asp¶àÎļþÉÏ´«£¨×ª£©
<html xmlns="http://www.w3.org/1999/xhtml" >
<HEAD>
<title>¶àÎļþÉÏ´« </title>
<script language="JavaScript">
function addFile()
{
var str = ' <br /> <INPUT type="file" size="50" NAME="File">'
document.getElementById('MyFile').insertAdjacentHTML("beforeEnd",str)
}
</script>
<link href="../Css/dinwei.css" rel="stylesheet" type="text/css" />
</HEAD>
<body>
<form id="form1" method="post" runat="server" enctype="multipart/form-data">
<div align="center">
<h3>¶àÎļþÉÏ´« </h3>
<P id="MyFile"> <INPUT type="file" size="50" NAME="File"> </P>
<P>
<asp:Button Runat="server" Text="¿ªÊ¼ÉÏ´«" ID="UploadButton"> </asp:Button>
<input onclick="this.form.reset()" type="button" value="ÖØÖÃ(ReSet)">
<input type="button" value="Ôö¼Ó(Add)" onclick="addFile()">
</P>
<P>
<asp:Label id="strStatus" runat="server" Font-Names="ËÎÌå" Font-Bold="True" Font-Size="9pt"
Width="500px" BorderStyle="None" BorderColor="White"> </asp:Label>
</P>
</div>
</form>
</body>
</HTML>
protected void Page_Load(obje
Ïà¹ØÎĵµ£º
Active Server Pages ÌṩÄÚ½¨¶ÔÏó£¬ÕâЩ¶ÔÏóʹÓû§¸üÈÝÒ×ÊÕ¼¯Í¨¹ýä¯ÀÀÆ÷ÇëÇó·¢Ë͵ÄÐÅÏ¢¡¢ÏìÓ¦ä¯ÀÀÆ÷ÒÔ¼°´æ´¢Óû§ÐÅÏ¢£¨ÈçÓû§Ê×Ñ¡Ï¡£±¾ÎļòҪ˵Ã÷ÿһ¸ö¶ÔÏó¡£
Application ¶ÔÏó
¿ÉÒÔʹÓà Application ¶ÔÏóʹ¸ø¶¨Ó¦ÓóÌÐòµÄËùÓÐÓû§¹²ÏíÐÅÏ¢¡£
Request ¶ÔÏó
¿ÉÒÔʹÓà Request ¶ÔÏó·ÃÎÊÈκÎÓà HTTP ÇëÇó ......
±äÁ¿ÉêÃ÷£¬ÃüÃû¹æÔòÓëÔËËã·û
1£¬ÓÃÈýÖÖÓï¾äÀ´ÉùÃ÷±äÁ¿£ºdim £¬public Óë private £¬±È½Ï³£ÓõĻ¹ÊÇ dim ¡£
È磺<% dim a %> £»<% dim a , b , c %>
2£¬ÃüÃû¹æÔò£º
<1> ±äÁ¿µÄµÚÒ»¸ö×Ö·û±ØÐëÊÇ×Öĸ£¬Êý×ֺͷûºÅ¶¼²»ÐС£
<2> ²»ÄÜǶÈë¾äµã¡£
<3> ³¤¶È²»Äܳ¬¹ý255¸ö×Ö·û¡£
<4> ......
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò Å ......
ÏÖÔÚÖ÷Á÷µÄÍøÕ¾¿ª·¢ÓïÑÔÎÞÍâºõasp¡¢php¡¢asp.net¡¢jspµÈ¡£
ÍøÒ³´Ó¿ªÊ¼¼òµ¥µÄhmtlµ½¸´ÔӵķþÎñÓïÑÔ£¬×ß¹ýÁË10¶à¸öÄêÍ·£¬¸÷ÖÖ¼¼Êõ²ã³ö²»Çµ¥¸öµÄÖ÷Á÷¼¼ÊõÒ²ÔÚ²»¶Ï·Ðµİ汾£¬ÏÖÔÚ·ÖÎöϸ÷ÖÖÓïÑÔµÄÇø±ð¡¢ÓÅÊÆ¡¢ÁÓÊÆ¡¢¿ª·¢×¢ÒâÊÂÏ
......