SQL×¢Èë¹¥»÷µÄÔÀí¼°Æä·À·¶´ëÊ©
ת£ºhttp://blog.csdn.net/flyfranker/archive/2009/01/08/3733764.aspx
ASP±à³ÌÃż÷ºÜµÍ£¬ÐÂÊÖºÜÈÝÒ×ÉÏ·¡£ÔÚÒ»¶Î²»³¤µÄʱ¼äÀÐÂÊÖÍùÍù¾ÍÒѾÄܹ»±à³ö¿´À´±È½ÏÍêÃÀµÄ¶¯Ì¬ÍøÕ¾£¬ÔÚ¹¦ÄÜÉÏ£¬ÀÏÊÖÄÜ×öµ½µÄ£¬ÐÂÊÖÒ²Äܹ»×öµ½¡£ÄÇôÐÂÊÖÓëÀÏÊÖ¾ÍÃ»Çø±ðÁËÂð£¿ÕâÀïÃæÇø±ð¿É¾Í´óÁË£¬Ö»²»¹ýÍâÐÐÈ˺ÜÄÑÒ»Ñ۾Ϳ´³öÀ´°ÕÁË¡£ÔÚ½çÃæµÄÓѺÃÐÔ¡¢ÔËÐÐÐÔÄÜÒÔ¼°ÍøÕ¾µÄ°²È«ÐÔ·½ÃæÊÇÐÂÊÖÓëÀÏÊÖÖ®¼äÇø±ðµÄÈý¸ö¼¯Öе㡣¶øÔÚ°²È«ÐÔ·½Ã棬ÐÂÊÖ×îÈÝÒ׺öÂÔµÄÎÊÌâ¾ÍÊÇSQL×¢Èë©¶´µÄÎÊÌâ¡£ÓÃNBSI 2.0¶ÔÍøÉϵÄһЩASPÍøÕ¾ÉÔ¼ÓɨÃ裬¾ÍÄÜ·¢ÏÖÐí¶àASPÍøÕ¾´æÔÚSQL×¢Èë©¶´£¬½ÌÓýÍøÀï¸ßУÄÚ²¿»ú¹¹µÄÒ»Ð©ÍøÕ¾ÕâÖÖ©¶´¾Í¸üÆÕ±éÁË£¬¿ÉÄÜÕâÊÇÒòΪÕâÐ©ÍøÕ¾´ó¶¼ÊÇһЩѧÉú×öµÄÔµ¹Ê°É£¬ËäÈ»¸ö¸ö¶¼ºÜ´ÏÃ÷£¬¿ÉÊDZϾ¹Ã»ÓоÑ飬¶øÇÒ´¦ÓÚѧϰÖУ¬ÄÑÃâ©¶´¶à¶àÁË¡£±¾ÎÄÖ÷Òª½²½²SQL×¢ÈëµÄ·À·¶´ëÊ©£¬¶øÒªÃ÷°×ÕâЩ·À·¶´ëÊ©µÄÓô¦£¬ÐëÏÈÏêϸ½²½âÀûÓÃSQL×¢Èë©¶´ÈëÇֵĹý³Ì¡£ÐÂÊÖÃÇ¿´Ã÷°×À²¡£
¡¡¡¡Ï൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£ÈçÕâÊÇÒ»¸öÕý³£µÄÍøÖ·http://localhost/lawjia/show.asp?ID=444£¬½«Õâ¸öÍøÖ·Ìá½»µ½·þÎñÆ÷ºó£¬·þÎñÆ÷½«½øÐÐÀàËÆSelect * from ±íÃû where ×Ö¶Î="&IDµÄ²éѯ(ID¼´¿Í»§¶ËÌá½»µÄ²ÎÊý£¬±¾ÀýÊǼ´444)£¬ÔÙ½«²éѯ½á¹û·µ»Ø¸ø¿Í»§¶Ë£¬Èç¹ûÕâÀï¿Í»§¶Ë¹ÊÒâÌá½»Õâôһ¸öÍøÖ·£º
¡¡¡¡http://localhost/lawjia/show.asp?ID=444 and user>0£¬Õâʱ£¬·þÎñÆ÷ÔËÐÐSelect * from ±íÃû where ×Ö¶Î=444 and user>0ÕâÑùµÄ²éѯ£¬µ±È»£¬Õâ¸öÓï¾äÊÇÔËÐв»ÏÂÈ¥µÄ£¬¿Ï¶¨³ö´í£¬´íÎóÐÅÏ¢ÈçÏ£º
¡¡¡¡·´íÎóÀàÐÍ£º
Microsoft OLE DB Provider for ODBC Drivers (0x80040E07)
[Microsoft][ODBC SQL Server Driver][SQL Server]½« nvarchar Öµ 'sonybb' ת»»ÎªÊý¾ÝÀàÐÍΪ int µÄÁÐʱ·¢ÉúÓï·¨´íÎó¡£
/lawjia/show.asp, µÚ 47 ÐÐ
