sql server 2000 ÖеÄÊý¾ÝÀàÐÍ
declare @tmp_table table(tempvalue varchar(100) null)
insert into @tmp_table
select optname from dbo.MSreplication_options
select * from @tmp_table
alter table testTable
(
decimal_field decimal null,
datetime_field datetime null,
money_field money null,
numeric_field numeric null,
binary_field binary null,
sql_variant_field sql_variant null
)
alter table testTable
alter column decimal_field decimal(4,2)
insert into testTable(decimal_field) values(99.999)
insert into testTable(datetime_field) values('12/07/1998')
insert into testTable(datetime_field) values('12/07/1998')
insert into testTable(datetime_field) values(12/07/1998)
insert into testTable(datetime_field) values(12/07/1998)
insert into testTable(money_field) values(99999999999999.12345)
insert into testTable(money_field) values($999999.12345)
insert into testTable(money_field) values(cast('$999,999.12345' as money))
insert into testTable(binary_field) values(0xe)
insert into testTable (sql_variant_field) values('0xe')
insert into testTable (sql_variant_field) values(0xe)
insert into testTable (sql_variant_field) values(123)
insert into testTable (sql_variant_field) values(1234567.123)
select * from testTable
delete from testTable
create table Êý×ÖÊý¾Ý
(
decimal_number decimal(8,6),
numeric_number numeric(5,3)
)
insert into Êý×ÖÊý¾Ý
values(99.99999788,50)
insert into Êý×ÖÊý¾Ý
values(99.999999,300)
Ïà¹ØÎĵµ£º
1.´ò¿ªSQL server enterprise mananger “ÆóÒµ¹ÜÀíÆ÷”
ÔÚÄãÒªµ¼³öµÄSQLÊý¾Ý¿âÉÏÊó±êÓÒ¼ü²Ëµ¥£ºËùÓÐÈÎÎñ-¡·µ¼³öÊý¾Ý
2.»Ø³öÏÖÒ»¸öµ¼³öÏòµ¼´°¿Ú¡£
Ñ¡Ôñ±»µ¼³öµÄÊý¾ÝÔ´£¬ÎªÄã¸Õ²ÅËùÑ¡ÔñµÄÊý¾Ý¿â£¬Èç¹û·¢ÏÖ²»¶ÔÓ¦×ÔÐÐÐ޸ġ£
3.½øÈëµ¼³öµ½Ä¿±êÊý¾ÝÔ´µÄÑ¡Ôñ£¬ÕâÀïÎÒÃÇҪת³ÉACCESSµÄÊý¾Ý¿â¡£×¢ÒâÑ¡ÔñÊý¾ÝÔ´ÀàÐÍÎ ......
Ò»°ã¹úÄÚµÄСһµãµÄÐÂÎÅÕ¾µã³ÌÐò ¶¼ÓÐ ""&request ÕâÖÖ©¶´£¬ÏÂÃæÎÒ½²½â¹¥»÷·½·¨
ÔÚµØÖ·À¸£º
and 1=1
²é¿´Â©¶´ÊÇ·ñ´æÔÚ,Èç¹û´æÔÚ¾ÍÕý³£·µ»Ø¸ÃÒ³,Èç¹ûûÓÐ,ÔòÏÔʾ´íÎ󣬼ÌÐø¼ÙÉèÕâ¸öÕ¾µÄÊý¾Ý¿â´æÔÚÒ»¸öadmin±í
ÔÚµØÖ·À¸£º
and 0<>(select count(*) from admin)
·µ»ØÒ³Õý³£,¼ÙÉè³ÉÁ¢ÁË¡£
ÏÂÃæÀ´²Â²Â¿´ ......
BSϵͳÖУ¬´«Í³µÄ×¢Èë¹¥»÷ÊÖ¶ÎÓкܶࡣ
×î»ù±¾µÄ£¬ÀûÓõ¥ÒýºÅ¹¥»÷µÄ£¬ºÜÈÝÒ×½â¾ö£¬ÓÃÀàËÆÓÚQuotedStr()£¨Êµ¼Ê¿ª·¢ÊÇÆäËûÓïÑÔ£¬ÕâÀïÓÃDELPHIÖеĺ¯Êý´úÌæ£©µÄº¯Êý´¦Àí²ÎÊý¼´¿É¡£
µ«Êµ¼ÊÓ¦ÓÃÖУ¬²»¿É±ÜÃâ»áÓÐһЩӦÓÃÐèÒªÖ±½Ó´«µÝ²ÎÊý£¬ÀýÈç±íÃû¡¢²éѯÌõ¼þ¡¢ÅÅÐòÌõ¼þµÈµÈ
¶ÔÕâЩӦÓõÄ×¢Èë¹¥»÷·À²»Ê¤·À¡£
ÎÒ¿¼ÂÇÁËÒ»¸ ......
´´½¨Îļþ¼Ð£ºexec xp_cmdshell 'md ÅÌ·û:\Îļþ¼ÐÃû³Æ', no_output
ÀýÈ磺ÔÚDÅÌ´´½¨ÃûΪ£º“×ÊÁÏ”µÄÎļþ¼Ð£ºexec xp_cmdshell 'md d:\×ÊÁÏ', no_output
²é¿´Îļþ£ºexec xp_cmdshell 'dirÅÌ·û:\Îļþ¼ÐÃû³Æ'¡£ÀýÈ磺exec xp_cmdshell 'dir d:\×ÊÁÏ'
ÅжÏÊý¾Ý¿âÊÇ·ñ´æÔÚ£ºif exists(select * from sysdat ......
PL/SQLµ¥Ðк¯ÊýºÍ×麯ÊýÏê½â
¡¡ º¯ÊýÊÇÒ»ÖÖÓÐÁã¸ö»ò¶à¸ö²ÎÊý²¢ÇÒÓÐÒ»¸ö·µ»ØÖµµÄ³ÌÐò¡£ÔÚSQLÖÐOracleÄÚ½¨ÁËһϵÁк¯Êý£¬ÕâЩº¯Êý¶¼¿É±»³ÆÎªSQL»òPL/SQLÓï¾ä£¬º¯ÊýÖ÷Òª·ÖΪÁ½´óÀࣺ
¡¡¡¡ µ¥Ðк¯Êý ×麯Êý
¡¡¡¡SQLÖеĵ¥Ðк¯Êý
¡¡¡¡SQLºÍPL/SQLÖÐ×Ô´øºÜ¶àÀ ......