SQL×¢Èë¹¥»÷µÄÔÀí¼°Æä·À·¶´ëÊ©
ת£ºhttp://blog.csdn.net/flyfranker/archive/2009/01/08/3733764.aspx
ASP±à³ÌÃż÷ºÜµÍ£¬ÐÂÊÖºÜÈÝÒ×ÉÏ·¡£ÔÚÒ»¶Î²»³¤µÄʱ¼äÀÐÂÊÖÍùÍù¾ÍÒѾÄܹ»±à³ö¿´À´±È½ÏÍêÃÀµÄ¶¯Ì¬ÍøÕ¾£¬ÔÚ¹¦ÄÜÉÏ£¬ÀÏÊÖÄÜ×öµ½µÄ£¬ÐÂÊÖÒ²Äܹ»×öµ½¡£ÄÇôÐÂÊÖÓëÀÏÊÖ¾ÍÃ»Çø±ðÁËÂð£¿ÕâÀïÃæÇø±ð¿É¾Í´óÁË£¬Ö»²»¹ýÍâÐÐÈ˺ÜÄÑÒ»Ñ۾Ϳ´³öÀ´°ÕÁË¡£ÔÚ½çÃæµÄÓѺÃÐÔ¡¢ÔËÐÐÐÔÄÜÒÔ¼°ÍøÕ¾µÄ°²È«ÐÔ·½ÃæÊÇÐÂÊÖÓëÀÏÊÖÖ®¼äÇø±ðµÄÈý¸ö¼¯Öе㡣¶øÔÚ°²È«ÐÔ·½Ã棬ÐÂÊÖ×îÈÝÒ׺öÂÔµÄÎÊÌâ¾ÍÊÇSQL×¢Èë©¶´µÄÎÊÌâ¡£ÓÃNBSI 2.0¶ÔÍøÉϵÄһЩASPÍøÕ¾ÉÔ¼ÓɨÃ裬¾ÍÄÜ·¢ÏÖÐí¶àASPÍøÕ¾´æÔÚSQL×¢Èë©¶´£¬½ÌÓýÍøÀï¸ßУÄÚ²¿»ú¹¹µÄÒ»Ð©ÍøÕ¾ÕâÖÖ©¶´¾Í¸üÆÕ±éÁË£¬¿ÉÄÜÕâÊÇÒòΪÕâÐ©ÍøÕ¾´ó¶¼ÊÇһЩѧÉú×öµÄÔµ¹Ê°É£¬ËäÈ»¸ö¸ö¶¼ºÜ´ÏÃ÷£¬¿ÉÊDZϾ¹Ã»ÓоÑ飬¶øÇÒ´¦ÓÚѧϰÖУ¬ÄÑÃâ©¶´¶à¶àÁË¡£±¾ÎÄÖ÷Òª½²½²SQL×¢ÈëµÄ·À·¶´ëÊ©£¬¶øÒªÃ÷°×ÕâЩ·À·¶´ëÊ©µÄÓô¦£¬ÐëÏÈÏêϸ½²½âÀûÓÃSQL×¢Èë©¶´ÈëÇֵĹý³Ì¡£ÐÂÊÖÃÇ¿´Ã÷°×À²¡£
¡¡¡¡Ï൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£ÈçÕâÊÇÒ»¸öÕý³£µÄÍøÖ·http://localhost/lawjia/show.asp?ID=444£¬½«Õâ¸öÍøÖ·Ìá½»µ½·þÎñÆ÷ºó£¬·þÎñÆ÷½«½øÐÐÀàËÆSelect * from ±íÃû where ×Ö¶Î="&IDµÄ²éѯ(ID¼´¿Í»§¶ËÌá½»µÄ²ÎÊý£¬±¾ÀýÊǼ´444)£¬ÔÙ½«²éѯ½á¹û·µ»Ø¸ø¿Í»§¶Ë£¬Èç¹ûÕâÀï¿Í»§¶Ë¹ÊÒâÌá½»Õâôһ¸öÍøÖ·£º
¡¡¡¡http://localhost/lawjia/show.asp?ID=444 and user>0£¬Õâʱ£¬·þÎñÆ÷ÔËÐÐSelect * from ±íÃû where ×Ö¶Î=444 and user>0ÕâÑùµÄ²éѯ£¬µ±È»£¬Õâ¸öÓï¾äÊÇÔËÐв»ÏÂÈ¥µÄ£¬¿Ï¶¨³ö´í£¬´íÎóÐÅÏ¢ÈçÏ£º
¡¡¡¡·´íÎóÀàÐÍ£º
Microsoft OLE DB Provider for ODBC Drivers (0x80040E07)
[Microsoft][ODBC SQL Server Driver][SQL Server]½« nvarchar Öµ 'sonybb' ת»»ÎªÊý¾ÝÀàÐÍΪ int µÄÁÐʱ·¢ÉúÓï·¨´íÎó¡£
/lawjia/show.asp, µÚ 47 ÐÐ
