asp½«Êý¾Ý¿âµÄÊý¾Ýת»»³Éexcelµ¼³ö
<% '--------------------------------------------------------------------------------------------------
Set rs9 = Server.CreateObject("ADODB.RecordSet")
sqlstr="select * from ¿Í»§×ÊÁÏ¿â order by id desc"
rs9.open sqlstr,conn,1,3
%>
<%Set fs = server.CreateObject("scripting.filesystemobject")
'--Éú³ÉµÄEXCELÎļþ×öÈçϵĴæ·Å
filename="¿Í»§×ÊÁÏ.xls"
temp=filename
filename=Request.ServerVariables("APPL_PHYSICAL_PATH")&"\"+filename
'--Èç¹ûÔÀ´µÄEXCELÎļþ´æÔڵϰɾ³ýËü
if fs.FileExists(filename) then
fs.DeleteFile(filename)
end if
'--´´½¨EXCELÎļþ
set myfile = fs.CreateTextFile(filename,true)
dim strLine,responsestr
strLine=""
For each x in rs9.fields
strLine= strLine & x.name & chr(9)
Next
'--½«±íµÄÁÐÃûÏÈдÈëEXCEL
myfile.writeline strLine
while not rs9.eof
strLine=""
for each x in rs9.Fields
strLine= strLine & x.value & chr(9)
next
'--½«±íµÄÊý¾ÝдÈëEXCEL
myfile.writeline strLine
rs9.movenext
wend
link="<A HREF="\" mce_HREF="\"" & temp & ">ÏÂÔØexcelÎļþ</a>"
if Request.Cookies("adminuser")="admin" then
Response.write link
end if
set myfile = nothing
Set fs=Nothing
rs9.close
%>
Ïà¹ØÎĵµ£º
±äÁ¿ÉêÃ÷£¬ÃüÃû¹æÔòÓëÔËËã·û
1£¬ÓÃÈýÖÖÓï¾äÀ´ÉùÃ÷±äÁ¿£ºdim £¬public Óë private £¬±È½Ï³£ÓõϹÊÇ dim ¡£
È磺<% dim a %> £»<% dim a , b , c %>
2£¬ÃüÃû¹æÔò£º
<1> ±äÁ¿µÄµÚÒ»¸ö×Ö·û±ØÐëÊÇ×Öĸ£¬Êý×ֺͷûºÅ¶¼²»ÐС£
<2> ²»ÄÜǶÈë¾äµã¡£
<3> ³¤¶È²»Äܳ¬¹ý255¸ö×Ö·û¡£
<4> ......
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò Å ......
<html xmlns="http://www.w3.org/1999/xhtml" >
<HEAD>
<title>¶àÎļþÉÏ´« </title>
<script language="JavaScript">
function addFile()
{
var str = ' <br / ......
ÔÚÍøÉÏ¿´µ½ºÜ¶àÕâ·½ÃæµÄ´úÂ룬µ«ÊÇÓÐЩÊDz»ÄÜÓã¬ÓÐЩÊÇÀ¬»ø´úÂëÌ«¶à£¬ÎÒ¼òµ¥µÄÐÞ¸ÄÁËÒ»ÏÂÏÖÔÚÓë´ó¼Ò¹²Ïíһϡ£
<%
Option Explicit
dim databasename '¶¨ÒåÊý¾Ý¿âÃû³Æ
databasename="database.mdb" 'Êý¾Ý¿âÃû³Æ
dim databasepath '¶¨ÒåÊý¾Ý¿â´æ·Å·¾¶
......
ǰ¶Îʱ¼ä¸ø¿Í»§×öÁ˼¸¸öÍøÒ³£¬¿Í»§ÒªÇóÔÚ×Ô¼ºµÄÍøÕ¾ÖÐÏÔʾ×Ô¼ºÔÚÐÂÀ˲©¿ÍÀïµÄÎÄÕ£¬×÷ÎªÍøÕ¾µÄÒ»²¿·Ö¡£ÕâÑùµÄÇé¿ö¿ÉÒÔ½â¾ö£¬Ö÷Òª¿ÉÒÔͨ¹ý²©¿ÍÖÐµÄ XMLÀ´ÊµÏÖ£¬Í¨¹ýÓÃaspÀ´¶ÁÈ¡²©¿ÍÖÐXML£¬½«²©¿ÍÖеıêÌâ¡¢·¢²¼Ê±¼äµÈÐÅÏ¢ÏÔʾÔÚÍøÕ¾ÖС£µ«ÊÇÔÚʹÓõĹý³ÌÖУ¬³öÏÖÁËÒ»¸öÎÊÌ⣺µ±²©¿ÍÖÐÌí¼ÓÎÄÕºó£¬ÔÚÍøÒ³ÖжÁÈ¡²©¿ÍÖеÄXMLºó½ ......