ÔÚPHPÖÐÈ«Ãæ×èÖ¹SQL×¢Èëʽ¹¥»÷Ö®¶þ
Ò»¡¢ ×¢Èëʽ¹¥»÷µÄÀàÐÍ
¡¡¡¡¿ÉÄÜ´æÔÚÐí¶à²»Í¬ÀàÐ͵Ĺ¥»÷¶¯»ú£¬µ«ÊÇÕ§¿´ÉÏÈ¥£¬Ëƺõ´æÔÚ¸ü¶àµÄÀàÐÍ¡£ÕâÊǷdz£ÕæÊµµÄ-Èç¹û¶ñÒâÓû§·¢ÏÖÁËÒ»¸öÄܹ»Ö´Ðжà¸ö²éѯµÄ°ì·¨µÄ»°¡£±¾ÎĺóÃæ£¬ÎÒÃÇ»á¶Ô´Ë×÷ÏêϸÌÖÂÛ¡£
¡¡¡¡Èç¹ûÄãµÄ½Å±¾ÕýÔÚÖ´ÐÐÒ»¸öSELECTÖ¸ÁÄÇô£¬¹¥»÷Õß¿ÉÒÔÇ¿ÆÈÏÔʾһ¸ö±í¸ñÖеÄÿһÐмǼ-ͨ¹ý°ÑÒ»¸öÀýÈç"1=1"ÕâÑùµÄÌõ¼þ×¢Èëµ½WHERE×Ó¾äÖУ¬ÈçÏÂËùʾ(ÆäÖУ¬×¢È벿·ÖÒÔ´ÖÌåÏÔʾ)£º
SELECT * from wines WHERE variety = 'lagrein' OR 1=1;'
¡¡¡¡ÕýÈçÎÒÃÇÔÚÇ°ÃæËùÌÖÂ۵ģ¬Õâ±¾Éí¿ÉÄÜÊǺÜÓÐÓõÄÐÅÏ¢£¬ÒòΪËü½ÒʾÁ˸ñí¸ñµÄÒ»°ã½á¹¹(ÕâÊÇÒ»ÌõÆÕͨµÄ¼Ç¼Ëù²»ÄÜʵÏÖµÄ)£¬ÒÔ¼°Ç±ÔÚµØÏÔʾ°üº¬»úÃÜÐÅÏ¢µÄ¼Ç¼¡£
¡¡¡¡Ò»Ìõ¸üÐÂÖ¸ÁîDZÔڵؾßÓиüÖ±½ÓµÄÍþв¡£Í¨¹ý°ÑÆäËüÊôÐԷŵ½SET×Ó¾äÖУ¬Ò»Ãû¹¥»÷Õß¿ÉÒÔÐ޸ĵ±Ç°±»¸üеļǼÖеÄÈκÎ×ֶΣ¬ÀýÈçÏÂÃæµÄÀý×Ó£¨ÆäÖУ¬×¢È벿·ÖÒÔ´ÖÌåÏÔʾ£©£º
UPDATE wines SET type='red'£¬'vintage'='9999' WHERE variety = 'lagrein'
¡¡¡¡Í¨¹ý°ÑÒ»¸öÀýÈç1=1ÕâÑùµÄºãÕæÌõ¼þÌí¼Óµ½Ò»Ìõ¸üÐÂÖ¸ÁîµÄWHERE×Ó¾äÖУ¬ÕâÖÖÐ޸ķ¶Î§¿ÉÒÔÀ©Õ¹µ½Ã¿Ò»Ìõ¼Ç¼£¬ÀýÈçÏÂÃæµÄÀý×Ó£¨ÆäÖУ¬×¢È벿·ÖÒÔ´ÖÌåÏÔʾ£©£º
UPDATE wines SET type='red'£¬'vintage'='9999 WHERE variety = 'lagrein' OR 1=1;'
¡¡¡¡×îΣÏÕµÄÖ¸Áî¿ÉÄÜÊÇDELETE-ÕâÊDz»ÄÑÏëÏñµÄ¡£Æä×¢Èë¼¼ÊõÓëÎÒÃÇÒѾ¿´µ½µÄÏàͬ-ͨ¹ýÐÞ¸ÄWHERE×Ó¾äÀ´À©Õ¹ÊÜÓ°ÏìµÄ¼Ç¼µÄ·¶Î§£¬ÀýÈçÏÂÃæµÄÀý×Ó£¨ÆäÖУ¬×¢È벿·ÖÒÔ´ÖÌåÏÔʾ£©£º
DELETE from wines WHERE variety = 'lagrein' OR 1=1;'
¡¡¡¡¶þ¡¢ ¶à¸ö²éѯעÈë
¡¡¡¡¶à¸ö²éѯעÈ뽫»á¼Ó¾çÒ»¸ö¹¥»÷Õß¿ÉÄÜÒýÆðµÄDZÔÚµÄËð»µ-ͨ¹ýÔÊÐí¶àÌõÆÆ»µÐÔÖ¸Áî°üÀ¨ÔÚÒ»¸ö²éѯÖС£ÔÚʹÓÃMySQLÊý¾Ý¿âʱ£¬¹¥»÷Õßͨ¹ý°ÑÒ»¸ö³öºõÒâÁÏÖ®ÍâµÄÖÕÖ¹·û²åÈëµ½²éѯÖм´¿ÉºÜÈÝÒ×ʵÏÖÕâÒ»µã-´Ëʱһ¸ö×¢ÈëµÄÒýºÅ(µ¥ÒýºÅ»òË«ÒýºÅ)±ê¼ÇÆÚÍû±äÁ¿µÄ½áβ£»È»ºóʹÓÃÒ»¸ö·ÖºÅÖÕÖ¹¸ÃÖ¸Áî¡£ÏÖÔÚ£¬Ò»¸öÁíÍâµÄ¹¥»÷Ö¸Áî¿ÉÄܱ»Ìí¼Óµ½ÏÖÔÚÖÕÖ¹µÄÔʼָÁîµÄ½áβ¡£×îÖÕµÄÆÆ»µÐÔ²éѯ¿ÉÄÜ¿´ÆðÀ´ÈçÏÂËùʾ£º
