ºÃ³¤µÄSQL£¡
select a.FRMNO,a.GATE,a.MSGID,a.MailSendTime,a.UserNM, a.MailSubject,a.IsRead,a.FRMID,a.isattach,b.STATE ,a.FLOWSTATE from ROAMSGE a, ROASTAT b where a.FRMID = b.FRMID and b.state='1' and a.FrmNm like '%" + Cdorpsel1 + "%' and a.MAILSENDTIME>to_date('" + date1 + "','YYYY-MM-DD') and a.MAILSENDTIME<=to_date('" + date2 + "','YYYY-MM-DD')+1 and a.ToUserId='" + flw_LogonId + "' order by MAILSENDTIME desc
Ïà¹ØÎĵµ£º
Sql´úÂë
--²ÉÓÃSQLÓï¾äʵÏÖsql2005ºÍExcel Êý¾ÝÖ®¼äµÄÊý¾Ýµ¼Èëµ¼³ö£¬ÔÚÍøÉÏÕÒÀ´Ò»--Ï£¬ÊµÏÖ·½·¨ÊÇÕâÑùµÄ£º
--Excel---->SQL2005 µ¼È룺
select * into useinfo from O ......
1.Ñ¡Ôñ×îÓÐЧÂʵıíÃû˳Ðò(Ö»ÔÚ»ùÓÚ¹æÔòµÄÓÅ»¯Æ÷ÖÐÓÐЧ)¡¡¡¡
¡¡¡¡ SQLSERVERµÄ½âÎöÆ÷°´ÕÕ´ÓÓÒµ½×óµÄ˳Ðò´¦Àífrom×Ó¾äÖеıíÃû£¬Òò´Ëfrom×Ó¾äÖÐдÔÚ×îºóµÄ±í£¨»ù´¡±ídriving table£©½«±»×îÏÈ´¦Àí£¬ÔÚfrom×Ó¾äÖаüº¬¶à¸ö±íµÄÇé¿öÏ£¬±ØÐëÑ¡Ôñ¼Ç¼ÌõÊý×îÉٵıí×÷Ϊ»ù´¡±í£¬µ±SQLSERVER´¦Àí¶à¸ö±íʱ£¬»áÔËÓÃÅÅÐò¼°ºÏ²¢µÄ·½Ê½Á ......
×÷Õß: ÈýÊ®¶øÁ¢Ê±¼ä£º2009Äê10ÔÂ15ÈÕ 19:21:13±¾Îijö×Ô ¡°inthirties£¨ÈýÊ®¶øÁ¢£©¡±²©¿Í£¬×ªÔØÇëÎñ±Ø×¢Ã÷×÷Õߺͱ£Áô³ö´¦http://blog.csdn.net/inthirties/archive/2009/10/15/4673331.aspx ѧϰÊÇ¿ÝÔïµÄ£¬ËùÒÔ×÷Ϊһ¸öѧϰÕߣ¬ÒªÑ§»áÔÚѧϰÖÐÕÒµ½¿ìÀÖ£¬ÕâÑù²ÅÄܼ¤·¢ÐËȤ£¬ÐËȤÊÇ×îºÃµÄÀÏʦ£¬ÕâÑù£¬Ñ§Ï°¾ÍÂýÂýµÄ±ä³ÉÁËÒ»¼þ ......
select * from student where name=?;
Èç¹û²»Óõ¥ÒýºÅÒýÆðÀ´£¬ pstmt.setString(1,"xx or 1=1");¼´sqlÓ¦¸Ã¾ÍÊÇselect * from student where name=xx or 1=1¾Í¿ÉÒÔÈ«²¿²é³ö¡£
Ç¿ÖƵ¥ÒýºÅÒýÆðÀ´£¬select * from student where name='xx or 1=1'¡£¾ÍÎÞЧÁË¡£
ÊýÖµÐ͵ÄûÓÐÒªÇóÓõ¥ÒýºÅÒýÆðÀ´£¬Ó¦¸ÃÊÇÓÉÓÚÓÐÒ»¸öת»»¹ý ......
ÕâÊÇÎÒ±ßѧ±ß×ܽáµÄ£¬×ܹ²»¨ÁËÒ»ÌìÒ»Ò¹µÄʱ¼ä£¬²é×ÊÁϺͿ´ÊÓƵÍê³ÉµÄ£¬µ«ÎÒ¶Ôµ¥Ðк¯ÊýºÍ¶àÐк¯ÊýûÓÐ×ö¹ý¶àµÄÑо¿£¬ÒòΪÕß¿ÉÒÔ²éÎĵµ¡£»¹ÓоÍÊǶà±í²éѯÑо¿Ò²±È½Ïdz£¬Õâ¿ÉÒÔÔÚÒÔºóÓõ½µÄʱºòÔÚ¾ßÌåÑо¿¡£ »¹ÓоÍÊÇÒªÊìϤÊý¾Ý¿âµÄ²Ù×÷£¬Ôöɾ¸Ä²é£¬ÕâЩ¶¼ÒªÏ൱ÊìÁ·£¬Íü¼ÇʱҪ¼°Ê±¿´±Ê¼Ç¡£
SQL
1....... ......