SQL ServerÈÕÆÚ¼ÆËã
ͨ³££¬ÄãÐèÒª»ñµÃµ±Ç°ÈÕÆÚºÍ¼ÆËãһЩÆäËûµÄÈÕÆÚ£¬ÀýÈ磬ÄãµÄ³ÌÐò¿ÉÄÜÐèÒªÅжÏÒ»¸öÔµĵÚÒ»Ìì»òÕß×îºóÒ»Ìì¡£ÄãÃǴ󲿷ÖÈË´ó¸Å¶¼ÖªµÀÔõÑù°ÑÈÕÆÚ½øÐзָÄê¡¢Ô¡¢Èյȣ©£¬È»ºó½ö½öÓ÷ָî³öÀ´µÄÄê¡¢Ô¡¢ÈյȷÅÔÚ¼¸¸öº¯ÊýÖмÆËã³ö×Ô¼ºËùÐèÒªµÄÈÕÆÚ£¡ÔÚÕâÆªÎÄÕÂÀÎÒ½«¸æËßÄãÈçºÎʹÓÃDATEADDºÍDATEDIFFº¯ÊýÀ´¼ÆËã³öÔÚÄãµÄ³ÌÐòÖпÉÄÜÄãÒªÓõ½µÄһЩ²»Í¬ÈÕÆÚ¡£
ÔÚʹÓñ¾ÎÄÖеÄÀý×Ó֮ǰ£¬Äã±ØÐë×¢ÒâÒÔϵÄÎÊÌâ¡£´ó²¿·Ö¿ÉÄܲ»ÊÇËùÓÐÀý×ÓÔÚ²»Í¬µÄ»úÆ÷ÉÏÖ´ÐеĽá¹û¿ÉÄܲ»Ò»Ñù£¬ÕâÍêÈ«ÓÉÄÄÒ»ÌìÊÇÒ»¸öÐÇÆÚµÄµÚÒ»ÌìÕâ¸öÉèÖþö¶¨¡£µÚÒ»Ì죨DATEFIRST£©É趨¾ö¶¨ÁËÄãµÄϵͳʹÓÃÄÄÒ»Ìì×÷ΪһÖܵĵÚÒ»Ìì¡£ËùÓÐÒÔϵÄÀý×Ó¶¼ÊÇÒÔÐÇÆÚÌì×÷ΪһÖܵĵÚÒ»ÌìÀ´½¨Á¢£¬Ò²¾ÍÊǵÚÒ»ÌìÉèÖÃΪ7¡£¼ÙÈçÄãµÄµÚÒ»ÌìÉèÖò»Ò»Ñù£¬Äã¿ÉÄÜÐèÒªµ÷ÕûÕâЩÀý×Ó£¬Ê¹ËüºÍ²»Í¬µÄµÚÒ»ÌìÉèÖÃÏà·ûºÏ¡£Äã¿ÉÒÔͨ¹ý@@DATEFIRSTº¯ÊýÀ´¼ì²éµÚÒ»ÌìÉèÖá£
ΪÁËÀí½âÕâЩÀý×Ó£¬ÎÒÃÇÏȸ´Ï°Ò»ÏÂDATEDIFFºÍDATEADDº¯Êý¡£DATEDIFFº¯Êý¼ÆËãÁ½¸öÈÕÆÚÖ®¼äµÄСʱ¡¢Ìì¡¢ÖÜ¡¢Ô¡¢ÄêµÈʱ¼ä¼ä¸ô×ÜÊý¡£DATEADDº¯Êý¼ÆËãÒ»¸öÈÕÆÚͨ¹ý¸øÊ±¼ä¼ä¸ô¼Ó¼õÀ´»ñµÃÒ»¸öеÄÈÕÆÚ¡£ÒªÁ˽â¸ü¶àµÄDATEDIFFºÍDATEADDº¯ÊýÒÔ¼°Ê±¼ä¼ä¸ô¿ÉÒÔÔĶÁ΢ÈíÁª»ú°ïÖú¡£
ʹÓÃDATEDIFFºÍDATEADDº¯ÊýÀ´¼ÆËãÈÕÆÚ£¬ºÍ±¾À´´Óµ±Ç°ÈÕÆÚת»»µ½ÄãÐèÒªµÄÈÕÆÚµÄ¿¼ÂÇ·½·¨Óе㲻ͬ¡£Äã±ØÐë´Óʱ¼ä¼ä¸ôÕâ¸ö·½ÃæÀ´¿¼ÂÇ¡£±ÈÈ磬´Óµ±Ç°ÈÕÆÚµ½ÄãÒªµÃµ½µÄÈÕÆÚÖ®¼äÓжàÉÙʱ¼ä¼ä¸ô£¬»òÕߣ¬´Ó½ñÌ쵽ijһÌ죨±ÈÈç1900-1-1£©Ö®¼äÓжàÉÙʱ¼ä¼ä¸ô£¬µÈµÈ¡£Àí½âÔõÑù×ÅÑÛÓÚʱ¼ä¼ä¸ôÓÐÖúÓÚÄãÇáËɵÄÀí½âÎҵIJ»Í¬µÄÈÕÆÚ¼ÆËãÀý×Ó¡£
Ò»¸öÔµĵÚÒ»Ìì
µÚÒ»¸öÀý×Ó£¬ÎÒ½«¸æËßÄãÈçºÎ´Óµ±Ç°ÈÕÆÚÈ¥Õâ¸öÔµÄ×îºóÒ»Ìì¡£Çë×¢Ò⣺Õâ¸öÀý×ÓÒÔ¼°ÕâÆªÎÄÕÂÖÐµÄÆäËûÀý×Ó¶¼½«Ö»Ê¹ÓÃDATEDIFFºÍDATEADDº¯ÊýÀ´¼ÆËãÎÒÃÇÏëÒªµÄÈÕÆÚ¡£Ã¿Ò»¸öÀý×Ó¶¼½«Í¨¹ý¼ÆË㵫ǰµÄʱ¼ä¼ä¸ô£¬È»ºó½øÐмӼõÀ´µÃµ½ÏëÒª¼ÆËãµÄÈÕÆÚ¡£