¡¡¡¡µ«ÊDZðÓÐÓÃÐĵÄÈË´ÓÕâ¸ö³ö´íÐÅÏ¢ÖУ¬¿ÉÒÔ»ñµÃÒÔÏÂÐÅÏ¢£º¸ÃվʹÓÃMS£ßSQLÊý¾Ý¿â£¬ÓÃODBCÁ¬½Ó£¬Á¬½ÓÕʺÅÃûΪ£ºsonybb¡£ËùνSQL×¢È루SQL Injection£©£¬¾ÍÊÇÀûÓóÌÐòÔ±¶ÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ¼ì²â²»ÑÏ»ò²»¼ì²âµÄÌØµã£¬¹ÊÒâ´Ó¿Í»§¶ËÌá½»ÌØÊâµÄ´úÂ룬´Ó¶øÊÕ¼¯³ÌÐò¼°·þÎñÆ÷µÄÐÅÏ¢£¬´Ó¶ø»ñÈ¡ÏëµÃµ½µÄ×ÊÁÏ¡£Í¨³£±ðÓÐÓÃÐÄÕßµÄÄ¿±êÊÇ»ñÈ¡ÍøÕ¾¹ÜÀíÔ±µÄÕʺźÍÃÜÂë¡£±ÈÈ統ij¸öÈËÖªµÀÍøÕ¾¹ÜÀíÔ±ÕʺŴæÔÚ±íloginÖУ¬¹ÜÀíÔ±ÕʺÅÃûΪadmin£¬ËûÏëÖªµÀ¹ÜÀíÔ±ÃÜÂ룬ÕâÀïËû´Ó¿Í»§¶Ë½Ó×ÅÌá½»ÕâÑùÒ»¸öÍøÖ
Ïà¹ØÎĵµ£º
Sql Server ÖÐÒ»¸ö·Ç³£Ç¿´óµÄÈÕÆÚ¸ñʽ»¯º¯Êý
Select CONVERT(varchar(100), GETDATE(), 0): 05 16 2006 10:57AM
Select CONVERT(varchar(100), GETDATE(), 1): 05/16/06
Select CONVERT(varchar(100), GETDATE(), 2): 06.05.16
Select CONVERT(varchar(100), GETDATE(), 3): 16/05/06
Select CONVERT(varchar(100), GE ......
pl/sql ÌṩÁËÇ¿´ó¶øÁé»îµÄÊÖ¶ÎÀ´²¶×½ºÍ´¦Àí³ÌÐò²úÉúµÄÒì³££¬´Ó¶øÊ¹ oracle µÄÓû§Ô¶ÀëһЩÁîÈË·³ÄÕµÄ bug ¡£
pl/sql Òì³£´¦ÀíµÄ¸ÅÄîºÍÊõÓï
ÔÚ oracle ÖÐËùÓеĴíÎó¶¼±»ÈÏΪÊDz»Ó¦¸Ã·¢ÉúµÄÒì³£¡£Ò»¸öÒì³£¿ÉÄÜÊÇÒÔÏ 3 ÖÖÇé¿öµÄÒ»ÖÖ£º
u ÓÉϵͳ²úÉúµÄ´íÎó£¨& ......
×°ÁËSQL2000ºó°²×°SQL2005,ËäȻʹÓñðÃû¼ÓÒÔÇø±ðÁË£¬µ«·¢ÏÖ2005ÖÐûÓпɹ©·ÃÎʵÄÀàËÆÆóÒµ¹ÜÀíÆ÷£¬Ò»Ê±³å¶¯£¬Ð¶ÁË2000£¬ÍêÕû°²×°ÁË2005£¬·¢ÏÖ»¹ÊÇûÓÐÆóÒµ¹ÜÀíÆ÷£¬ËÑË÷¹ýºó²Å·¢ÏÖÐèÒª°²×°SQLServer2005_SSMSEE.msi£¨¼´SQLServerManagerStudioExpressEdition£©£¬ËüÌṩÁËÀàËÆÆóÒµ¹ÜÀíÆ÷µÄͼÐλ¯²Ù×÷½çÃæ¡£
×°ºÃºó£¬SQL ......
ÈÕÖ¾´«ËÍÊÇSQL SERVER2000ÆóÒµ°æ½øÐÐË«»úÈȱ¸µÄÒ»¸öÖ÷Òª½â¾ö·½°¸£¬ÆäÔÀí±È½Ï¼òµ¥£¬ÊµÏÖÒ²±È½Ï·½±ã£¬Ö»ÊÇÓÉÓÚºÍWindowsÖ®¼ä´í×Û¸´ÔӵĹØÏµ£¬µ¼ÖÂÉèÖÃÆðÀ´Óв»ÉÙÀ§ÄÑ£¬³öÏÖÎÊÌâÒ²²»ÈÝÒ×Õï¶Ï¡£
1.ʵÏÖ¸ÅÊö
*Ë«»úÈȱ¸Õë¶ÔµÄÊǾßÌåµÄij¸öÊý¾Ý¿â¶ø²»ÊÇÕû¸ö·þÎñÆ÷
Ë«» ......
ÔÚijЩ³¡ºÏÏ£¬´æ´¢¹ý³Ì»ò´¥·¢Æ÷ÀïµÄSQLÓï¾äÐèÒª¶¯Ì¬Éú³É¡£OracleµÄDBMS_SQL°ü¿ÉÒÔÓÃÀ´Ö´Ðж¯Ì¬SQLÓï¾ä¡£±¾ÎÄͨ¹ýÒ»¸ö¼òµ¥µÄÀý×ÓÀ´Õ¹Ê¾ÈçºÎÀûÓÃDBMS_SQL°üÖ´Ðж¯Ì¬SQLÓï¾ä£º
DECLARE
v_cursor NUMBER;
v_stat NUMBER;
& ......