hzhost·Àasp¹¥»÷º¯Êý
hzhost·Àasp¹¥»÷º¯Êý
Function SafeRequest(ParaName)
Dim ParaValue
ParaValue=Request(ParaName)
if IsNumeric(ParaValue) then
SafeRequest=ParaValue
exit Function
else
ParaValuetemp=lcase(ParaValue)
tempvalue="select
|insert |delete from|'|count(|drop table|update |truncate
|asc(|mid(|char(|xp_cmdshell|exec master|net localgroup
administrators|net user| or | and |%20from"
temps=split(tempvalue,"|")
for mycount=0 to ubound(temps)
if Instr(ParaValuetemp,temps(mycount)) > 0 then
call errorpage(-2,"·Ç·¨ÇëÇ󣡣¡£¡")
response.end
end if
next
SafeRequest=ParaValue
end if
End function
'=================
Ïà¹ØÎĵµ£º
ÔÎÄÒýÓÃ:
http://www.17558.net/cmd.asp?act=tb&id=16&key=43840
ÔÎĵØÖ·:http://www.17558.net/post/16.html
żÊÇÒ»¸öµ×²ãµÄASP¼¼ÊõÈËÔ±(ÊôÓÚ°ë·³ö¼ÒµÄÄÇÖÖ,ÒÔǰÊÇÒ»ÃûÍøÂç¼¼ÊõÈËÔ±),×î½ü²ÎÓëÖÆ×÷Ò»¸öCRMϵͳ,¼Ü¹»²ÉÓÃASP+SQL,¿¼Âǵ½ÒÔºóÊý¾Ý²éѯЧÂÊÎÊÌâ,ËùÒÔÔÚÍøÉÏÕÒÁËÒ»¸ö AspÊý¾Ý²Ù×÷×é¼þ(°ÙÍò¼¶·ÖÒ³) , ......
ActiveConnection ÉèÖûò·µ»ØCommand¶ÔÏóµÄÁ¬½ÓÐÅÏ¢£¬¸ÃÊôÐÔ¿ÉÒÔÊÇÒ»¸öConnection¶ÔÏó»òÁ¬½Ó×Ö·û´®¡£
CommandText ÉèÖûò·µ»Ø¶ÔÊý¾ÝÔ´µÄÃüÁî´®£¬Õâ¸ö´®¿ÉÒÔÊÇSQLÓï¾ä¡¢±í¡¢´¢´æ¹ý³Ì»òÊý¾ÝÌṩÕßÖ§³ÖµÄÈÎ ºÎÌØÊâÓÐЧµÄÃüÁîÎı¾¡£
Prepared Ìá³öÔÚµ÷ÓÃCommand¶ÔÏóµÄExecute·½·¨Ê±£¬ÊÇ·ñ½«²éѯµÄ±àÒë½á¹û´¢´æÏÂÀ´¡£Èç¹û½«¸ ......
'-------------------------------------------------------------------------------------------------------1.asp
<!--#include file="function.asp" -->
<%if Request.Cookies("venshop")("user_name")<>"" then%>
<script>
function checkAll(){
for (i=0;i&l ......
'--------------------------------------------------------------------------------------1.asp
<!--#include file="function.asp" -->
<script>
function checkAll(){
for (i=0;i<document.forms[1].length;i++){
if (document.forms[1][i].tagName= ......
<input type="submit" name=""byt id="byt" value="ÏÖ½ðÏúÊÛÌá½»" >
ÀýÈ磺±íµ¥ÖÐÓÐÒ»¸öÃûΪ byt µÄ°´Å¥£¬ÒªÇóÍøÒ³´ò¿ª1Ãëºó£¬×Ô¶¯µã»÷°´Å¥£¬
·½·¨£º°ÑÈçÏ´úÂë¼ÓÔÚ</form>ºó¡£
<script language="javascript">
function window.onload()
{
setTimeout("document.form1.byt.click()",1 ......