WEB°²È«½â¾ö·½°¸Ò»Ö®SQL×¢Èë·À·¶
Ò»¡¢SQL×¢Èë·À·¶
ÔÚÒ»¸öWEB¶¯Ì¬Ò³ÃæÖУ¨ÀýÈçaspx»òÕßjsp£©£¬Õâ¸öÒ³ÃæÔÊÐíÓû§ÔÚÊäÈë¿òÖÐÊäÈë×Ö·û£¬Õâ¸ö×Ö·û¿ÉÒÔ±»ÒýÈëµ½Êý¾Ý¿âÖÐÈ¥½øÐвéѯ£¨ÕâÀïµÄ²éѯÊÇͨÓõÄ˵·¨£¬Êµ¼ÊÉϰüÀ¨ÁËÔöɾ¸Ä²é£©²Ù×÷¡£Ò»¸öºÚ¿ÍÔÚÕâ¸öÊäÈë¿òÖÐÊäÈëÁËÒ»¸ö»ûÐβéѯ×Ö·û´®£¬´Ó¶ø¸Ä±äÁËÔÓеIJéѯ£¬Õâ¿ÉÒÔ±»ÓÃÀ´²åÈ룬¸Ä±ä£¬»òË𺦺ǫ́Êý¾Ý¿â¡£Ôõô¿ÉÄÜÄØ£¿Çë¿´ÏÂÃæµÄÀý×Ó¡£
ÒԵǽΪÀý£¬ºǫ́´úÂëͨ¹ý¹¹ÔìSQLÓï¾ä“select * from user where username = 'txtUserName.Text.Trim() 'and password ='txtPwd.Text.Trim()';Èç¹ûÓû§ÔÚÊäÈë¿òÖÐÊäÈëÓû§ÃûΪadmin'or'1'='1, ÈúóÈÎÒâÊäÈë±ÈÈç123ΪÃÜÂ룬Ôòºǫִ́ÐеÄSQLÓï¾äΪselect * from user where username='admin'or'1'='1'and password='123';ÕâÊÇ£¬ÎÞÂÛÃÜÂëÊÇ·ñÕýÈ·£¬×îÖÕSQLÓï¾ä²éѯ½á¹û¶¼²»Îª¿Õ£¬Õâ±ãÊÇÒ»¸öµäÐ͵ÄSQL×¢Èë¹¥»÷£¬Í¨¹ý´ËÖÖ·½Ê½£¬¹¥»÷Õ߳ɹ¦ÈƹýÃÜÂëÑéÖ¤£¬µÇ½ϵͳ¡£Ò»¸öµäÐ͵Ľâ¾ö·½°¸Êǹ¹Ôì“select count(*) from user where username='txtUserName.Text.Trim() 'and password = 'txtPwd.Text.Trim()'ÕâÑùµÄSQLÓï¾ä£¬ÕâÑùÈç¹û¹¥»÷Õß²ÉÈ¡ÉÏÊö¹¥»÷·½Ê½£¬Ôò»áÒòΪ·µ»ØµÄcountÖµ´óÓÚ1¶øÑé֤ʧ°Ü¡£
µ«ÎÊÌâ²¢²»»áÒò´Ë½áÊø£¬Èç¹û¹¥»÷Õß¹¹ÔìÈçÏµĹ¥»÷Óï¾äÄØ£¿±ÈÈç“select count(*) from user where username=’txtUserName.Text.Trim() ‘--and password =’txtPwd.Text.Trim’£¬×¢Òâ¼Ó´ÖµÄ²¿·Öʵ¼ÊÉÏÊDZ»×¢Ê͵ôÁË£¬Ò²¾ÍÊÇ˵ÑéÖ¤½«»á³É¹¦¡£¸üÀ÷º¦µÄ£¬¹¥»÷Õ߻ṹÔì³ö“select count(*) from user where username ='txtUserName.Text.Trim() ';drop table user ;--’ and password ='txtPwd.Text.Trim';×¢Òâµ½²»½öÑé֤ͨ¹ý£¬¶øÇÒuser±í±»É¾³ý£¬ÕâÏÂ×Ó˶¼²»ÒªÏëÔٵǽÁË¡£
ÀàËÆµÄ£¬ºÚ¿ÍÃÇͨ¹ý¾«ÇɵĹ¹Ô죬¿ÉÒÔ´ïµ½ÈÆ¹ýÃÜÂëÈÏÖ¤£¬ÐÞ¸ÄÆÆ»µ¹Ø¼üÊý¾Ý£¬ÄËÖÁ»ñȡϵͳÍêÈ«¿ØÖÆÈ¨µÄÄ¿µÄ¡£ÕâÀïÄãÒ²Ðí»áÎʹ¥»÷ÕßÈçºÎµÃµ½Êý¾Ý¿âÖеıíÃûºÍ×ֶΣ¬ÕâÀïÒ»ÖÖ·½·¨ÊDZ©Á¦ÆÆ½â£¬¸ù¾Ý¹æÂɳ¢ÊÔ£¬±ÈÈçϵͳ¶à´æÔÚuser±í£¬ÓÃÀ´´æ·ÅÓû§ÐÅÏ¢¡£ÁíÍâÒ»ÖÖ·½·¨ÊÇÀûÓÃSQL×¢Èë¹¥»÷²Â½â£¬Í¨¹ý¹¹ÔìһЩÄܹ»Ê¹Êý¾Ý¿â²úÉú´íÎóÐÅÏ¢µÄSQLÓï¾ä£¬»ñÈ¡Êý¾Ý¿âµÄÃô¸ÐÐÅÏ¢£¬½øÐбíÃûºÍ×ֶεIJ½⣬ÃÜÂëÆÆ½âµÈ¡£
½â¾ö·½·¨
1. ±ÜÃâʹÓö¯Ì¬Éú³ÉµÄSQLÓï¾ä
ͨ¹ý×Ö·û´®Ïà¼ÓµÄ·½Ê½¶¯Ì¬Éú³ÉµÄSQLÓï¾äÕýÊÇSQL×¢ÈëµÄÍò¶ñÖ®Ô´£¬
Ïà¹ØÎĵµ£º
declare @XML XML
SET @XML='<root>
<OLDVALUE>
<H_Action id="1130">030</H_Action>
<D_Action>030</D_Action>
<OrderCompany>00220</OrderCompany>
<OrderNumber>10004035</OrderNumber> ......
