Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

ÈçºÎ·ÀÖ¹SQL×¢Èë¹¥»÷

BSϵͳÖУ¬´«Í³µÄ×¢Èë¹¥»÷ÊÖ¶ÎÓкܶࡣ
×î»ù±¾µÄ£¬ÀûÓõ¥ÒýºÅ¹¥»÷µÄ£¬ºÜÈÝÒ×½â¾ö£¬ÓÃÀàËÆÓÚQuotedStr()£¨Êµ¼Ê¿ª·¢ÊÇÆäËûÓïÑÔ£¬ÕâÀïÓÃDELPHIÖеĺ¯Êý´úÌæ£©µÄº¯Êý´¦Àí²ÎÊý¼´¿É¡£
µ«Êµ¼ÊÓ¦ÓÃÖУ¬²»¿É±ÜÃâ»áÓÐһЩӦÓÃÐèÒªÖ±½Ó´«µÝ²ÎÊý£¬ÀýÈç±íÃû¡¢²éѯÌõ¼þ¡¢ÅÅÐòÌõ¼þµÈµÈ
¶ÔÕâЩӦÓõÄ×¢Èë¹¥»÷·À²»Ê¤·À¡£
ÎÒ¿¼ÂÇÁËÒ»¸ö˼·£¬¹©´ó¼Ò²Î¿¼¡£
1 ¶ÔËùÓÐÍøÒ³´«ÈëµÄ²ÎÊý·ÖÈýÖÖ¡£
  a) Êý×ÖÀàÐÍ£¬ÓÃStrToIntº¯Êý´¦Àí¡£
  b) ×Ö·û´®ÀàÐÍ£¬ÓÃQuotedStrº¯Êý´¦Àí¡£
  c) ÐèÒªÖ±½Ó´«µÝµÄ²ÎÊý£¬ÕâÊÇÐèÒª×ÅÖØ¿¼ÂǵÄÀàÐÍ¡£
2 ¶ÔËùÓÐÊý¾Ý¿â²Ù×÷Ö÷Òª·ÖÎåÖÖ£¬²»ÔÊÐí³ÌÐòÖ±½ÓÖ´ÐÐSQLÓï¾ä£º
  a) select ²éѯ
  b) update ¸üÐÂ
  c) insert ÐÂÔö
  d) delete ɾ³ý
  e) exec Ö´Ðд洢¹ý³Ì
3 ¶ÔÓÚÒÔÉϼ¸ÖÖÊý¾Ý¿â²Ù×÷µÄËùÓвÎÊý£¬ÀýÈçselect ²Ù×÷ÖÐµÄ ²éѯÌõ¼þ¡¢ÅÅÐòÌõ¼þµÈ£¬¶¼½øÐкϷ¨ÐÔУÑ飺
  a) ÀïÃæ´æÔÚ "--" "/*" "*/" µÄ£¬¶¼ÊÓΪ·Ç·¨Ìõ¼þ¡£
  b) ½«Ìõ¼þ²ð·ÖΪµ¥´Ê£¬Èç¹û´æÔÚÒÔϵ¥´Ê£ºdelete insert update exec execute create drop grantµÄ£¬¶¼ÊÓΪ·Ç·¨Ìõ¼þ¡££¨Õý³£µÄ±íÃû¡¢×Ö¶ÎÃûÖв»¿ÉÄÜÓÐÉÏÃæÕâЩ¹Ø¼ü×Ö°É¡££©
  c) ´«ÈëµÄ²éѯÌõ¼þ£¬Ð£ÑéÀïÃæµÄÀ¨ºÅ£¬·²ÊÇÓÒÀ¨ºÅÔÚ×óÀ¨ºÅÇ°Ãæ£¨²»Åä¶Ô£©µÄ£¬¶¼ÊÓΪ·Ç·¨Ìõ¼þ¡£
  d) ´«ÈëµÄ²éѯÌõ¼þ£¬Ç°ºó¼ÓÀ¨ºÅ¡£
¾­¹ýÒÔÉÏУÑ飬Ӧ¸Ã»ù±¾¿ÉÒÔ±£Ö¤²ÎÊýÊÇÕý³£µÄ²ÎÊý£¬¹©´ó¼Ò²Î¿¼¡£Í¬Ê±Ò²Ï£Íû´ó¼ÒÄÜÕÒ³öÆäÖеÄ©¶´£¬ÎÒ¿ÉÒÔ½øÐиĽø^_^


