Çø±ðÁËÂð£¿ÕâÀïÃæÇø±ð¿É¾Í´óÁË£¬Ö»²»¹ýÍâÐÐÈ˺ÜÄÑÒ»Ñ۾Ϳ´³öÀ´°ÕÁË¡£ÔÚ½çÃæµÄÓѺÃÐÔ¡¢ÔËÐÐÐÔÄÜÒÔ¼°ÍøÕ¾µÄ°²È«ÐÔ·½ÃæÊÇÐÂÊÖÓëÀÏÊÖÖ®¼äÇø±ðµÄÈý¸ö¼¯Öе㡣¶øÔÚ°²È«ÐÔ·½Ã棬ÐÂÊÖ×îÈÝÒ׺öÂÔµÄÎÊÌâ¾ÍÊÇSQL×¢Èë©¶´µÄÎÊÌâ¡£ÓÃNBSI 2.0¶ÔÍøÉϵÄһЩASPÍøÕ¾ÉÔ¼ÓɨÃ裬¾ÍÄÜ·¢ÏÖÐí¶àASPÍøÕ¾´æÔÚSQL×¢Èë©¶´£¬½ÌÓýÍøÀï¸ßУÄÚ²¿»ú¹¹µÄÒ»Ð©ÍøÕ¾ÕâÖÖ©¶´¾Í¸üÆÕ±éÁË£¬¿ÉÄÜÕâÊÇÒòΪÕâÐ©ÍøÕ¾´ó¶¼ÊÇһЩѧÉú×öµÄÔµ¹Ê°É£¬ËäÈ»¸ö¸ö¶¼ºÜ´ÏÃ÷£¬¿ÉÊDZϾ¹Ã»ÓоÑ飬¶øÇÒ´¦ÓÚѧϰÖУ¬ÄÑÃâ©¶´¶à¶àÁË¡£±¾ÎÄÖ÷Òª½²½²SQL×¢ÈëµÄ·À·¶´ëÊ©£¬¶øÒªÃ÷°×ÕâЩ·À·¶´ëÊ©µÄÓô¦£¬ÐëÏÈÏêϸ½²½âÀûÓÃSQL×¢Èë©¶´ÈëÇֵĹý³Ì¡£ÐÂÊÖÃÇ¿´Ã÷°×À²¡£
¡¡¡¡Ï൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£ÈçÕâÊÇÒ»¸öÕý³£µÄÍøÖ·http://localhost/lawjia/show.asp?ID=444£¬½«Õâ¸öÍøÖ·Ìá½»µ½·þÎñÆ÷ºó£¬·þÎñÆ÷½«½øÐÐÀàËÆSelect * from ±íÃû where ×Ö¶Î="&IDµÄ²éѯ(ID¼´¿Í»§¶ËÌá½»µÄ²ÎÊý£¬±¾ÀýÊǼ´444)£¬ÔÙ½«²éѯ½á¹û·µ»Ø¸ø¿Í»§¶Ë£¬Èç¹ûÕâÀï¿Í»§¶Ë¹ÊÒâÌá½»Õâôһ¸öÍøÖ·£º
¡¡¡¡http://localhost/lawjia/show.asp?ID=444 and user>0£¬Õâʱ£¬·þÎñÆ÷ÔËÐÐSelect * from ±íÃû where ×Ö¶Î=444 and user>0ÕâÑùµÄ²éѯ£¬µ±È»£¬Õâ¸öÓï¾äÊÇÔËÐв»ÏÂÈ¥µÄ£¬¿Ï¶¨³ö´í£¬´íÎóÐÅÏ¢ÈçÏ£º
¡¡¡¡·´íÎóÀàÐÍ£º
Microsoft OLE DB Provider for ODBC Drivers (0x80040E07)
[Microsoft][ODBC SQL Server Driver][SQL Server]½« nvarchar Öµ 'sonybb' ת»»ÎªÊý¾ÝÀàÐÍΪ int µÄÁÐʱ·¢ÉúÓï·¨´íÎó¡£
/lawjia/show.asp, µÚ 47 ÐÐ
¡¡¡¡µ«ÊDZðÓÐÓÃÐĵÄÈË´ÓÕâ¸ö³ö´íÐÅÏ¢ÖУ¬¿ÉÒÔ»ñµÃÒÔÏÂÐÅÏ¢£º¸ÃվʹÓÃMS£ßSQLÊý¾Ý¿â£¬ÓÃODBCÁ¬½Ó£¬Á¬½ÓÕʺÅÃûΪ£ºsonybb¡£ËùνSQL×¢È루SQL Injection£©£¬¾ÍÊÇÀûÓóÌÐòÔ±¶ÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ¼ì²â²»ÑÏ»ò²»¼ì²âµÄÌØµã£¬¹ÊÒâ´Ó¿Í»§¶ËÌá½»ÌØÊâµÄ´úÂ룬´Ó¶øÊÕ¼¯³ÌÐò¼°·þÎñÆ÷µÄÐÅÏ¢£¬´Ó¶ø»ñÈ¡ÏëµÃµ½µÄ×ÊÁÏ¡£Í¨³£±ðÓÐÓÃÐÄÕßµÄÄ¿±êÊÇ»ñÈ¡ÍøÕ¾¹ÜÀíÔ±µÄÕʺźÍÃÜÂë¡£±ÈÈ統ij¸öÈËÖªµÀÍøÕ¾¹ÜÀíÔ±ÕʺŴæÔÚ±íloginÖУ¬¹ÜÀíÔ±ÕʺÅÃûΪadmin£¬ËûÏëÖªµÀ¹ÜÀíÔ±ÃÜÂ룬ÕâÀïËû´Ó¿Í»§¶Ë½Ó×ÅÌá½»ÕâÑùÒ»¸öÍøÖ
