Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

SQL×¢ÈëÒ»ÈÕͨ£¨Ï£©|Findnet.com.cn


Îå¡¢ÉÏ´«ASPľÂí
        ËùνASPľÂí£¬¾ÍÊÇÒ»¶ÎÓÐÌØÊ⹦ÄܵÄASP´úÂ룬²¢·ÅÈëWEBÐéÄâĿ¼µÄScriptsÏ£¬Ô¶³Ì¿Í»§Í¨¹ýIE¾Í¿ÉÖ´ÐÐËü£¬½ø¶øµÃµ½ÏµÍ³µÄUSERȨÏÞ£¬ÊµÏÖ¶ÔϵͳµÄ³õ²½¿ØÖÆ¡£ÉÏ´«ASPľÂíÒ»°ãÓÐÁ½ÖֱȽÏÓÐЧµÄ·½·¨£º
1¡¢ÀûÓÃWEBµÄÔ¶³Ì¹ÜÀí¹¦ÄÜ
        Ðí¶àWEBÕ¾µã£¬ÎªÁËά»¤µÄ·½±ã£¬¶¼ÌṩÁËÔ¶³Ì¹ÜÀíµÄ¹¦ÄÜ£»Ò²Óв»ÉÙWEBÕ¾µã£¬ÆäÄÚÈÝÊǶÔÓÚ²»Í¬µÄÓû§Óв»Í¬µÄ·ÃÎÊȨÏÞ¡£ÎªÁË´ïµ½¶ÔÓû§È¨Ï޵ĿØÖÆ£¬¶¼ÓÐÒ»¸öÍøÒ³£¬ÒªÇóÓû§ÃûÓëÃÜÂ룬ֻÓÐÊäÈëÁËÕýÈ·µÄÖµ£¬²ÅÄܽøÐÐÏÂÒ»²½µÄ²Ù×÷,¿ÉÒÔʵÏÖ¶ÔWEBµÄ¹ÜÀí£¬ÈçÉÏ´«¡¢ÏÂÔØÎļþ£¬Ä¿Â¼ä¯ÀÀ¡¢ÐÞ¸ÄÅäÖõȡ£
Òò´Ë£¬Èô»ñÈ¡ÕýÈ·µÄÓû§ÃûÓëÃÜÂ룬²»½ö¿ÉÒÔÉÏ´«ASPľÂí£¬ÓÐʱÉõÖÁÄܹ»Ö±½ÓµÃµ½USERȨÏÞ¶øä¯ÀÀϵͳ£¬ÉÏÒ»²½µÄ“·¢ÏÖWEBÐéÄâĿ¼”µÄ¸´ÔÓ²Ù×÷¶¼¿ÉÊ¡ÂÔ¡£
Óû§Ãû¼°ÃÜÂëÒ»°ã´æ·ÅÔÚÒ»ÕűíÖУ¬·¢ÏÖÕâÕÅ±í²¢¶ÁÈ¡ÆäÖÐÄÚÈݱã½â¾öÁËÎÊÌâ¡£ÒÔϸø³öÁ½ÖÖÓÐЧ·½·¨¡£
A¡¢ ×¢Èë·¨£º
´ÓÀíÂÛÉÏ˵£¬ÈÏÖ¤ÍøÒ³ÖлáÓÐÐÍÈ磺
select * from admin where username='XXX' and password='YYY' µÄÓï¾ä£¬ÈôÔÚÕýʽÔËÐд˾ä֮ǰ£¬Ã»ÓнøÐбØÒªµÄ×Ö·û¹ýÂË£¬ÔòºÜÈÝÒ×ʵʩSQL×¢Èë¡£
ÈçÔÚÓû§ÃûÎı¾¿òÄÚÊäÈ룺abc’ or 1=1--    ÔÚÃÜÂë¿òÄÚÊäÈ룺123   ÔòSQLÓï¾ä±ä³É£º
select * from admin where username='abc’ or 1=1 and password='123’  ²»¹ÜÓû§ÊäÈëÈκÎÓû§ÃûÓëÃÜÂ룬´ËÓï¾äÓÀÔ¶¶¼ÄÜÕýÈ·Ö´ÐУ¬Óû§ÇáÒׯ­¹ýϵͳ£¬»ñÈ¡ºÏ·¨Éí·Ý¡£
B¡¢²Â½â·¨£º
       »ù±¾Ë¼Â·ÊÇ£º²Â½âËùÓÐÊý¾Ý¿âÃû³Æ£¬²Â³ö¿âÖеÄÿÕűíÃû£¬·ÖÎö¿ÉÄÜÊÇ´æ·ÅÓû§ÃûÓëÃÜÂëµÄ±íÃû£¬²Â³ö±íÖеÄÿ¸ö×Ö¶ÎÃû£¬²Â³ö±íÖеÄÿÌõ¼Ç¼ÄÚÈÝ¡£
 ²Â½âËùÓÐÊý¾Ý¿âÃû ³Æ
HTTP://xxx.xxx.xxx/abc.asp?p=YY and (select count(*) from master.dbo.sysdatabases where name>1 and dbid=6) <>0    ÒòΪ dbid µÄÖµ´Ó1µ½5£¬ÊÇϵͳÓÃÁË¡£ËùÒÔÓû§×Ô¼º½¨µÄÒ»¶¨ÊÇ´Ó6¿ªÊ¼µÄ¡£²¢ÇÒÎÒÃÇÌá½»ÁË name>1 (name×Ö¶ÎÊÇÒ»¸ö×Ö·ûÐ͵Ä×ֶκÍÊý×ֱȽϻá³ö´í),abc.asp¹¤×÷Òì³££¬¿ÉµÃµ½µÚÒ»¸öÊý¾Ý¿âÃû£¬Í¬Àí°ÑDBID·Ö±ð¸Ä³É7,8£¬9,10,11,12…¾Í¿ÉµÃµ½ËùÓÐÊý¾Ý¿âÃû¡£
ÒÔϼÙÉèµÃµ½µÄÊý¾Ý¿âÃûÊÇTestDB¡£
 ²Â½âÊý¾Ý¿âÖÐÓû§Ãû ±íµÄÃû ³Æ
²Â½â·¨£º´


