ÓÃSQLÉú³ÉÁ÷Ë®ºÅ
ÓÃSQLÉú³ÉÁ÷Ë®ºÅ
ת£ºÎ¤½ÌÎ ·¢±íÓÚ2010Äê02ÔÂ03ÈÕ 09:38 ÔĶÁ(4) ÆÀÂÛ(0)
if exists (select * from dbo.sysobjects where id = object_id(N'[dbo].[fn_FillNumberWithZero]') and xtype in (N'FN', N'IF', N'TF'))
drop function [dbo].[fn_FillNumberWithZero]
GO
if exists (select * from dbo.sysobjects where id = object_id(N'[dbo].[fn_FormatDate]') and xtype in (N'FN', N'IF', N'TF'))
drop function [dbo].[fn_FormatDate]
GO
if exists (select * from dbo.sysobjects where id = object_id(N'[dbo].[fn_GetNewFlowNumber]') and xtype in (N'FN', N'IF', N'TF'))
drop function [dbo].[fn_GetNewFlowNumber]
GO
if exists (select * from dbo.sysobjects where id = object_id(N'[dbo].[fn_GetNowDate]') and xtype in (N'FN', N'IF', N'TF'))
drop function [dbo].[fn_GetNowDate]
GO
SET QUOTED_IDENTIFIER OFF
GO
SET ANSI_NULLS OFF
GO
/*
Éú³ÉÁ÷Ë®ºÅºóÃæ¼¸Î»Êý×Ö×Ö·ûµÄÏà¹Øº¯Êý
²»×ãλÊýÔÚ×ó±ßÓÃ0Ìî³ä
*/
CREATE FUNCTION dbo.fn_FillNumberWithZero
(
--Ìî³äµÄÊý×Ö
@num int,
--×ÜλÊý
@len int
)
RETURNS varchar(50) AS
BEGIN
--Èç¹û´«ÈëµÄÁ÷Ë®ºÅ´óÓÚ×ܵij¤¶È£¬ÄÇôֱ½Ó·µ»ØÁ÷Ë®ºÅ×Ö·û´®¸ñʽ
if(len(Convert(varchar(50),@num))>@len)
return Convert(varchar(50),@num)
ELSE
BEGIN
--ÐèÒªÌî³ä0µÄλÊý
declare @NeedFillLen int
set @NeedFillLen=@Len-len(Convert(varchar(50),@num))
--»ñÈ¡ÐèÒªÌî³äµÄ0µÄ×Ö·û´®
declare @i int
set @i=0
declare @temp varchar(50)
set @temp=N''
while @i<@NeedFillLen
BEGIN
SET @temp=@temp+'0'
SET @i=@i+1
END
--·µ»Ø×éºóµÄ×Ö·û´®
return @temp+Convert(varchar(50),@num)
END
return ''
END
GO
SET QUOTED_IDENTIFIER OFF
GO
SET ANSI_NULLS ON
GO
SET QUOTED_IDENTIFIER OFF
GO
Ïà¹ØÎĵµ£º
ÔÚ.Net Framework 3.5 ÖУ¬×¶¯ÈËÐĵľÍÊÇÔö¼ÓÁËLINQ¹¦ÄÜ£¬LINQÔÚÊý¾Ý¼¯³ÉµÄ»ù´¡ÉÏÌṩÁËеÄÇáÐÍ·½Ê½¡£ÓÐÁËLINQ£¬ÎÒÃÇ´´½¨µÄ²éѯÏÖÔھͱà³ÌÁË.Net ¿ò¼ÜµÄÒ»¸ö³ÉÔ±£¬ÔÚ¶ÔÒª²Ù×÷µÄÊý¾Ý´æ´¢Ö´Ðвéѯʱ£¬»áºÜ¿ì·¢ÏÖËûÃÇÏÖÔڵIJÙ×÷·½Ê½ÀàËÆÓÚϵͳÖеÄÀàÐÍ¡£Õâ˵Ã÷£¬ÏÖÔÚ¿ÉÒÔʹÓÃÈÎÒâ¼æÈÝ.Net µÄÓïÑÔÀ´²éѯµ×²ãµÄÊý¾Ý´æ´¢£¬Õ ......
1¡¢ÔÚÁíһ̨»úÆ÷ÉϽ¨Á¢¶ÀÁ¢µÄÊý¾Ý¿â·þÎñÆ÷£¬×÷ΪÁ´½ÓÄ¿±ê
2¡¢±¾µØÊý¾Ý¿â·þÎñÆ÷ÉÏÌí¼Ó“Á´½Ó·þÎñÆ÷”£º
Ãû×Ö£ºËæ±ãȡһ¸öÃû×Ö
·þÎñÆ÷ÀàÐÍ£ºÑ¡ÔñÊý¾ÝÔ´£ºMicrosoft OLE DB Provider for SQL Server
Êý¾ÝÔ´£ºÐ´±ðÃû£¨ÔÚ¿Í»§¶ËÍøÂçʵÓù¤¾ßÖÐÉèÖã©
Ñ¡ÖÐRPCºÍRPCÊä³ö ......
SQLÊÖ¹¤×¢Èë´óÈ«
2006Äê08ÔÂ11ÈÕ ÐÇÆÚÎå 21:00
±È·½ËµÔÚ²éѯidÊÇ50µÄÊý¾Ýʱ£¬Èç¹ûÓû§´«½üÀ´µÄ²ÎÊýÊÇ50 and 1=1£¬Èç¹ûûÓÐÉèÖùýÂ˵ϰ£¬¿ÉÒÔÖ±½Ó²é³öÀ´£¬SQL ×¢ÈëÒ»°ãÔÚASP³ÌÐòÖÐÓöµ½×î¶à£¬
¿´¿´ÏÂÃæµÄ
1.ÅжÏÊÇ·ñÓÐ×¢Èë
;and 1=1
;and 1=2
2.³õ²½ÅжÏÊÇ·ñÊÇmssql
;and user>0
3.ÅжÏÊý¾Ý¿âϵͳ
;and ......
±äÁ¿ÉùÃ÷
Syntax:
identifier [CONSTANT] datatype [NOT NULL] [:= | DEFAULT expr];
SQL> declare
2 a date;
3 b number(20) not null :=100;
4 c varchar2(10);
5 d constant number(20) default 1000;
6 begin
7 null;
8 end;
9 /
PL/SQL procedure successful ......