SQL×¢Èë½Ì³ÌÖ®ÈëÃÅÆª
Èë Êƪ
Èç¹ûÄãÒÔǰûÊÔ¹ýSQL×¢ÈëµÄ»°£¬ÄÇôµÚÒ»²½ÏȰÑIE²Ëµ¥=>¹¤¾ß=>InternetÑ¡Ïî=>¸ß¼¶=>ÏÔʾÓѺà HTTP ´íÎóÐÅÏ¢Ç°ÃæµÄ¹´È¥µô¡£·ñÔò£¬²»ÂÛ·þÎñÆ÷·µ»ØÊ²Ã´´íÎó£¬IE¶¼Ö»ÏÔʾΪHTTP 500·þÎñÆ÷´íÎ󣬲»ÄÜ»ñµÃ¸ü¶àµÄÌáʾÐÅÏ¢¡£
µÚÒ»½Ú¡¢SQL×¢ÈëÔÀí
ÒÔÏÂÎÒÃÇ´ÓÒ»¸öÍøÕ¾www.19cn.com¿ªÊ¼£¨×¢£º±¾ÎÄ·¢±íǰÒÑÕ÷µÃ¸ÃÕ¾Õ¾³¤Í¬Ò⣬´ó²¿·Ö¶¼ÊÇÕæÊµÊý¾Ý£©¡£
ÔÚÍøÕ¾Ê×Ò³ÉÏ£¬ÓÐÃûΪ“IE²»ÄÜ´ò¿ªÐ´°¿ÚµÄ¶àÖÖ½â¾ö·½·¨”µÄÁ´½Ó£¬µØÖ·Îª£ºhttp://www.19cn.com/showdetail.asp?id=49£¬ÎÒÃÇÔÚÕâ¸öµØÖ·ºóÃæ¼ÓÉϵ¥ÒýºÅ’£¬·þÎñÆ÷»á·µ»ØÏÂÃæµÄ´íÎóÌáʾ£º
Microsoft JET Database Engine ´íÎó '80040e14'
×Ö·û´®µÄÓï·¨´íÎó ÔÚ²éѯ±í´ïʽ 'ID=49'' ÖС£
/showdetail.asp£¬ÐÐ8
´ÓÕâ¸ö´íÎóÌáʾÎÒÃÇÄÜ¿´³öÏÂÃæ¼¸µã£º
1.ÍøÕ¾Ê¹ÓõÄÊÇAccessÊý¾Ý¿â£¬Í¨¹ýJETÒýÇæÁ¬½ÓÊý¾Ý¿â£¬¶ø²»ÊÇͨ¹ýODBC¡£
2.³ÌÐòûÓÐÅжϿͻ§¶ËÌá½»µÄÊý¾ÝÊÇ·ñ·ûºÏ³ÌÐòÒªÇó¡£
3.¸ÃSQLÓï¾äËù²éѯµÄ±íÖÐÓÐÒ»ÃûΪIDµÄ×ֶΡ£
´ÓÉÏÃæµÄÀý×ÓÎÒÃÇ¿ÉÒÔÖªµÀ£¬£Ó£Ñ£Ì×¢ÈëµÄÔÀí£¬¾ÍÊÇ´Ó¿Í»§¶ËÌá½»ÌØÊâµÄ´úÂ룬´Ó¶øÊÕ¼¯³ÌÐò¼°·þÎñÆ÷µÄÐÅÏ¢£¬´Ó¶ø»ñÈ¡ÄãÏëµ½µÃµ½µÄ×ÊÁÏ¡£
µÚ¶þ½Ú¡¢ÅжÏÄÜ·ñ½øÐУӣѣÌ×¢Èë
¿´ÍêµÚÒ»½Ú£¬ÓÐһЩÈË»á¾õµÃ£ºÎÒÒ²ÊǾ³£ÕâÑù²âÊÔÄÜ·ñ×¢ÈëµÄ£¬Õâ²»ÊǺܼòµ¥Âð£¿Æäʵ£¬Õâ²¢²»ÊÇ×îºÃµÄ·½·¨£¬ÎªÊ²Ã´ÄØ£¿
Ê×ÏÈ£¬²»Ò»¶¨Ã¿Ì¨·þÎñÆ÷µÄIIS¶¼·µ»Ø¾ßÌå´íÎóÌáʾ¸ø¿Í»§¶Ë£¬Èç¹û³ÌÐòÖмÓÁËcint(²ÎÊý)Ö®ÀàÓï¾äµÄ»°£¬£Ó£Ñ£Ì×¢ÈëÊDz»»á³É¹¦µÄ£¬µ«·þÎñÆ÷ͬÑù»á±¨´í£¬¾ßÌåÌáʾÐÅϢΪ´¦Àí URL ʱ·þÎñÆ÷Éϳö´í¡£ÇëºÍϵͳ¹ÜÀíÔ±ÁªÂç¡£
Æä´Î£¬²¿·Ö¶Ô£Ó£Ñ£Ì×¢ÈëÓÐÒ»µãÁ˽âµÄ³ÌÐòÔ±£¬ÈÏΪֻҪ°Ñµ¥ÒýºÅ¹ýÂ˵ô¾Í°²È«ÁË£¬ÕâÖÖÇé¿ö²»ÎªÉÙÊý£¬Èç¹ûÄãÓõ¥ÒýºÅ²âÊÔ£¬ÊDzⲻµ½×¢ÈëµãµÄ
ÄÇô£¬Ê²Ã´ÑùµÄ²âÊÔ·½·¨²ÅÊDZȽÏ×¼È·ÄØ£¿´ð°¸ÈçÏ£º
¢Ù http://www.19cn.com/showdetail.asp?id=49
¢Ú http://www.19cn.com/showdetail.asp?id=49 and 1=1
¢Û http://www.19cn.com/showdetail.asp?id=49 and 1=2
