Asp.netÖÐ,´Óµ¯³ö´°ÌåȡѡÔñÖµ
ÔÚAsp.netÖУ¬´ÓAÒ³ÃæÖе¯³öBÒ³Ãæ£¬ÔÚBÒ³ÃæÖÐÑ¡ÔñÊý¾Ýºó£¬¹Ø±Õ²¢½«Êý¾Ý¸üе½AÒ³Ãæ£¬ÊÇÒ»ÖÖ³£Óà µÄ·½Ê½¡£Ö»ÊÇÎÒ¶ÔJavascript²»ÊìϤ£¬ËùÒÔµ·¹ÄÁËÒ»ÏÂÎ磬ÖÕÓÚÓÐÁËÒ»µã³É¼¨£º
²âÊÔÏîÄ¿ÓÐÁ½¸öÒ³Ãæ£ºDefault.aspx¼°Default2.aspx£¬ÔÚDefault.aspxÒ³ÃæÉÏÓÐÒ»¸öTextBox1¼°Ò»¸öButton1£¬Button1ÓÃÓÚ´¥·¢Default2.aspx£¬TextBox1ÓÃÓÚ½ÓÊÕ´Ó×ÓÒ³Ãæ´«»ØµÄÖµ¡£
Button1µÄ´úÂëÈçÏ£º
CODE:
StringBuilder s = new StringBuilder();
s.Append("<script language=javascript>");
s.Append("var a=window.showModalDialog('Default2.aspx');");
s.Append("if(a!=null)");
s.Append("document.all('TextBox1').value=a;");
s.Append("</script>");
Type cstype = this.GetType();
ClientScriptManager cs = Page.ClientScript;
string sname = "lt";
if (!cs.IsStartupScriptRegistered(cstype, sname))
cs.RegisterStartupScript(cstype, sname, s.ToString());
Default2.aspxÒ³ÃæÄÚÓÐÒ»¸öCheckBoxList1¼°Ò»¸öButton1£¬Button1Ö´Ðзµ»ØÑ¡ÔñµÄCheckBoxList1µÄÖµ£¬²¢½«µ±Ç°Ò³Ãæ¹Ø±Õ¡£
´úÂëÈçÏ£º
CODE:
protected void Button1_Click(object sender, EventArgs e)
{
StringBuilder s = new StringBuilder();
s.Append("<script language=javascript>" + "\n");
s.Append("window.returnValue='" + this.GetSelectValue() + "';" + "\n");
s.Append("window.close();"+"\n");
s.Append("</script>");
Type cstype = this.GetType();
ClientScriptManager cs = Page.ClientScript;
string csname = "ltype";
if (!cs.IsStartupScriptRegistered(cstype, csname))
&nbs
Ïà¹ØÎĵµ£º
using System.Text.RegularExpressions; //ÒýÈëµÄÃüÃû¿Õ¼ä
ÒÔÏÂΪÒýÓõÄÄÚÈÝ£º
//Çå³ýHTMLº¯Êý
public static string NoHTML(string Htmlstring)
{
//ɾ³ý½Å±¾
Htmlstr ......
´Ë´¦ÌṩµÄ´úÂëÓÃÀ´ÊµÏÖµ±asp.netÒ³ÃæÖеÄij¸öButton±»µã»÷ºódisableµô¸ÃÒ³ÃæÖÐËùÓеÄButton£¬´Ó¶ø·ÀÖ¹Ìá½»ÑÓʱµ¼ÖµĶà´ÎÌá½»¡£»ùÓÚ֮ǰµÄonceclickbutton½Å±¾.
//ASP.NETÖзÀÖ¹Ò³Ãæ¶à´ÎÌá½»µÄ´úÂë:javascript< script language="javascript"> < !-- function disableOtherSubmit()
{
var obj ......
ÒÔǰ·¢¹ýÒ»¸ö.NETÉÏ´«ÎļþµÄ·½·¨µÄ£¬²»¹ýÄǸö·½·¨ÖжÔÎļþÀàÐ͵ÄÅжÏÖ»ÊǶԺó׺ÃûÀ´½øÐÐÅжϵģ¬ÕâÑù¼ÙÈçÎÒ°ÑÒ»¸ötxtÎı¾ÎļþµÄºó׺Ãû¸ÄΪjpgÁËÒ²¿ÉÒÔÉÏ´«£¬ÕâÑùÎÞÒâÖоÍÔì³ÉÁ˰²È«ÎÊÌâ¡£
¸Õ¸Õ´ÓÍøÉÏÕÒÁ˸ö·½·¨£¬ÊÔÑéÁËһϣ¬ÊÇÄܹ»±æÈϳöÕýÈ·µÄÎļþÀàÐ͵ģ¬ÈçÏ£º
using System;
using System.Collections.Generic; ......
ÔÚÐÂÔöÊý¾ÝÏîµÄʱºò£¬ÓÃajaxʵÏÖÎÞË¢ÐÂÌá½»£¬µ«ÉÏ´«ÎļþµÄʱºò£¬ÓÉÓÚÊý¾ÝÀàÐÍÔÒò£¬²»Äܽ«Ò³ÃæµÄ<asp:FileUpload>ÖÐÒÔ×Ö·û´®ÖµµÄ·½Ê½´«µ½jsÀïµ÷Óá£ÎÒÒ»¹²ÕÒµ½ÁËÁ½¸ö·½·¨ÓèÒÔ½â¾ö£¬ÊµÏÖÎÞË¢ÐÂÉÏ´«¡£
µÚÒ»ÖÖ·½·¨£ºÀûÓÃjsµÄADODB.Stream£¬½«ÎļþÏÈת»»³ÉÁ÷£¬ÔÙͨ¹ýjsÉÏ´«µ½·þÎñÆ÷£¬ÕâÑùÓиöºÃ´¦¾ÍÊÇ¿ÉÒÔÉÏ´«³¬´óÎļþ£ ......
×öÏîĿҲÓÐÒ»¶Îʱ¼äÁË£¬ÔÚ³ÌÐòÖÐÒ²Óöµ½ºÜ¶à°²È«·½ÃæµÄÎÊÌâ¡£Ò²¸Ã×ܽáÒ»ÏÂÁË¡£Õâ¸öÏîÄ¿ÊÇÒ»¸ö CMS ϵͳ¡£ÏµÍ³ÊÇÓà ASP.NET ×öµÄ¡£¿ª·¢µÄʱºò·¢ÏÖ΢Èí×öÁ˺ܶలȫ´ëÊ©£¬Ö»ÊÇÓÐЩÐÂÊÖ³ÌÐòÔ±²»ÖªµÀÔõô¿ªÆô¡£ÏÂÃæÎÒͨ¹ý¼¸¸ö·½Ãæ¼òµ¥½éÉÜ£º
¡¡¡¡1£ºSQL ×¢Èë
¡¡¡¡2£ºXSS
¡¡¡¡3£ºCSRF
¡¡¡¡4£ºÎļþÉÏ´«
SQL ×¢Èë
¡¡¡¡ÒýÆðÔÒ ......