ÕâÊǼÆËãÒ»¸öÔµÚÒ»ÌìµÄSQL ½Å±¾£º
SELECT DATEADD(mm, DATEDIFF(mm,0,getdate()), 0)
&n
Ïà¹ØÎĵµ£º
ϵͳ»·¾³£ºWindows 7
Èí¼þ»·¾³£ºVisual C++ 2008 SP1 +SQL Server 2005
±¾´ÎÄ¿µÄ£º±àдһ¸öº½¿Õ¹ÜÀíϵͳ
ÕâÊÇÊý¾Ý¿â¿Î³ÌÉè¼ÆµÄ³É¹û£¬ËäÈ»³É¼¨²»¼Ñ£¬µ«ÊÇ×÷ΪÎÒÓÃVC++ ÒÔÀ´±àдµÄ×î´ó³ÌÐò»¹ÊÇ´«µ½ÍøÉÏ£¬ÒÔ¹©²Î¿¼¡£ÓÃVC++ ×öÊý¾Ý¿âÉè¼Æ²¢²»ÈÝÒ×£¬µ«Ò²²»ÊDz»¿ÉÄÜ¡£ÒÔÏÂÊÇÎҵijÌÐò½çÃæ£¬ºóÃæ ......
1.²éѯµÄÄ£ºýÆ¥Åä
¾¡Á¿±ÜÃâÔÚÒ»¸ö¸´ÔÓ²éѯÀïÃæÊ¹Óà LIKE '%parm1%'—— ºìÉ«±êʶλÖõİٷֺŻᵼÖÂÏà¹ØÁеÄË÷ÒýÎÞ·¨Ê¹Óã¬×îºÃ²»ÒªÓÃ.
½â¾ö°ì·¨:
ÆäʵֻÐèÒª¶Ô¸Ã½Å±¾ÂÔ×ö¸Ä½ø£¬²éѯËٶȱã»áÌá¸ß½ü°Ù±¶¡£¸Ä½ø·½·¨ÈçÏ£º
a¡¢ÐÞ¸Äǰ̨³ÌÐò——°Ñ²éѯÌõ¼þµÄ¹©Ó¦ÉÌÃû³ÆÒ»À¸ÓÉÔÀ´µÄÎı¾ÊäÈë¸ÄΪÏÂÀÁб ......
1¡¢¼ì²éÊÇ·ñÓзǷ¨×Ö·û
public static boolean sql_inj(String str)
{
String inj_str = "'|and|exec|insert|select|delete|update|
count|*|%|chr|mid|master|truncate|char|declare|;|or|-|+|,";
//ÕâÀïµÄ¶«Î÷»¹¿ÉÒÔ×Ô¼ºÌí¼Ó
String[] inj_stra=inj_str.split("\\|");
for ......
Ò»¡¢SQLƴд½¨Òé 1¡¢²éѯʱ²»·µ»Ø²»ÐèÒªµÄÐС¢ÁÐ ÒµÎñ´úÂëÒª¸ù¾Ýʵ¼ÊÇé¿ö¾¡Á¿¼õÉÙ¶Ô±íµÄ·ÃÎÊÐÐÊý£¬×îС»¯½á¹û¼¯£¬ÔÚ²éѯʱ£¬²»Òª¹ý¶àµØÊ¹ÓÃͨÅä·ûÈ磺select * from table1Óï¾ä£¬ÒªÓõ½¼¸ÁоÍÑ¡Ôñ¼¸ÁУ¬È磺select col1,col2 from table1;ÔÚ¿ÉÄܵÄÇé¿öϾ¡Á¿ÏÞÖÆ½á¹û¼¯ÐÐÊýÈ磺se ......
----²é¿´ËùÓнDZ¾
Create table #y (txt text)
select name, iid = identity(int,1,1) into #x from SysObjects where xtype = 'TR'
declare @i int, @max int
declare @name varchar(40)
set @i = 1
select @max = max(iid) from #x
while @i <= @max
begin
select @name = name from #x w ......