sql×¢ÈëÍ»ÆÆ¹Ø¼ü×Ö¹ýÂË
Ò»Ö±ÒÔÀ´¶¼ÒÔΪֻÓпոñ£¬tab¼üºÍ×¢ÊÍ·û/**/¿ÉÒÔÓÃÀ´Çиîsql¹Ø¼ü×Ö£¬¶Îʱ¼ä
ÔÚа°Ë¿´ÁË·çѸcms×¢Èë©¶´ÄÇÆªÌû×Ó£¬²ÅÖªµÀÔÀ´»Ø³µÒ²¿ÉÒÔÓÃÀ´×÷Ϊ·Ö¸î·û£¨
ÒÔǰ¾¹È»Ã»ÓÐÏëµ½£¬ÕæÊÇʧ°Ü£©¡£»Ø³µµÄasciiÂëÊÇchr(13)&chr(10)£¬ÖÁÓÚΪʲ
ôҪÁ½¸öÁ¬ÔÚÒ»Æð£¬Õâ¸öÎÒÒ²²»ÖªµÀ¡£×ª»»³Éurl±àÂëÐÎʽÊÇ%0d%0a£¬ÓÚÊǾͿÉÒÔ
ÓÃ%0d%0a´úÌæ¿Õ¸ñpassһЩ¹ýÂ˿ոñµÄ¼ì²éÁË¡£
ÒýÉêһϣ¬Ö»ÓÃ%0dÄÜÕý³£Ö´ÐÐÓï¾äÂð£¿Ö»ÓÃ%0aÄØ£¿²âÊÔÖ¤Ã÷£¬ÓÃÈÎÒâÒ»ÖÖ·Ö¸î
ÔÚmssql¡¢mysqlºÍaccessÀïÃæ¶¼ÊÇ¿ÉÒԵġ£
ÁíÍ⣬¹ØÓÚmssqlµÄ¶àÓï¾äÎÊÌâ¡£ÎÒÒÔǰһֱÒÔΪ±ØÐëÓ÷ֺÅ×÷ΪÓï¾äµÄ½á⣬ºó
À´·¢ÏÖ£¬ÍêÈ«²»ÊÇÄÇÑù¡£ÀàËÆ
Copy code
select * from table exec xp_cmdshell'xxxxxxxxxx'
select * from table/**/exec xp_cmdshell'xxxxxxxxxx'
select * from table|---tab---|exec xp_cmdshell'xxxxxxxxxx'
select * from table|---enter---|exec xp_cmdshell'xxxxxxxxxx'
µÄÓï¾ä¶¼ÊÇ¿ÉÒÔÕý³£Ö´Ðеġ£¶øÎÒÒÔǰ¾¹È»Ò»Ö±²»ÖªµÀ£¡²»¹ýÕâ¸öÃ²ËÆ¸úÁ¬½ÓÊý
¾Ý¿âÇý¶¯ÓйØÏµ£¬odbc¿ÉÒÔÕý³£Ö´ÐУ¬sqloledbµÄ»°¾Í»á±¨´í¡£ÓÐÐËȤµÄ¼ÌÐøÑÐ
¾¿°É
ÕâÑù£¬ÒÔºóÓöµ½´ø¿Õ¸ñ¹ýÂ˹ؼü×ÖµÄÀ¹½Ø³ÌÐò£¬ÓÖ¿ÉÒÔ·¢»Ó·¢»ÓÁË
¿ÉÄÜ´ó¼ÒÔç¾ÍÖªµÀÁË£¬²»¹ÜÔõô˵£¬·¢ÔÚÕâÀï°É£¡
×î½üÏëÆð¿ÉÄÜ»¹ÓÐЩasciiÂë¿ÉÒÔÓÃÀ´ÔÚsqlÓï¾äÖдúÌæ¿Õ¸ñ£¬ÓÚÊÇд¸ö½Å±¾²âÊÔ
ÁËһϣ¬½á¹ûÔÚËùÓÐ128¸öµÍλascii×Ö·ûÖУ¬chr(12)Ò²¿ÉÒÔÔÚaccessÀïÓ㬲»¹ý
Ã²ËÆchr(12)²»ÄܳöÏÖÔÚand¡¢orÖ®ÀàµÄ¹Ø¼ü´Ê¸½½ü£¬ÔÒò²»Çå³þ¡£mysqlÖбÈ
access¶àÒ»¸öchr(11)¿ÉÒÔ¡£ÖÁÓÚmssql£¬ÍÚÈÕ£¬Ö±½Ó´Ó1µ½32µÄasciiÂë»»³É×Ö·û
ºó¶¼¿ÉÒÔÕý³£Ê¹Óá£
Ïà¹ØÎĵµ£º
1¡¢ÏÂÔØ£ºÐèÒªÏÂÔØ2¸öÎļþ¡£ 1) sql server express studioÏÂÔØµØÖ·£º Microsoft SQL Server Management Studio Express http://www.microsoft.com/downloads/details.aspx?FamilyID=C243A5AE-4BD1-4E3D-94B8-5A0F62BF7796&displaylang=zh-cn ÔÙÏÂÔØ£º 2£©Microsoft SQL Server 2005 Express Edition http:// ......