SELECT * from wines WHERE variety = 'lagrein';
GRANT ALL ON *.* TO 'BadGuy@%' IDENTIFIED BY 'gotcha';'
¡¡¡¡Õâ¸ö×¢È뽫´´½¨Ò»¸öеÄÓû§BadGuy²¢¸³ÓèÆäÍøÂçÌØÈ¨£¨ÔÚËùÓеıí¸ñÉϾßÓÐËùÓеÄÌØÈ¨£©£»ÆäÖУ¬»¹ÓÐÒ»¸ö"²»Ïé"µÄ¿ÚÁî±»¼ÓÈëµ½Õâ¸ö¼òµ¥µÄSELECTÓï¾äÖС£Èç¹ûÄã×ñÑÎÒÃÇÔÚÒÔǰÎÄÕÂÖеĽ¨Òé£ÑϸñÏÞÖÆ¸Ã¹ý³ÌÓû§µÄÌØÈ¨£¬ÄÇô£¬ÕâÓ¦¸ÃÎÞ·¨¹¤×÷£¬ÒòΪweb·þÎñÆ÷ÊØ»¤³ÌÐò²
Ïà¹ØÎĵµ£º
µ¼ÈëµÄÏêϸÁ÷³Ì
1¡¢Ð½¨Ò»¸öÊý¾Ý¿â
2¡¢ÔÚеÄÊý¾Ý¿âÉϵãÓÒ¼ü-¡·“ËùÓÐÈÎÎñ”-¡·“µ¼ÈëÊý¾Ý¿â”£¬µãÏÂÒ»²½
3¡¢Ê²Ã´¶¼²»Òª¸Ä£¬ÔÚÊý¾Ý¿âÖÐÑ¡ÔñÄǸö¾ÉµÄÊý¾Ý¿â£¬µãÏÂÒ»²½
4¡¢ÔÚÕâ¸ö½çÃæµÄÊý¾Ý¿âÖÐÑ¡ÔñÄãн¨µÄÊý¾Ý¿â£¬µãÏÂÒ»²½
5¡¢Ñ¡Ôñ“ÔÚSQL SERVERÊý¾Ý¿âÖ®¼ä¸´ÖƶÔÏóºÍÊý¾Ý”£¬µãÏÂÒ»²½
......
¡¡¡¡php ×÷Ϊ“×î¼òµ¥”µÄ Web ½Å±¾ÓïÑÔ, ÔÚ¹úÄÚµÄÊг¡Ô½À´Ô½´ó£¬phper Ô½À´Ô½¶à£¬µ«ÊǸоõ´ó¶àÊýÈ˺ÃÏñûÓп¼Âǵ½Ä£Ê½ÎÊÌ⣬ʲôÑùµÄÉè¼ÆÄ£Ê½²ÅÊÇ×îÓŵ쬲ÅÊÇ×îÊʺÏ×Ô¼ºÄ¿Ç°¹¤×÷µÄ£¬±Ï¾¹Ð§ÂÊÊÇ×îÖØÒªµÄ£¨ÓÃʡϵÄʱ¼ä´òÓÎÏ·£¬¶àÃÀ°¡...£©¡£MVC Ó¦¸ÃÊÇÊ×Ñ¡£¬www.sourceforge.net ÉÏÓкöàÓÅÐãµÄ»ùÓÚ MVC µ ......
£¨1£© Ñ¡Ôñ×îÓÐЧÂʵıíÃû˳Ðò(Ö»ÔÚ»ùÓÚ¹æÔòµÄÓÅ»¯Æ÷ÖÐÓÐЧ)£º
ORACLE µÄ½âÎöÆ÷°´ÕÕ´ÓÓÒµ½×óµÄ˳Ðò´¦Àífrom×Ó¾äÖеıíÃû£¬from×Ó¾äÖÐдÔÚ×îºóµÄ±í(»ù´¡±í driving table)½«±»×îÏÈ´¦Àí£¬ÔÚfrom×Ó¾äÖаüº¬¶à¸ö±íµÄÇé¿öÏÂ,Äã±ØÐëÑ¡Ôñ¼Ç¼ÌõÊý×îÉٵıí×÷Ϊ»ù´¡±í¡£Èç¹ûÓÐ3¸öÒÔÉϵıíÁ¬½Ó²éѯ, ÄǾÍÐèÒª ......
±¾ÎÄ×ܽáÁË¿ª·¢¹¤×÷Öг£ÓõÄSQLÓï¾ä,¹©´ó¼Ò²Î¿¼……
--Óï ¾ä ¹¦ ÄÜ
--Êý¾Ý²Ù×÷
SELECT --´ÓÊý¾Ý¿â±íÖмìË÷Êý¾ÝÐкÍÁÐ
INSERT --ÏòÊý¾Ý¿â±íÌí¼ÓÐÂÊý¾ÝÐÐ
DELETE --´ÓÊý¾Ý¿â±íÖÐɾ³ýÊý¾ÝÐÐ
UPDATE --¸üÐÂÊý¾Ý¿â±íÖеÄÊý¾Ý
--Êý¾Ý¶¨Òå
CREATE TABLE --´´½¨Ò»¸öÊý¾Ý¿â±í
DROP TABLE --´ÓÊý¾Ý¿âÖÐɾ³ý±í
A ......