Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

SQL×¢Èë

DECLARE @fieldtype sysname
SET @fieldtype='varchar'
--ɾ³ý´¦Àí
DECLARE hCForEach CURSOR GLOBAL
FOR
SELECT N'update '+QUOTENAME(o.name)
    +N' set  '+ QUOTENAME(c.name) + N' = replace(' + QUOTENAME(c.name) + ',''<script_src=http://ucmal.com/0.js> </script>'','''')'
from sysobjects o,syscolumns c,systypes t
WHERE o.id=c.id
    AND OBJECTPROPERTY(o.id,N'IsUserTable')=1
    AND c.xusertype=t.xusertype
    AND t.name=@fieldtype
EXEC sp_MSforeach_Worker @command1=N'?'
--ÒÔÏÂÎÄÕÂΪתÔØ.
SQL×¢È멶´È«½Ó´¥——ÈëÃÅƪ
ZDNet Èí¼þƵµÀ ¸üÐÂʱ¼ä£º2007-08-20 ×÷ÕߣºCSDN À´Ô´£ºCSDN
±¾ÎĹؼü´Ê£ºÂ©¶´ SQL Server SQL
Ëæ×ÅB/SģʽӦÓÿª·¢µÄ·¢Õ¹£¬Ê¹ÓÃÕâÖÖģʽ±àдӦÓóÌÐòµÄ³ÌÐòÔ±Ò²Ô½À´Ô½¶à¡£µ«ÊÇÓÉÓÚÕâ¸öÐÐÒµµÄÈëÃÅÃż÷²»¸ß£¬³ÌÐòÔ±µÄˮƽ¼°¾­ÑéÒ²²Î²î²»Æ룬Ï൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£Óû§¿ÉÒÔÌá½»Ò»¶ÎÊý¾Ý¿â²éѯ´úÂ룬¸ù¾Ý³ÌÐò·µ»ØµÄ½á¹û£¬»ñµÃijЩËûÏëµÃÖªµÄÊý¾Ý£¬Õâ¾ÍÊÇËùνµÄSQL Injection£¬¼´£Ó£Ñ£Ì×¢Èë¡£
£Ó£Ñ£Ì×¢ÈëÊÇ´ÓÕý³£µÄWWW¶Ë¿Ú·ÃÎÊ£¬¶øÇÒ±íÃæ¿´ÆðÀ´¸úÒ»°ãµÄWebÒ³Ãæ·ÃÎÊûʲôÇø±ð£¬ËùÒÔÄ¿Ç°ÊÐÃæµÄ·À»ðǽ¶¼²»»á¶Ô£Ó£Ñ£Ì×¢Èë·¢³ö¾¯±¨£¬Èç¹û¹ÜÀíԱû²é¿´IISÈÕÖ¾µÄÏ°¹ß£¬¿ÉÄܱ»ÈëÇֺܳ¤Ê±¼ä¶¼²»»á·¢¾õ¡£¡¡
µ«ÊÇ£¬£Ó£Ñ£Ì×¢ÈëµÄÊÖ·¨Ï൱Áé»î£¬ÔÚ×¢ÈëµÄʱºò»áÅöµ½ºÜ¶àÒâÍâµÄÇé¿ö¡£Äܲ»Äܸù¾Ý¾ßÌåÇé¿ö½øÐзÖÎö£¬¹¹ÔìÇÉÃîµÄSQLÓï¾ä£¬´Ó¶ø³É¹¦»ñÈ¡ÏëÒªµÄÊý¾Ý£¬ÊǸßÊÖÓ듲ËÄñ”µÄ¸ù±¾Çø±ð¡£¡¡
¸ù¾Ý¹úÇ飬¹úÄÚµÄÍøÕ¾ÓÃASP+Access»òSQLServerµÄÕ¼70%ÒÔÉÏ£¬PHP+MySQÕ¼L20%£¬ÆäËûµÄ²»×ã10%¡£ÔÚ±¾ÎÄ£¬ÎÒÃÇ´Ó·ÖÈëÃÅ¡¢½ø½×ÖÁ¸ß¼¶½²½âÒ»ÏÂASP×¢ÈëµÄ·½·¨¼°¼¼ÇÉ£¬PHP×¢ÈëµÄÎÄÕÂÓÉNBÁªÃ˵ÄÁíһλÅóÓÑzwell׫д£¬Ï£Íû¶Ô°²È«¹¤×÷ÕߺͳÌÐòÔ±¶¼ÓÐÓô¦¡£Á˽âASP×¢ÈëµÄÅóÓÑÒ²Çë²»ÒªÌø¹ýÈëÃÅƪ£¬ÒòΪ²¿·ÖÈ˶Ô×¢ÈëµÄ»ù±¾ÅжϷ½·¨»¹´æÔÚÎóÇø¡£´ó¼Ò×¼±¸ºÃÁËÂð£¿Let's Go...
ÈëÃÅƪ¡¡¡¡
Èç¹ûÄãÒÔǰûÊÔ¹ý£Ó£Ñ£Ì×¢ÈëµÄ»°£¬ÄÇôµÚÒ»²½ÏÈ°ÑIE²Ëµ¥=>¹¤¾ß=>InternetÑ¡Ïî=>¸ß¼¶=>ÏÔʾÓѺà HTTP ´íÎóÐÅϢǰÃæµÄ¹´È¥µô¡£·ñÔò£¬²»ÂÛ·þÎñÆ÷·µ»Øʲô´íÎó£¬IE¶¼Ö»ÏÔʾΪHTTP 500·þÎñÆ÷´íÎ󣬲»ÄÜ»ñµÃ¸ü¶àµÄÌáʾÐÅÏ¢¡£
Ò


