WEB°²È«½â¾ö·½°¸Ò»Ö®SQL×¢Èë·À·¶
Ò»¡¢SQL×¢Èë·À·¶
ÔÚÒ»¸öWEB¶¯Ì¬Ò³ÃæÖУ¨ÀýÈçaspx»òÕßjsp£©£¬Õâ¸öÒ³ÃæÔÊÐíÓû§ÔÚÊäÈë¿òÖÐÊäÈë×Ö·û£¬Õâ¸ö×Ö·û¿ÉÒÔ±»ÒýÈëµ½Êý¾Ý¿âÖÐÈ¥½øÐвéѯ£¨ÕâÀïµÄ²éѯÊÇͨÓõÄ˵·¨£¬Êµ¼ÊÉϰüÀ¨ÁËÔöɾ¸Ä²é£©²Ù×÷¡£Ò»¸öºÚ¿ÍÔÚÕâ¸öÊäÈë¿òÖÐÊäÈëÁËÒ»¸ö»ûÐβéѯ×Ö·û´®£¬´Ó¶ø¸Ä±äÁËÔÓеIJéѯ£¬Õâ¿ÉÒÔ±»ÓÃÀ´²åÈ룬¸Ä±ä£¬»òË𺦺ǫ́Êý¾Ý¿â¡£Ôõô¿ÉÄÜÄØ£¿Çë¿´ÏÂÃæµÄÀý×Ó¡£
ÒԵǽΪÀý£¬ºǫ́´úÂëͨ¹ý¹¹ÔìSQLÓï¾ä“select * from user where username = 'txtUserName.Text.Trim() 'and password ='txtPwd.Text.Trim()';Èç¹ûÓû§ÔÚÊäÈë¿òÖÐÊäÈëÓû§ÃûΪadmin'or'1'='1, ÈúóÈÎÒâÊäÈë±ÈÈç123ΪÃÜÂ룬Ôòºǫִ́ÐеÄSQLÓï¾äΪselect * from user where username='admin'or'1'='1'and password='123';ÕâÊÇ£¬ÎÞÂÛÃÜÂëÊÇ·ñÕýÈ·£¬×îÖÕSQLÓï¾ä²éѯ½á¹û¶¼²»Îª¿Õ£¬Õâ±ãÊÇÒ»¸öµäÐ͵ÄSQL×¢Èë¹¥»÷£¬Í¨¹ý´ËÖÖ·½Ê½£¬¹¥»÷Õ߳ɹ¦ÈƹýÃÜÂëÑéÖ¤£¬µÇ½ϵͳ¡£Ò»¸öµäÐ͵Ľâ¾ö·½°¸Êǹ¹Ôì“select count(*) from user where username='txtUserName.Text.Trim() 'and password = 'txtPwd.Text.Trim()'ÕâÑùµÄSQLÓï¾ä£¬ÕâÑùÈç¹û¹¥»÷Õß²ÉÈ¡ÉÏÊö¹¥»÷·½Ê½£¬Ôò»áÒòΪ·µ»ØµÄcountÖµ´óÓÚ1¶øÑé֤ʧ°Ü¡£
µ«ÎÊÌâ²¢²»»áÒò´Ë½áÊø£¬Èç¹û¹¥»÷Õß¹¹ÔìÈçÏµĹ¥»÷Óï¾äÄØ£¿±ÈÈç“select count(*) from user where username=’txtUserName.Text.Trim() ‘--and password =’txtPwd.Text.Trim’£¬×¢Òâ¼Ó´ÖµÄ²¿·Öʵ¼ÊÉÏÊDZ»×¢Ê͵ôÁË£¬Ò²¾ÍÊÇ˵ÑéÖ¤½«»á³É¹¦¡£¸üÀ÷º¦µÄ£¬¹¥»÷Õ߻ṹÔì³ö“select count(*) from user where username ='txtUserName.Text.Trim() ';drop table user ;--’ and password ='txtPwd.Text.Trim';×¢Òâµ½²»½öÑé֤ͨ¹ý£¬¶øÇÒuser±í±»É¾³ý£¬ÕâÏÂ×Ó˶¼²»ÒªÏëÔٵǽÁË¡£
ÀàËÆµÄ£¬ºÚ¿ÍÃÇͨ¹ý¾«ÇɵĹ¹Ô죬¿ÉÒÔ´ïµ½ÈÆ¹ýÃÜÂëÈÏÖ¤£¬ÐÞ¸ÄÆÆ»µ¹Ø¼üÊý¾Ý£¬ÄËÖÁ»ñȡϵͳÍêÈ«¿ØÖÆÈ¨µÄÄ¿µÄ¡£ÕâÀïÄãÒ²Ðí»áÎʹ¥»÷ÕßÈçºÎµÃµ½Êý¾Ý¿âÖеıíÃûºÍ×ֶΣ¬ÕâÀïÒ»ÖÖ·½·¨ÊDZ©Á¦ÆÆ½â£¬¸ù¾Ý¹æÂɳ¢ÊÔ£¬±ÈÈçϵͳ¶à´æÔÚuser±í£¬ÓÃÀ´´æ·ÅÓû§ÐÅÏ¢¡£ÁíÍâÒ»ÖÖ·½·¨ÊÇÀûÓÃSQL×¢Èë¹¥»÷²Â½â£¬Í¨¹ý¹¹ÔìһЩÄܹ»Ê¹Êý¾Ý¿â²úÉú´íÎóÐÅÏ¢µÄSQLÓï¾ä£¬»ñÈ¡Êý¾Ý¿âµÄÃô¸ÐÐÅÏ¢£¬½øÐбíÃûºÍ×ֶεIJ½⣬ÃÜÂëÆÆ½âµÈ¡£
