Èç¹û´æ´¢¹ý³ÌÊÇÆ´µÄSQL£¬ÄÇôҪ·ÀÖ¹×¢È룬Ôõô°ì£¿
ÊDz»ÊÇÖ»ÄÜÔÚÖ´Ðд洢¹ý³ÌÖ®Ç°Ìæ»»µôÃô¸Ð×Ö·ûÁË£¿
Ó¦¸ÃÊǵģ¬¿ÉÒÔÓÃÕýÔòÈ¥Ìæ»»ÒýÓà Ӧ¸ÃÊǵģ¬¿ÉÒÔÓÃÕýÔòÈ¥Ìæ»» µÃ´ç½ø³ßµÄÎÊÏ£¬³ýÁËÌæ»»µ¥ÒýºÅ£¬»¹ÐèÒªÌæ»»ÄÄÐ©ÄØ£¿Ð»Ð»~ C# code: ÎÒ×Ô¼ºÒ»Ö±ÊÇÕâôдµÄ£¬Ï£Íû¶ÔÄãÓÐÆô·¢ #region ¹ýÂË×Ö·û /// <summary> /// ¾ßÌåÇé¿öÀ´¶¨Òª¹ýÂ˵Ä×Ö·û /// </summary> /// <param name="param">Òª¹ýÂ˵Ä×Ö·û</param> public static string CheckSaftParam(string param) { param = param.Replace("net user", ""); param = param.Replace("xp_cmdshell", ""); param = param.Replace("/add", ""); param = param.Replace("exec%20master.dbo.xp_cmdshell", ""); param = param.Replace("net localgroup administrators", ""); param = param.Replace("select", ""); param = param.Replace("'", "''"); param = param.Replace("insert", ""); param = param.Replace("delete", ""); param = param.Replace("drop", ""); param = param.Replace("truncate", "");
Ïà¹ØÎÊ´ð£º
....½Óµ½Ò»¸öС³ÌÐò..¹¤×÷ÔÀ´´ó¸ÅÊÇÕâÑùµÄ...ǰ̨ÊÇWEB·þÎñÆ÷.¼Ü¹¹¾ÍÊÇASP+SQL..ǰ̨ÓÉASPÏòSQLÌí¼Ó·þÎñÀà±ð(±íµ¥).È»ºóÓÖºǫ́³ÌÐò¶ÁÈ¡±íµ¥..Ҫʵʱ¶ÁÈ¡..È»ºóÏÔʾÔÚ·þÎñÆ÷ÉÏÃæ..´ÓÀíÂÛÉÏÃæÄÜÐÐͨ²»?Èç¹û¿ÉÒÔ..ºǫ́ ......
sql table±íÓиöÎı¾ÀàÐ͵Äa×ֶΣ¬´æ´¢µÄÄÚÈÝÈ«²¿ÊÇÊý×Ö£¬ÀýÈç2009001£¬2008578ÕâÑùµÄ¸ñʽ£»b×Ö¶ÎÎı¾ÀàÐÍ£¬´æµÄÒ²ÊÇÊý×ÖÀýÈç 001£¬123 aspÀïÃæ strday=100£¬strb=001 ÎÒÏë¶Á³ö£¬´Óa×ֶεÄÊý×Ö°´´óµ½Ð¡µÄË ......
²éѯ½á¹û¼¯£º ps online totle a 0 10 b 1 11 c 5 8 ÏëÏÔʾ³ÉÕâÑù ......
Êý¾Ý¿âij±í£¬Ï뽫ÆäÖÐf1,f2Á½¸ö×ֶεÄÄÚÈÝ·10±¶£¬Çë½ÌÈçºÎд·¨£¿ update tbl set f1= f1*10£¬f2= f2*10 where id=10451 ÕâÖÖд·¨»áÔì³Éplsql¿¨ËÀ ²»»á°É£¬ÄǸöid=10451 µÄÊý¾ÝÓжàÉÙ°¡~~~~ ÎÒ¹À¼ÆsqlÊDz» ......
ÎÒµÄÊý¾Ý¿âµÄ±íÊǶ¯Ì¬µÄ±í,ÔÚÌí¼ÓÊý¾ÝµÄʱºòÓÐÒ»¸ö×Ö¶ÎÊÇDATETIMEÊý¾ÝÀàÐ͵Ä,ÏÂÃæÊÇ´æ´¢¹ý³Ì if exists (select * from sysobjects where name='proc_ADD_Order') drop proc proc_ADD_Order go ......