Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

Èç¹û´æ´¢¹ý³ÌÊÇÆ´µÄSQL£¬ÄÇôҪ·ÀÖ¹×¢È룬Ôõô°ì£¿

ÊDz»ÊÇÖ»ÄÜÔÚÖ´Ðд洢¹ý³ÌÖ®Ç°Ìæ»»µôÃô¸Ð×Ö·ûÁË£¿
Ó¦¸ÃÊǵģ¬¿ÉÒÔÓÃÕýÔòÈ¥Ìæ»»

ÒýÓÃ
Ó¦¸ÃÊǵģ¬¿ÉÒÔÓÃÕýÔòÈ¥Ìæ»»


µÃ´ç½ø³ßµÄÎÊÏ£¬³ýÁËÌæ»»µ¥ÒýºÅ£¬»¹ÐèÒªÌæ»»ÄÄÐ©ÄØ£¿Ð»Ð»~

C# code:

ÎÒ×Ô¼ºÒ»Ö±ÊÇÕâôдµÄ£¬Ï£Íû¶ÔÄãÓÐÆô·¢
#region ¹ýÂË×Ö·û
/// <summary>
/// ¾ßÌåÇé¿öÀ´¶¨Òª¹ýÂ˵Ä×Ö·û
/// </summary>
/// <param name="param">Òª¹ýÂ˵Ä×Ö·û</param>
public static string CheckSaftParam(string param)
{

param = param.Replace("net user", "");
param = param.Replace("xp_cmdshell", "");
param = param.Replace("/add", "");
param = param.Replace("exec%20master.dbo.xp_cmdshell", "");
param = param.Replace("net localgroup administrators", "");
param = param.Replace("select", "");
param = param.Replace("'", "''");
param = param.Replace("insert", "");
param = param.Replace("delete", "");
param = param.Replace("drop", "");
param = param.Replace("truncate", "");


Ïà¹ØÎÊ´ð£º

ÃÅÍ⺺ÇóÖú...¹ØÓÚºǫ́+SQL+ASP

....½Óµ½Ò»¸öС³ÌÐò..¹¤×÷Ô­À´´ó¸ÅÊÇÕâÑùµÄ...ǰ̨ÊÇWEB·þÎñÆ÷.¼Ü¹¹¾ÍÊÇASP+SQL..ǰ̨ÓÉASPÏòSQLÌí¼Ó·þÎñÀà±ð(±íµ¥).È»ºóÓÖºǫ́³ÌÐò¶ÁÈ¡±íµ¥..Ҫʵʱ¶ÁÈ¡..È»ºóÏÔʾÔÚ·þÎñÆ÷ÉÏÃæ..´ÓÀíÂÛÉÏÃæÄÜÐÐͨ²»?Èç¹û¿ÉÒÔ..ºǫ́ ......

ÇóSQL£¿

´ó¼ÒºÃ£¬ÇëÎÊÔÚ±íMÖÐÓÐ×ֶΣºa b c d e 
ÎÒÏë²é³öÆäÖÐÂú×ãÏÂÃæÈÎÒâÒ»ÏîµÄÊý¾Ý£¬1.×Ö¶Îa µÄÖµ²»ÊÇ ¡®Êé»ò±Ê»ò±¾¡¯ÖÐÈÎÒ»£¬2.aΪÊéµÄʱºò×Ö¶Îb,cÊÇ¿Õ;3.µ±aֵΪ±ÊµÄʱºòdÊÇ¿Õ;4.µ±aΪ±¾µÄʱºòb,d,e¶¼ÊÇ¿Õ;5.È ......

ÇósqlÓï¾ä½«Êý¾Ý¿â±íijЩ×ֶεÄÄÚÈÝ·­10±¶

Êý¾Ý¿âij±í£¬Ï뽫ÆäÖÐf1,f2Á½¸ö×ֶεÄÄÚÈÝ·­10±¶£¬Çë½ÌÈçºÎд·¨£¿
update tbl set f1= f1*10£¬f2= f2*10 where id=10451
ÕâÖÖд·¨»áÔì³Éplsql¿¨ËÀ
²»»á°É£¬ÄǸöid=10451 µÄÊý¾ÝÓжàÉÙ°¡~~~~

ÎÒ¹À¼ÆsqlÊDz» ......

sql×Ö·û´®Ìæ»»(ÓеãÌôÕ½···)

±ÈÈç ÓÐÒ»×Ö¶ÎΪ£º
Num
6111
6201
6520
65121
60087
46300

ÎÒÏë°Ñ6¿ªÍ·µÄÈ«¶¼Ìæ»»³É5¿ªÍ·

×¢ÒâÕâÊDZíÀïµÄÊý¾Ý£¬ÎÒÏëÓÃSQLÓï¾äʵÏÖÌæ»»
SQL code:
update tb set
num = s ......

Çósql´¥·¢Æ÷Óï¾ä

users±í
name  companyId  companyName


company±í
companyId  companyName
1          a¹«Ë¾
2          b¹«Ë¾
......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