2¡¢sql express °²×° Èç¹ûÔÚXPÏ£¬Ö±½ÓË«»÷°²×°¾ÍºÃÁË¡£ ÏȰ²×° [ÔÚvistaÏÂÈç¹ûÖ±½ÓË«»÷¿ÉÄÜ»á³öÏÖ °²×°sql server express ³ö´í29506 ] [Vista°²×°µÄʱºò£¬ÐèҪʹÓá°ÒÔ¹ÜÀíÔ±Éí·ÝÔËÐС±°²×°] SQLServer2005_SSMSEE.msi°²×°½áÊø studioÒѾ°²×°ÉÏÈ¥£¬µ«ÊÇÄãÓÐûÓз¢ÏÖ£¬°²×°sqlµÄʱºòûÓз¢ÏÖÓÐÓû§saµÄà ......
Ò»¡¢SQL SERVER ºÍACCESSµÄÊý¾Ýµ¼Èëµ¼³ö
³£¹æµÄÊý¾Ýµ¼Èëµ¼³ö£º
ʹÓÃDTSÏòµ¼Ç¨ÒÆÄãµÄAccessÊý¾Ýµ½SQL Server£¬Äã¿ÉÒÔʹÓÃÕâЩ²½Öè:
¡¡¡¡¡ð1ÔÚSQL SERVERÆóÒµ¹ÜÀíÆ÷ÖеÄTools£¨¹¤¾ß£©²Ëµ¥ÉÏ£¬Ñ¡ÔñData Transformation
¡¡¡¡¡ð2Services£¨Êý¾Ýת»»·þÎñ£©£¬È»ºóÑ¡Ôñ czdImport Dat ......
1.´ò¿ªSQL server enterprise mananger “ÆóÒµ¹ÜÀíÆ÷”
ÔÚÄãÒªµ¼³öµÄSQLÊý¾Ý¿âÉÏÊó±êÓÒ¼ü²Ëµ¥£ºËùÓÐÈÎÎñ-¡·µ¼³öÊý¾Ý
2.»Ø³öÏÖÒ»¸öµ¼³öÏòµ¼´°¿Ú¡£
Ñ¡Ôñ±»µ¼³öµÄÊý¾ÝÔ´£¬ÎªÄã¸Õ²ÅËùÑ¡ÔñµÄÊý¾Ý¿â£¬Èç¹û·¢ÏÖ²»¶ÔÓ¦×ÔÐÐÐ޸ġ£
3.½øÈëµ¼³öµ½Ä¿±êÊý¾ÝÔ´µÄÑ¡Ôñ£¬ÕâÀïÎÒÃÇҪת³ÉACCESSµÄÊý¾Ý¿â¡£×¢ÒâÑ¡ÔñÊý¾ÝÔ´ÀàÐÍÎ ......
http://www.umgr.com/blog/PostView.aspx?bpId=36294
1. Ö´ÐÐsqlÓï¾ä
int sqlite3_exec(sqlite3*£¬ const char *sql£¬ sqlite3_callbacksql Óï·¨
£¬ void *£¬ char **errmsg );
Õâ¾ÍÊÇÖ´ÐÐÒ»Ìõ sql Óï¾äµÄº¯Êý¡£
µÚ1¸ö²ÎÊý²»ÔÙ˵ÁË£¬ÊÇÇ°Ãæopenº¯ÊýµÃµ½µÄÖ¸Õ롣˵ÁËÊǹؼüÊý¾Ý½á¹¹¡£
µÚ2¸ö²ÎÊýconst char ......