¡¡¡¡µ«ÊDZðÓÐÓÃÐĵÄÈË´ÓÕâ¸ö³ö´íÐÅÏ¢ÖУ¬¿ÉÒÔ»ñµÃÒÔÏÂÐÅÏ¢£º¸ÃվʹÓÃMS£ßSQLÊý¾Ý¿â£¬ÓÃODBCÁ¬½Ó£¬Á¬½ÓÕʺÅÃûΪ£ºsonybb¡£ËùνSQL×¢È루SQL Injection£©£¬¾ÍÊÇÀûÓóÌÐòÔ±¶ÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ¼ì²â²»ÑÏ»ò²»¼ì²âµÄÌØµã£¬¹ÊÒâ´Ó¿Í»§¶ËÌá½»ÌØÊâµÄ´úÂ룬´Ó¶øÊÕ¼¯³ÌÐò¼°·þÎñÆ÷µÄÐÅÏ¢£¬´Ó¶ø»ñÈ¡ÏëµÃµ½µÄ×ÊÁÏ¡£Í¨³£±ðÓÐÓÃÐÄÕßµÄÄ¿±êÊÇ»ñÈ¡ÍøÕ¾¹ÜÀíÔ±µÄÕʺźÍÃÜÂë¡£±ÈÈ統ij¸öÈËÖªµÀÍøÕ¾¹ÜÀíÔ±ÕʺŴæÔÚ±íloginÖУ¬¹ÜÀíÔ±ÕʺÅÃûΪadmin£¬ËûÏëÖªµÀ¹ÜÀíÔ±ÃÜÂ룬ÕâÀïËû´Ó¿Í»§¶Ë½Ó×ÅÌá½»ÕâÑùÒ»¸öÍøÖ
Ïà¹ØÎĵµ£º
ÎÒÃÇʹÓÃoracleµÄÈ˶¼ÖªµÀ¿ÉÒÔͨ¹ýrownumαÁеõ½²éѯ½á¹ûÐòÁÐÇ°ÃæµÄÖ¸¶¨µÄÐУ¬ÎªÁËÏÂÃæ¸üºÃµÄ½øÐÐ˵Ã÷ÎÊÌ⣬ÎÒÃÇÏÈÀ´´´½¨Ò»¸öÊý¾Ý±ítable1£º
create table table1
(AAA integer primary key,
BBB varchar(30));
È»ºóÔÚtable1ÖвåÈë9ÌõÊý¾Ý£º
insert into table1 values (8, 'good');
insert into table1 values (7 ......
×°ÁËSQL2000ºó°²×°SQL2005,ËäȻʹÓñðÃû¼ÓÒÔÇø±ðÁË£¬µ«·¢ÏÖ2005ÖÐûÓпɹ©·ÃÎʵÄÀàËÆÆóÒµ¹ÜÀíÆ÷£¬Ò»Ê±³å¶¯£¬Ð¶ÁË2000£¬ÍêÕû°²×°ÁË2005£¬·¢ÏÖ»¹ÊÇûÓÐÆóÒµ¹ÜÀíÆ÷£¬ËÑË÷¹ýºó²Å·¢ÏÖÐèÒª°²×°SQLServer2005_SSMSEE.msi£¨¼´SQLServerManagerStudioExpressEdition£©£¬ËüÌṩÁËÀàËÆÆóÒµ¹ÜÀíÆ÷µÄͼÐλ¯²Ù×÷½çÃæ¡£
×°ºÃºó£¬SQL ......
ÔÚijЩ³¡ºÏÏ£¬´æ´¢¹ý³Ì»ò´¥·¢Æ÷ÀïµÄSQLÓï¾äÐèÒª¶¯Ì¬Éú³É¡£OracleµÄDBMS_SQL°ü¿ÉÒÔÓÃÀ´Ö´Ðж¯Ì¬SQLÓï¾ä¡£±¾ÎÄͨ¹ýÒ»¸ö¼òµ¥µÄÀý×ÓÀ´Õ¹Ê¾ÈçºÎÀûÓÃDBMS_SQL°üÖ´Ðж¯Ì¬SQLÓï¾ä£º
DECLARE
v_cursor NUMBER;
v_stat NUMBER;
& ......
SQL Server 2000 Êý¾Ý¿âͬ²½ÅäÖõÄÔÀí
¸´ÖƵĸÅÄî
Microsoft? SQL Server? 2000 µÄ¸´ÖÆÊÇÔÚÊý¾Ý¿âÖ®¼ä¶ÔÊý¾ÝºÍÊý¾Ý¿â¶ÔÏó½øÐи´ÖÆ
ºÍ·Ö·¢²¢½øÐÐͬ²½ÒÔÈ·±£ÆäÒ»ÖÂÐÔµÄÒ»×é¼¼Êõ¡£
ʹÓø´ÖÆ¿ÉÒÔ½«Êý¾Ý·Ö·¢µ½²»Í¬Î»Öã¬Í¨¹ý¾ÖÓòÍø¡¢Ê¹Óò¦ºÅÁ¬½Ó¡¢Í¨¹ý Internet ·Ö
·¢¸øÔ¶³Ì»òÒÆ¶¯Óû§¡£¸´ÖÆ»¹Äܹ»Ê¹Óû§Ìá¸ßÓ¦ÓóÌÐòÐÔÄÜ ......
SQL Server CE 2.0µÄÈ«ÃûÊÇSQL Server 2000 Windows CE Edition version 2.0¡£
Àý×Ó1£º¹«Ë¾ÅÉÈËÈ¥²Ö¿âÑé»õ¡¢µã»õ£¬¿ÉÒÔ°ÑÇ嵥ͬ²½µ½Pocket PCÉÏ£¬È»ºóÔÚ²Ö¿âÀïÃæÖ±½ÓÔÚPPCÉÏÃæupdate£¬»Øµ½¹«Ë¾Ò»Í¬²½¾Í¿ÉÒÔÁË¡£·ñÔò°´ÕÕÔÏÈ×ö·¨£¬ÐèÒªÏÈ´òÓ¡Ò»ÕÅÇåµ¥£¬»ØÀ´ÒÔºóÔÙ¼ÈëÒ»±é¡£
Àý×Ó2£ºÁªÏëÅÉÈËÉÏÃÅÀ´ÐÞµçÄÔ£¬ÒÔǰ×ÜÊÇ´ ......