Ïà¹ØÎĵµ£º

½â¾öSQL ServerתACCESS×Ô¶¯±àºÅÎÊÌâ


1.´ò¿ªSQL server enterprise mananger “ÆóÒµ¹ÜÀíÆ÷”
ÔÚÄãÒªµ¼³öµÄSQLÊý¾Ý¿âÉÏÊó±êÓÒ¼ü²Ëµ¥£ºËùÓÐÈÎÎñ-¡·µ¼³öÊý¾Ý
2.»Ø³öÏÖÒ»¸öµ¼³öÏòµ¼´°¿Ú¡£
Ñ¡Ôñ±»µ¼³öµÄÊý¾ÝÔ´£¬ÎªÄã¸Õ²ÅËùÑ¡ÔñµÄÊý¾Ý¿â£¬Èç¹û·¢ÏÖ²»¶ÔÓ¦×ÔÐÐÐ޸ġ£
3.½øÈëµ¼³öµ½Ä¿±êÊý¾ÝÔ´µÄÑ¡Ôñ£¬ÕâÀïÎÒÃÇҪת³ÉACCESSµÄÊý¾Ý¿â¡£×¢ÒâÑ¡ÔñÊý¾ÝÔ´ÀàÐÍÎ ......

ʹÓÃSQLServerÄ£°åÀ´Ð´¹æ·¶µÄSQLÓï¾ä

Èç¹ûÄã¾­³£Óöµ½ÏÂÃæµÄÎÊÌ⣬Äã¾ÍÒª¿¼ÂÇʹÓÃSQL ServerµÄÄ£°åÀ´Ð´¹æ·¶µÄSQLÓï¾äÁË£º
SQL³õѧÕß¡£
¾­³£Íü¼Ç³£ÓõÄDML»òÊÇDDL SQL Óï¾ä¡£
ÔÚ¶àÈË¿ª·¢Î¬»¤µÄSQLÖУ¬Ã¿¸öÈ˶¼ÓÐ×Ô¼ºµÄSQLϰ¹ß£¬Ã»ÓÐÒ»Ì×ͳһµÄ¹æ·¶¡£
ÔÚSQL Server Management StudioÖУ¬ÒѾ­¸ø´ó¼ÒÌṩÁ˺ܶೣÓõÄÏÖ³ÉSQL¹æ·¶Ä£°å¡£
SQL Server Management ......

SQL SERVER¶àÁÐÈ¡×î´ó»òÕß×îСֵ

/*
lvl1  lvl2    lvl3    lvl4    lvl
4      3      4      1       
3      2      2&nb ......

SQL¸ßÊÖÆª:¾«ÃîSQLÓï¾ä½éÉÜ

 ËµÃ÷£º¸´ÖƱí(Ö»¸´Öƽṹ,Ô´±íÃû£ºa бíÃû£ºb)
¡¡¡¡SQL: select * into b from a where 1<>1 ¡¡¡¡
¡¡¡¡ËµÃ÷£º¿½±´±í(¿½±´Êý¾Ý,Ô´±íÃû£ºa Ä¿±ê±íÃû£ºb)
¡¡¡¡SQL: insert into b(a, b, c) select d,e,f from b; ¡¡¡¡
¡¡¡¡ËµÃ÷£ºÏÔʾÎÄÕ¡¢Ìá½»È˺Í×îºó»Ø¸´Ê±¼ä
¡¡¡¡SQL: select a.title,a.username,b. ......

²ËÄñѧϰSQL×¢Éä

 Ò»°ã¹úÄÚµÄСһµãµÄÐÂÎÅÕ¾µã³ÌÐò ¶¼ÓÐ ""&request ÕâÖÖ©¶´£¬ÏÂÃæÎÒ½²½â¹¥»÷·½·¨
ÔÚµØÖ·À¸£º
and 1=1
²é¿´Â©¶´ÊÇ·ñ´æÔÚ,Èç¹û´æÔÚ¾ÍÕý³£·µ»Ø¸ÃÒ³,Èç¹ûûÓÐ,ÔòÏÔʾ´íÎ󣬼ÌÐø¼ÙÉèÕâ¸öÕ¾µÄÊý¾Ý¿â´æÔÚÒ»¸öadmin±í
ÔÚµØÖ·À¸£º
and 0<>(select count(*) from admin)
·µ»ØÒ³Õý³£,¼ÙÉè³ÉÁ¢ÁË¡£
ÏÂÃæÀ´²Â²Â¿´ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