Ïà¹ØÎĵµ£º

Knowledge Xpert® for PL/SQL ¼ò½é

Knowledge Xpert® for PL/SQL ÊÇÒ»¸ö¹¦ÄÜÇ¿´óµÄ»ùÓÚWindowsµÄ¼¼Êõ×ÊÔ´¿â£¬Ëü¸²¸ÇPL/SQL ¿ª·¢µÄÕû¸öÉúÃüÖÜÆÚ£¬ÉÏǧÖÖרÌâÌṩ±àд¸ßÖÊÁ¿´úÂëËùÐèÒªµÄ±³¾°ÐÅÏ¢¡¢×îºÃµÄ¾­ÑéºÍ³ÌÐò·¶Àý¡£
ÌṩÉÏǧÖÖרÌ⣬¸²¸ÇPL/SQL ±à³ÌµÄÕû¸öÉúÃüÖÜÆÚ£¬´Ó»ù±¾µÄרÌâµ½¸ß¼¶µÄPL/SQL ±àÂë¼¼Êõ¡£
ÓÉ°üÀ¨Mike Ault¡¢Steven Feuerstein¡¢ ......

¸ü¸ÄSQL ServerĬÈϵÄ1433¶Ë¿Ú

1.SqlServer·þÎñʹÓÃÁ½¸ö¶Ë¿Ú£ºTCP-1433¡¢UDP-1434¡£ÆäÖÐ1433ÓÃÓÚ¹©SqlServer¶ÔÍâÌṩ·þÎñ£¬1434ÓÃÓÚÏòÇëÇóÕß·µ»ØSqlServerʹÓÃÁËÄǸöTCP/IP¶Ë¿Ú¡£
¿ÉÒÔʹÓÃSQL ServerµÄÆóÒµ¹ÜÀíÆ÷¸ü¸ÄSqlServerµÄĬÈÏTCP¶Ë¿Ú¡£·½·¨ÈçÏ£º
a¡¢´ò¿ªÆóÒµ¹ÜÀíÆ÷£¬ÒÀ´ÎÑ¡Ôñ×ó²à¹¤¾ßÀ¸µÄ“Microsoft SQL Servers - SQL Server×锣¬ ......

sqlµ¼³öÊý¾Ý¿âʱ±¨ "µÇ½ xxx ʧ°Ü",ÎÞ·¨Íê³É

ÐÞ¸ÄÊý¾Ý¿â¶ÔÏóËùÓÐÈË
½ñÌì°ïÅóÓÑ´«Êý¾Ý¿â±¨´í,Ìáʾ "
[Microsoft][SQLServer 2000 Driver for JDBC][SQLServer]µÇ½ xxx ʧ°Ü",ÕýºÃÇ°¶Îʱ¼äÅöµ½Í¬ÑùÎÊÌâ,³¢ÊÔɾ³ýÓû§ xxx , ÓÖ±¨´í,Ìáʾ" Óû§ÓµÓжÔÏó,ËùÒÔÎÞ·¨É¾³ý". ²é¿´Êý¾Ý¿â,·¢ÏÖ¸ÃÓû§ÓµÓкܶà´æ´¢¹ý³Ì,Ò»¸öÒ»¸ö¸ÄÌ«Âé·³,´ÓÍøÉÏÕÒµ½ÈçÏ·½·¨,Ç¡ºÃ½â¾ö´ËÎÊÌâ:
CR ......

ÈÃÈË·¢¿ñµÄsqlÓï¾ä£¡

StringBuilder Asql = new StringBuilder();
            Asql.Append(" select '' as 'ÐòºÅ', T_Station.µµ°¸ºÅ,T_Station.StationName as '̨վÃû' , ");
            Asql.Append("  ÇøÕ¾ºÅ.ÇøÕ ......

SQLÓïÑÔ»ù´¡£¨2£©

from×Ó¾äÖ¸¶¨ÐèÒª½øÐÐÊý¾Ý²éѯµÄ±í£¬ÊÓͼµÈÊý¾ÝÔ´£¬ÓöººÅ·Ö¸ô¡£
from×Ӿ仹¿ÉÒÔÖ¸¶¨Êý¾Ý±í»òÊÓͼ֮¼äµÄÁ¬½ÓÀàÐÍ£¬ÀàÐÍÈ¡¾öÓÚon×Ó¾äÖÐÖ¸¶¨µÄÁ¬½ÓÌõ¼þ¡£
T-SQL¿ÉÒÔÖ§³ÖÔÚfrom×Ó¾äÖÐÖ¸¶¨³ýÊý¾Ý±í»òÊÓͼÍâµÄÆäËû¶ÔÏó¹¹³ÉÅÉÉú±í¡£
ÀýÈ磺select emp.Ô±¹¤±àºÅ£¬emp.Ô±¹¤ÐÕÃû£¬sp.²¿ÃÅÃû³Æ
      fr ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