Ïà¹ØÎĵµ£º

sqlÓï¾ä×ܽá¶þ

sql¾«ÃîÓ÷¨
ÎÄÕ·ÖÀà:Êý¾Ý¿â
˵Ã÷£º¸´ÖƱí(Ö»¸´Öƽṹ,Ô´±íÃû£ºa бíÃû£ºb)
select * into b from a where 1<>1
˵Ã÷£º¿½±´±í(¿½±´Êý¾Ý,Ô´±íÃû£ºa Ä¿±ê±íÃû£ºb)
insert into b(a, b, c) select d,e,f from b;
˵Ã÷£ºÏÔʾÎÄÕ¡¢Ìá½»È˺Í×îºó»Ø¸´Ê±¼ä
select a.title,a.username,b.adddate ......

Sql(ÊÂÎï+Óαê)ʹÓ÷½·¨

--µ±Á½¸ö»òÁ½ÒÔÉϵIJÙ×÷Ҫô¶¼Ö´ÐУ¬ÒªÃ´¶¼²»Ö´ÐÐʱҪÓÃÊÂÎñ¡£
1. Sqlд·¨(ÊÂÎï+Óαê)
--¿ªÊ¼ÊÂÎñ
BEGIN TRAN
--²»ÏÔʾ¼ÆÊýÐÅÏ¢
SET NOCOUNT ON
DECLARE @ProjNo varchar(50),@CusNo varchar(50)
--ÉùÃ÷Óαê
DECLARE CRMPSContact_cursor CURSOR FOR 
SEL ......

ÔÚSQLÓï¾ä²éѯ½á¹ûÖмÓÈë×ÔÔö³¤ÁÐ

Óï¾ä£ºselect rank() over(Order By ±íµÄÖ÷¼ü Desc) As UID ,ÆäËûÁÐ from ±í
˵Ã÷£ºrankº¯Êý
×÷Óãº
·µ»ØÖ¸¶¨Ôª×éÔÚÖ¸¶¨¼¯ÖеÄÅÅÃû£¨ÅÅÃû´Ó 1 ¿ªÊ¼£©
Rank(Tuple_Expression, Set_Expression [ ,Numeric Expression ] )
²ÎÊý£º
Tuple_Expression
Ò»¸öÓÐЧµÄ¶àά±í´ïʽ (MDX) Ôª ......

SQL£­²éѯËùÓд¥·¢Æ÷

----²é¿´ËùÓнDZ¾
Create table #y (txt text)
select name, iid = identity(int,1,1) into #x from SysObjects where xtype = 'TR'
declare @i int, @max int
declare @name varchar(40)
set @i = 1
select @max = max(iid) from #x
while @i <= @max
begin
    select @name = name from #x w ......

SQL ServerÖйØÓÚµÄcheckpointʹÓÃ˵Ã÷

ÔÚSQL ServerÖÐÓÐÒ»¸ö·Ç³£ÖØÒªµÄÃüÁî¾ÍÊÇCheckPoint£¬ËüÖ÷Òª×÷ÓÃÊǰѻº´æÖеÄÊý¾ÝдÈëmdfÎļþÖС£
ÆäʵÔÚÎÒÃǽøÐÐinsert, update, deleteʱ£¬Êý¾Ý²¢Ã»ÓÐÖ±½ÓдÈëÊý¾Ý¿â¶ÔÓ¦µÄmdfÎļþÖУ¬¶øÊÇдÈëÁË»º´æÀÕâÓеãÏñµç¿£¬ÒòΪ¹ýÓÚÆµ·±µÄдÈë»áʹ´ÅÅ̵ÄÊÙÃü´ó´ó¼õС¡£
 
´ÓÉÏͼ¿ÉÒÔÖ±¹ÛµÄ¿´³ö¡£Ö»Óе±·¢Éúcheckpoint ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