½â¾ö·½·¨
1. ±ÜÃâʹÓö¯Ì¬Éú³ÉµÄSQLÓï¾ä
ͨ¹ý×Ö·û´®Ïà¼ÓµÄ·½Ê½¶¯Ì¬Éú³ÉµÄSQLÓï¾äÕýÊÇSQL×¢ÈëµÄÍò¶ñÖ®Ô´£¬
Ïà¹ØÎĵµ£º
SQLµÄÓÅ»¯Ó¦¸Ã´Ó5¸ö·½Ãæ½øÐе÷Õû£º
1.È¥µô²»±ØÒªµÄ´óÐͱíµÄÈ«±íɨÃè
2.»º´æÐ¡ÐͱíµÄÈ«±íɨÃè
3.¼ìÑéÓÅ»¯Ë÷ÒýµÄʹÓÃ
4.¼ìÑéÓÅ»¯µÄÁ¬½Ó¼¼Êõ
5.¾¡¿ÉÄܼõÉÙÖ´Ðмƻ®µÄCost
SQLÓï¾ä£º
ÊǶÔÊý¾Ý¿â(Êý¾Ý)½øÐвÙ×÷µÄΩһ;¾¶£»
ÏûºÄÁË70%~90%µÄÊý¾Ý¿â×ÊÔ´£»¶ÀÁ¢ÓÚ³ÌÐòÉè¼ÆÂß¼£¬Ïà¶ÔÓÚ¶Ô³ÌÐòÔ´´úÂëµÄÓÅ»¯£¬¶ÔSQLÓï¾äµÄÓÅ»¯Ô ......
Creating a CLR user define aggregate (part 2). Use multiple columns in the aggregation function
In part 1 we created a nice user defined aggregate. Now we are going to make it more sophisticated and let its value depend on two parameters ShipCountry and ShipShipCity. You might try having two parame ......
´¥·¢Æ÷ÊÇÒ»ÖÖÌØÊâµÄ´æ´¢¹ý³Ì£¬ÔÚÓû§ÊÔͼ¶ÔÖ¸¶¨µÄ±íÖ´ÐÐÖ¸¶¨µÄÊý¾ÝÐÞ¸ÄÓï¾äʱ×Ô¶¯Ö´ÐС£Microsoft® SQL Server™ ÔÊÐíΪÈκθø¶¨µÄ INSERT¡¢UPDATE »ò DELETE Óï¾ä´´½¨¶à¸ö´¥·¢Æ÷¡£
1¡¢INSERT´¥·¢Æ÷£º¿ÉÒÔ¶¨ÒåÒ»¸öÎÞÂÛºÎʱÓÃINSERTÓï¾äÏò±íÖвåÈëÊý¾Ýʱ¶¼»áÖ´ÐеĴ¥·¢Æ÷¡£
......
ÔÚÍøÉÏÕÒµÄÒ»¸ö·½·¨£¬¾ÍÒòΪһ¸öhostNameûÅäÖöԣ¬º¦µÃÎÒ»¨ÁË3¸öСʱ²Å¸ã¶¨
²âÊÔ»·¾³:
oracle·þÎñÆ÷: windowsXPϵͳ£¬ oracle9.2.0.7£¬Ö÷»úÃû£ºoracleHost
sqlserver·þÎñÆ÷:windows2003 r2ϵͳ£¬sqlserver 2000,Ö÷»úÃû£ºsqlHost
Ä¿µÄ£ºÔÚOracleÊý¾ÝÖзÃÎÊsqlserverÖеÄNorthwindÊý¾Ý¿â
1¡¢ÔÚ°²×°ORACLE9iʱ, Ò ......
/*------------------------------------------------------------------
-- Author : htl258(Tony)
-- Date : 2010-04-15 22:07:01
-- Version: Microsoft SQL Server 2008 (RTM) - 10.0.1600.22 (Intel X86)
Jul 9 2008 14:43:34
Copy ......