Õâ¾ÍÊǾµäµÄ1=1¡¢1=2²âÊÔ·¨ÁË£¬ÔõôÅжÏÄØ£¿¿´¿´ÉÏÃæÈý¸öÍøÖ··µ»ØµÄ½á¹û¾ÍÖªµÀÁË£º
¿ÉÒÔ×¢ÈëµÄ±íÏÖ£º
¢Ù Õý³£ÏÔʾ£¨ÕâÊDZØÈ»µÄ£¬²»È»¾ÍÊdzÌÐòÓдíÎóÁË£©
¢Ú Õý³£ÏÔʾ£¬ÄÚÈÝ»ù±¾Óë¢ÙÏàͬ
¢Û ÌáʾBOF»òEOF£¨³ÌÐòû×öÈκÎÅжÏʱ£©¡¢»òÌáʾÕÒ²»µ½¼Ç¼£¨ÅжÏÁËrs.eofʱ£©¡¢»òÏÔʾÄÚÈÝΪ¿Õ£¨³ÌÐò¼ÓÁËon error resume next£©
²»¿ÉÒÔ×¢Èë¾Í±È½ÏÈÝÒ×ÅжÏÁË£¬¢ÙͬÑùÕý³£ÏÔʾ£
Ïà¹ØÎĵµ£º
create proc dbo.PROC_SQL_COMP @sql1 varchar(8000),@sql2 varchar(8000),@t int
as
/*
µ÷Óãºexec dbo.PROC_SQL_COMP @sql1='',@sql2='',@t=5 & ......
1.±ÜÃâÔÚwhere×Ó¾äÖжÔ×Ö¶ÎÊ©¼Óº¯Êý£¬ÕâÑù½«µ¼ÖÂË÷ÒýʧЧ£¬±ÈÈ磺
select * from user where
to_char(create_time,'yyyymmdd')='20090101';
ÔÒò£ºÔÚ½¨Á¢indexµÄʱºòÊǸù¾Ý×Ö¶ÎÀ´½¨Á¢µÄ£¬Ò²¾ÍÊÇ˵oracleÔÚinidexµÄʱºòÊÇË÷ÒýµÄ×ֶεÄÖµ£¬Èç¹ûÌṩ¸øoracleµÄÊÇÒ»¸öÐèÒª¾¹ýº¯Êý´¦ÀíµÄ±È½Ï£¬oracle¾Íû°ì·¨Í¨¹ýË÷ÒýÖÐµÄ ......
µÚ1ÖÖ·½·¨£º
ÆóÒµ¹ÜÀíÆ÷
--¹ÜÀí
--ÓÒ¼üÊý¾Ý¿âά»¤¼Æ»®
--н¨Î¬»¤¼Æ»®
--<ÏÂÒ»²½>
--Ñ¡ÔñÄãÒª±¸·ÝµÄÊý¾Ý¿â
--<ÏÂÒ»²½>Ö±µ½"Ö¸¶¨Êý¾Ý¿â±¸·Ý¼Æ»®"ÕâÏî
--Ö¸¶¨´æ´¢±¸·ÝÎļþµÄλÖÃ,ÕâÀï¸ù¾ÝÐèҪѡÔñ±¸·Öµ½´Å´ø»¹ÊÇ´ÅÅÌ
--µ¥»÷µ÷¶ÈºóÃæµÄ"¸ü¸Ä"°´ ......
sql serverµÄËæ»úº¯ÊýnewID()ºÍRAND()¡¡¡¡
¡¡¡¡SELECT * from Northwind..Orders ORDER BY NEWID()
¡¡¡¡--Ëæ»úÅÅÐò
¡¡¡¡SELECT TOP 10 * from Northwind..Orders ORDER BY NEWID()
¡¡¡¡--´ÓOrders±íÖÐËæ»úÈ¡³ö10Ìõ¼Ç¼¡¡¡¡
¡¡¡¡Ê¾Àý¡¡¡¡
¡¡¡¡A.¶Ô±äÁ¿Ê¹Óà NEWID º¯Êý
¡¡¡¡ÒÔÏÂʾÀýʹÓà NEWID() ¶ÔÉùÃ÷Ϊ uniq ......
--½áºÏsys.indexesºÍsys.index_columns,sys.objects,sys.columns²éѯË÷ÒýËùÊôµÄ±í»òÊÓͼµÄÐÅÏ¢
select
o.name as ±íÃû,
i.name as Ë÷ÒýÃû,
c.name as ÁÐÃû,
i.type_desc as ÀàÐÍÃèÊö,
is_primary_key as Ö÷¼üÔ¼Êø,
is_unique_constraint as Î¨Ò»Ô¼Êø,
is_disable ......