Èç¹û´æ´¢¹ý³ÌÊÇÆ´µÄSQL£¬ÄÇôҪ·ÀÖ¹×¢È룬Ôõô°ì£¿
ÊDz»ÊÇÖ»ÄÜÔÚÖ´Ðд洢¹ý³ÌÖ®Ç°Ìæ»»µôÃô¸Ð×Ö·ûÁË£¿
Ó¦¸ÃÊǵģ¬¿ÉÒÔÓÃÕýÔòÈ¥Ìæ»»ÒýÓà Ӧ¸ÃÊǵģ¬¿ÉÒÔÓÃÕýÔòÈ¥Ìæ»» µÃ´ç½ø³ßµÄÎÊÏ£¬³ýÁËÌæ»»µ¥ÒýºÅ£¬»¹ÐèÒªÌæ»»ÄÄÐ©ÄØ£¿Ð»Ð»~ C# code: ÎÒ×Ô¼ºÒ»Ö±ÊÇÕâôдµÄ£¬Ï£Íû¶ÔÄãÓÐÆô·¢ #region ¹ýÂË×Ö·û /// <summary> /// ¾ßÌåÇé¿öÀ´¶¨Òª¹ýÂ˵Ä×Ö·û /// </summary> /// <param name="param">Òª¹ýÂ˵Ä×Ö·û</param> public static string CheckSaftParam(string param) { param = param.Replace("net user", ""); param = param.Replace("xp_cmdshell", ""); param = param.Replace("/add", ""); param = param.Replace("exec%20master.dbo.xp_cmdshell", ""); param = param.Replace("net localgroup administrators", ""); param = param.Replace("select", ""); param = param.Replace("'", "''"); param = param.Replace("insert", ""); param = param.Replace("delete", ""); param = param.Replace("drop", ""); param = param.Replace("truncate", "");
Ïà¹ØÎÊ´ð£º
Óöµ½µÄÏÖÏóÊÇ Í¬Ò»¸ö±íµÄquery»á×èÈûupdate sql query ºÍupdate ²Ù×÷ query»á×èÈûupdate²Ù×÷Âð Ôõô½â¾ö ÊDz»ÊÇʲôÉèÖò»¶Ô»¹ÊÇÔõµÄ Èç¹û»áµÄ»°£¬ÄÇͬһ¸ö±íµÄƵ·±query and ......
sqlÓï¾ä£º select loan_plan_id,l_collect_plan.loan_id,l_collect_detail.collect_isfinished from l_collect_plan left join l_collect_detail on l_collect_plan.return_times=l_collect_detail.collect_vo ......
ÏÖÔÚÓÐÁ½¸öÒì¹¹µÄsql serverÊý¾Ý¿â,ÎÒÏ뽫µÚÒ»¸ö±íÖеÄÊý¾Ýµ¼Èëµ½µÚ¶þ¸ö±íÖÐ,×Ô¼ºÖ¸¶¨µ¼ÈëÊý¾ÝµÄ×Ö¶Î,ÈçºÎµ¼ÈëÊý¾ÝÄØ,´ó¼ÒÌÖÂÛÒ»ÏÂ? dts¹¤¾ß µ¼Èëµ¼³ö¹¤¾ß. DD ¹þ¹þ£¬¹À¼ÆÕâλÊǵØQIOU¶¼Êܲ»ÁËµÄ Ö±½ÓÐ ......
СµÜÊǸöÐÂÊÖ ÏÖÔÚÓиöÎÊÌâÒ»Ö±²»Äܽâ¾ö ÀýÈç procedure produce_proc @p001 nvarchar(8000), @p002 nvarchar(8000), @p003 nvarchar(8000), & ......