Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

SQL 2005 ´æ´¢¹ý³Ì·ÖÒ³

create PROCEDURE [dbo].[P_PageTest]
    @SQL Nvarchar(max),  --SQLÓï¾ä²»°üÀ¨ÅÅÐò
    @CurPage int,    --µ±Ç°Ò³
    @PageRows int,    --Ò³Ãæ³ß´ç
 @Order Nvarchar(20),  --ÅÅÐò×Ö¶Î
 @OrderType Nvarchar(10), --ÅÅÐòÀàÐ͵¹Ðòdesc»òÕýÐòasc
    @TotalRecorder int output
AS
BEGIN
    SET NOCOUNT ON;
    declare @ExceSQL nvarchar(4000)
    --ÉèÖÿªÊ¼ÐкÅ
    declare  @start_row_num AS int
 declare  @end_row_num AS int
 if(@CurPage=1)
  begin
  SET @start_row_num = (@CurPage - 1) * @PageRows
  SET @end_row_num = @start_row_num+@PageRows
  end
 else
  begin
  SET @start_row_num = ((@CurPage - 1) * @PageRows)+1
  SET @end_row_num = (@start_row_num+@PageRows)-1
  end
    --ÉèÖñíʾ
    declare @RowNumber nvarchar(100)
    set @RowNumber = ', ROW_NUMBER() OVER(ORDER BY ' + @Order +' '+ @OrderType + ') as RowNumber from '
    set @SQL = Replace(@SQL,' from ',@RowNumber)
    --»ñµÃ×ܼǼÊý
    set @ExceSQL = 'WITH tmp AS (' + @SQL + ')
        select @TotalRecorder=max(RowNumber) from tmp'
    execute sp_executesql @ExceSQL,N'@TotalRecorder int output',@TotalRecorder output
    --²éѯÓï¾ä
    set @ExceSQL = 'WITH tmp AS (' + @SQL + ')
        select * from tmp where RowNumber between ' + Convert(nvarchar,@start_row_num)
        + ' And ' + Convert(nvarchar,@end_row_num)
    execute(@ExceSQL)
END


Ïà¹ØÎĵµ£º

Ìí¼ÓÊý¾ÝÔ´²¢ÅäÖÃÊý¾ÝÔ´Óësql ServerÉí·ÝÑé֤ģʽ

      ÔÚÊý¾Ý¿âÓ¦ÓóÌÐò·¢²¼Ê±£¬¿Í»§¶Ë°²×°ÔÚ¾ÖÓòÍøÖеÄÖ÷»úAÉÏ£¬sql server °²×°ÔڸþÖÓòÍøµÄÖ÷»úBÉÏ¡£¿Í»§¶ËÈí¼þÖаüº¬ÓÐËüÒªÁ¬½ÓµÄÊý¾Ý¿âµÄÐÅÏ¢¡£ÈçÊý¾ÝÔ´£¬·þÎñÆ÷Ãû³Æ£¬Êý¾Ý¿âµÈ£¬ÊµÀý£ºdata source=SQLOLEDB;SERVER=DongZi\sqlExpress;uid=sa;pwd=123;database=MachineRoom
¡£ÄÇôÎÒÃÇÔÚÖ÷» ......

SQL ServerÊý¾Ý¿âËø»úÖÆ¼°ÀàÐÍ

Microsoft SQL Server£¨ÒÔϼò³ÆSQL Server£©×÷ΪһÖÖÖÐСÐÍÊý¾Ý¿â¹ÜÀíϵͳ£¬ÒѾ­µÃµ½Á˹㷺µÄÓ¦Ó㬸Ãϵͳ¸üÇ¿µ÷ÓÉϵͳÀ´¹ÜÀíËø¡£ÔÚÓû§ÓÐSQLÇëÇóʱ£¬ÏµÍ³·ÖÎöÇëÇó£¬×Ô¶¯ÔÚÂú×ãËø¶¨Ìõ¼þºÍϵͳÐÔÄÜÖ®¼äΪÊý¾Ý¿â¼ÓÉÏÊʵ±µÄËø£¬Í¬Ê±ÏµÍ³ÔÚÔËÐÐÆÚ¼ä³£³£×Ô¶¯½øÐÐÓÅ»¯´¦Àí£¬ÊµÐж¯Ì¬¼ÓËø¡£
¡¡¡¡¶ÔÓÚÒ»°ãµÄÓû§¶øÑÔ£¬Í¨¹ýϵͳµÄ× ......

SQL ServerÊý¾Ý¿â¸÷¶ÔÏóµÄ×î´óÈÝÁ¿ËµÃ÷

ϱí˵Ã÷ÔÚ Microsoft SQL Server Êý¾Ý¿âÖж¨ÒåµÄ£¬»òÔÚ Transact-SQL
Óï¾äÖÐÒýÓõĸ÷ÖÖ¶ÔÏóµÄ×î´óÖµ£¨ÊýÁ¿»ò´óС£©¡£ÏÂ±í²»°üº¬ Microsoft® SQL Server 2000™ Windows® CE °æ¡£
 
×î´óÖµ£¨ÊýÁ¿»ò´óС£©
¶ÔÏó
SQL Server 7.0
SQL Server 2000
Åú´¦Àí´óС
65,536 * ÍøÂçÊý¾Ý°ü´óС1
65,536 * Í ......

sqlÊÖ¹¤×¢Èë

SQLÊÖ¹¤×¢Èë´óÈ«
2006Äê08ÔÂ11ÈÕ ÐÇÆÚÎå 21:00
±È·½ËµÔÚ²éѯidÊÇ50µÄÊý¾Ýʱ£¬Èç¹ûÓû§´«½üÀ´µÄ²ÎÊýÊÇ50 and 1=1£¬Èç¹ûûÓÐÉèÖùýÂ˵ϰ£¬¿ÉÒÔÖ±½Ó²é³öÀ´£¬SQL ×¢ÈëÒ»°ãÔÚASP³ÌÐòÖÐÓöµ½×î¶à£¬
¿´¿´ÏÂÃæµÄ
1.ÅжÏÊÇ·ñÓÐ×¢Èë
;and 1=1
;and 1=2
2.³õ²½ÅжÏÊÇ·ñÊÇmssql
;and user>0
3.ÅжÏÊý¾Ý¿âϵͳ
;and ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