Ïà¹ØÎĵµ£º
update CHELIANG_MINGDAN set clmd_yunxuzaizhong = cast(clmd_yunxuzaizhong/1000 as decimal(14,4)) where clmd_yunxuzaizhong is not null
update CHELIANG_MINGDAN set clmd_carweight = cast(clmd_carweight/1000 as decimal(14,4)) where clmd_carweight is not null ......
SQLServerºÍOracleÊÇ´ó¼Ò¾³£Óõ½µÄÊý¾Ý¿â£¬Ôڴ˸Ðл×÷Õß×ܽá³öÕâЩ³£Óú¯ÊýÒÔ¹©´ó¼Ò²Î¿¼¡£
Êýѧº¯Êý£º
¡¡1.¾ø¶ÔÖµ
¡¡¡¡ S:SELECT abs(-1) value
¡¡¡¡ O:SELECT abs(-1) value from dual
2.È¡Õû(´ó)
¡¡¡¡ S:SELECT ceiling(-1.001) value
¡¡¡¡ O:SELECT ceil(-1.001) value from dual
3.È¡Õû£¨Ð¡£© ......
pl/sql ÌṩÁËÇ¿´ó¶øÁé»îµÄÊÖ¶ÎÀ´²¶×½ºÍ´¦Àí³ÌÐò²úÉúµÄÒì³££¬´Ó¶øÊ¹ oracle µÄÓû§Ô¶ÀëһЩÁîÈË·³ÄÕµÄ bug ¡£
pl/sql Òì³£´¦ÀíµÄ¸ÅÄîºÍÊõÓï
ÔÚ oracle ÖÐËùÓеĴíÎó¶¼±»ÈÏΪÊDz»Ó¦¸Ã·¢ÉúµÄÒì³£¡£Ò»¸öÒì³£¿ÉÄÜÊÇÒÔÏ 3 ÖÖÇé¿öµÄÒ»ÖÖ£º
u ÓÉϵͳ²úÉúµÄ´íÎó£¨& ......
¾¹ýºÃ¼¸ÌìµÄ·ÜÕ½£¬JDBCÖÕÓڳɹ¦Á¬½ÓÁËSQL Server 2000£¬ÆÚ¼ä×ßÁ˲»ÉÙÍä·£¬ÔÚÕâÀï·ÖÏíÎÒµÄÒ»µã¾Ñé
Ò»¡¢ÎҵĻ·¾³
Windows XP+JDK6u15+Microsoft SQL Server 2000£¨SP4£©+JCreator
ÎÒÏÈÔÚÍøÉÏÏÂÔØÊý¾Ý¿âÇý¶¯³ÌÐò£¬Ä¿Â¼ÏÂÓÐÈý¸ö°ümsbase.jar mssqlserver.jar msutil.jar
1 ......
General Overview
FeatureSQL Server 2008 (RC0)MySQL 5.1/6PostgreSQL 8.3/PostGIS 1.3/1.4
OS
Windows XP, Windows Vista, Windows 2003, Windows 2008
Windows XP, Windows Vista, (haven't tested on 2008), Linux, Unix, Mac
Windows 2000+ (including Vista and 2003, haven't tested on 2008), Linux, Unix, Ma ......