SQLµÄÓÅ»¯Ó¦¸Ã´Ó5¸ö·½Ãæ½øÐе÷Õû£º
1.È¥µô²»±ØÒªµÄ´óÐͱíµÄÈ«±íɨÃè
2.»º´æÐ¡ÐͱíµÄÈ«±íɨÃè
3.¼ìÑéÓÅ»¯Ë÷ÒýµÄʹÓÃ
4.¼ìÑéÓÅ»¯µÄÁ¬½Ó¼¼Êõ
5.¾¡¿ÉÄܼõÉÙÖ´Ðмƻ®µÄCost
SQLÓï¾ä£º
ÊǶÔÊý¾Ý¿â(Êý¾Ý)½øÐвÙ×÷µÄΩһ;¾¶£»
ÏûºÄÁË70%~90%µÄÊý¾Ý¿â×ÊÔ´£»¶ÀÁ¢ÓÚ³ÌÐòÉè¼ÆÂß¼£¬Ïà¶ÔÓÚ¶Ô³ÌÐòÔ´´úÂëµÄÓÅ»¯£¬¶ÔSQLÓï¾äµÄÓÅ»¯Ô ......
ÓÃSQL²éѯ·ÖÎöÆ÷²Ù×ÝExcel¼°µ¼Èëµ¼³öÊý¾Ý
http://www.delphibbs.com/keylife/iblog_show.asp?xid=32983
SQL SERVER ºÍEXCELµÄÊý¾Ýµ¼Èëµ¼³ö
ͨ³£µÄ·½·¨ÊÇʹÓÃͼÐνçÃæµÄdts¹¤¾ß£¬µ«·¢¾õÓÐЩʹÓÃÃüÁîÐнçÃæµÄ·½Ê½¸ü¼òµ¥
1¡¢ÔÚSQL SERVERÀï²éѯExcelÊý¾Ý:
-- ======================================================
SE ......
´Ótablename ±íÖÐÈ¡³öµÚ n Ìõµ½µÚ m ÌõµÄ¼Ç¼
SQL SERVERµÄд·¨
SELECT TOP m-n+1 *
from tablename
WHERE (id NOT IN
(SELECT TOP n-1 id from tablename))
ÄãÕâÊÇÒ»¸ö·ÖÒ³Ëã·¨µÄ£¬ÎÒÌṩµÄ±È½Ï¼òµ¥£¬ÍøÉÏ»¹Óкܶ಻´íµÄ£¬Èç¹ûÄã¶ÔÕâ¸ö²»ÂúÒ⣬ÔÙÈ¥ÍøÉÏÕÒÕÒ ¹Ø¼ü×Ö “·ÖÒ³Ëã·¨”
ORACLEµÄ»°¸ÄһϠ......
´¥·¢Æ÷ÊÇÒ»ÖÖÌØÊâµÄ´æ´¢¹ý³Ì£¬ÔÚÓû§ÊÔͼ¶ÔÖ¸¶¨µÄ±íÖ´ÐÐÖ¸¶¨µÄÊý¾ÝÐÞ¸ÄÓï¾äʱ×Ô¶¯Ö´ÐС£Microsoft® SQL Server™ ÔÊÐíΪÈκθø¶¨µÄ INSERT¡¢UPDATE »ò DELETE Óï¾ä´´½¨¶à¸ö´¥·¢Æ÷¡£
1¡¢INSERT´¥·¢Æ÷£º¿ÉÒÔ¶¨ÒåÒ»¸öÎÞÂÛºÎʱÓÃINSERTÓï¾äÏò±íÖвåÈëÊý¾Ýʱ¶¼»áÖ´ÐеĴ¥·¢Æ÷¡£
......