ÇóÒ»ÌõSQLÓï¾ä - MS-SQL Server / »ù´¡Àà
±íÃû: teacher ×ֶηֱðÓÐ ÐòºÅ£¬ÐÕÃû£¬ÄêÁ䣬ÐÔ±ð£¬ÄêÊÕÈë¡¡¡¡
ÏÖÏëÇóÒ»ÌõSQLÓï¾äÊÇ ³ýÁË"ÐòºÅ"Õâ¸ö×ֶβ»ÏÔʾ,ÆäËû×ֶξùÏÔʾµÄÓï¾ä£¬ ²¢·Ç select ÐÕÃû£¬ÄêÁ䣬ÐÔ±ð£¬ÄêÊÕÈë¡¡¡¡
from teacher ÕâÌõÓï¾ä(ÒòΪ×ֶμÙÉèÓÐ30¶à¸ö»áдËÀÈ˵Ä)лл£¡
Óö¯Ì¬SQL
SQL code:
DECLARE @s VARCHAR(8000)
SELECT @s = ISNULL(@s+',', '')+name
from syscolumns
WHERE id = OBJECT_ID('teacher')
AND name<>'ÐòºÅ'
EXEC ('SELECT '+@s+' from teacher')
²Î¿¼:
SQL code:
µÃµ½±íÖгýCol1¡¢Col2µÄËùÓÐÁÐ
ÀýÈ磺userno_fm¡¢userno_to
create table test(
num int identity(1,1),
userno_fm varchar(10),
userno_to varchar(10),
username varchar(10))
select * from test
declare @sql varchar(8000)
select @sql=''
select @sql=@sql+','+[name] from
(select [name] from syscolumns where object_id(N'[test]')=[id] and [name] not in ('userno_fm','userno_to')) A
set @sql='select '+stuff(@sql,1,1,'')+' from [test]'
--print @sql
exec (@sql)
drop table test
SQL code:
declare @sql varchar(8000)
select @sql=''
select @sql=@sql+','+[name] from
(selec
Ïà¹ØÎÊ´ð£º
Ö´ÐеÄ˳Ðò£º
1£©Îļþä¯ÀÀ¿ò£¨Ñ¡ÔñÎļþʹÓã©
Ñ¡ÔñºÃÎļþºó
µã»÷Ò»¸öµ¼Èë°´Å¥µÄʱºò £¬°ÑÉÏÃæÉÏ´«¿òÀïµÄcsvÎļþÒÔÒ»¸öIDΪÎļþÃû£¬ÉÏ´«µ½**/**Îļþ¼ÐÏÂ
2£©¶ÁÈ¡Õâ¸öÎļþ¼ÐϵÄcsvµÄÎļþ£¬×ª»»³Ésql
3 ......
¿ÉÄÜÒòΪ¹¤×÷µÄÔÒò ½Ó´¥Êý¾Ý¿âÕâ¿é±È½ÏÉÙ£¬Ö®Ç°¶¼ÊÇ×ö³ÌÐòÕâ¿é£¬Êý¾Ý¿âÕâ¿é¶¼ÓÐרÃŵÄÈËÀ´×ö ·Ö¹¤¶¼ºÜÃ÷ϸ ËùÒÔ¶ÔÊý¾Ý¿âÕâÒ»¿éÍêÈ«²»Á˽⡣ǰ¶Îʱ¼ä È¥ÃæÊÔÁ˼¸¼Ò¹«Ë¾ ¼¸ºõ¶¼ÊÇÔÚÊý¾Ý¿âÕâ¿é¹ÒµôµÄ Á¬¸ö¼òµ¥µÄSQ ......
ͨ¹ýNAME×Ö¶ÎÌõ¼þ²éѯһ¸öÊý¾Ý±í£¬¼ÙÉèÎÒÓÐ100¸öÐÕÃû£¬ÓÐÒÔÏÂÁ½¸ö·½·¨£¬
·½·¨1£º
°Ñ100¸öName ×é³ÉÒ»¸öSQLÓï¾ä£¬±ÈÈç Select * from tmp_table where Name='ÕÅÈý' or Name ='ÀîËÄ' Or ...Or Name='µÚÒ»°Ù¸öÐÕÃû'
......
¸÷λºÃ£¬ÎÒ¸Õ°ÑÒ»¸öASPÍøÕ¾ÉèÖúÃÁË£¬Ò²ÄÜÕý³£·ÃÎÊ¡£µ«ÊÇÔÚÎÒ±¾»úÉϲ»ÄÜ´ò¿ªadmin\login.asp,ËùÒÔÎÞ·¨ÊµÏÖºǫ́¹ÜÀí¡££¨´íÎóÌáʾÎÞ·¨ÕÒµ½ÍøÒ³£¬´úÂë404£¬ÎҵIJÙ×÷ϵͳÊÇwin2000 server)
µ«ÊÇÆæ¹ÖµÄÊÇÔÚ¾ÖÓòÍøµÄÆäËû» ......