WEB°²È«½â¾ö·½°¸Ò»Ö®SQL×¢Èë·À·¶
Ò»¡¢SQL×¢Èë·À·¶
ÔÚÒ»¸öWEB¶¯Ì¬Ò³ÃæÖУ¨ÀýÈçaspx»òÕßjsp£©£¬Õâ¸öÒ³ÃæÔÊÐíÓû§ÔÚÊäÈë¿òÖÐÊäÈë×Ö·û£¬Õâ¸ö×Ö·û¿ÉÒÔ±»ÒýÈëµ½Êý¾Ý¿âÖÐÈ¥½øÐвéѯ£¨ÕâÀïµÄ²éѯÊÇͨÓõÄ˵·¨£¬Êµ¼ÊÉϰüÀ¨ÁËÔöɾ¸Ä²é£©²Ù×÷¡£Ò»¸öºÚ¿ÍÔÚÕâ¸öÊäÈë¿òÖÐÊäÈëÁËÒ»¸ö»ûÐβéѯ×Ö·û´®£¬´Ó¶ø¸Ä±äÁËÔÓеIJéѯ£¬Õâ¿ÉÒÔ±»ÓÃÀ´²åÈ룬¸Ä±ä£¬»òË𺦺ǫ́Êý¾Ý¿â¡£Ôõô¿ÉÄÜÄØ£¿Çë¿´ÏÂÃæµÄÀý×Ó¡£
ÒԵǽΪÀý£¬ºǫ́´úÂëͨ¹ý¹¹ÔìSQLÓï¾ä“select * from user where username = 'txtUserName.Text.Trim() 'and password ='txtPwd.Text.Trim()';Èç¹ûÓû§ÔÚÊäÈë¿òÖÐÊäÈëÓû§ÃûΪadmin'or'1'='1, ÈúóÈÎÒâÊäÈë±ÈÈç123ΪÃÜÂ룬Ôòºǫִ́ÐеÄSQLÓï¾äΪselect * from user where username='admin'or'1'='1'and password='123';ÕâÊÇ£¬ÎÞÂÛÃÜÂëÊÇ·ñÕýÈ·£¬×îÖÕSQLÓï¾ä²éѯ½á¹û¶¼²»Îª¿Õ£¬Õâ±ãÊÇÒ»¸öµäÐ͵ÄSQL×¢Èë¹¥»÷£¬Í¨¹ý´ËÖÖ·½Ê½£¬¹¥»÷Õ߳ɹ¦ÈƹýÃÜÂëÑéÖ¤£¬µÇ½ϵͳ¡£Ò»¸öµäÐ͵Ľâ¾ö·½°¸Êǹ¹Ôì“select count(*) from user where username='txtUserName.Text.Trim() 'and password = 'txtPwd.Text.Trim()'ÕâÑùµÄSQLÓï¾ä£¬ÕâÑùÈç¹û¹¥»÷Õß²ÉÈ¡ÉÏÊö¹¥»÷·½Ê½£¬Ôò»áÒòΪ·µ»ØµÄcountÖµ´óÓÚ1¶øÑé֤ʧ°Ü¡£
µ«ÎÊÌâ²¢²»»áÒò´Ë½áÊø£¬Èç¹û¹¥»÷Õß¹¹ÔìÈçÏµĹ¥»÷Óï¾äÄØ£¿±ÈÈç“select count(*) from user where username=’txtUserName.Text.Trim() ‘--and password =’txtPwd.Text.Trim’£¬×¢Òâ¼Ó´ÖµÄ²¿·Öʵ¼ÊÉÏÊDZ»×¢Ê͵ôÁË£¬Ò²¾ÍÊÇ˵ÑéÖ¤½«»á³É¹¦¡£¸üÀ÷º¦µÄ£¬¹¥»÷Õ߻ṹÔì³ö“select count(*) from user where username ='txtUserName.Text.Trim() ';drop table user ;--’ and password ='txtPwd.Text.Trim';×¢Òâµ½²»½öÑé֤ͨ¹ý£¬¶øÇÒuser±í±»É¾³ý£¬ÕâÏÂ×Ó˶¼²»ÒªÏëÔٵǽÁË¡£
ÀàËÆµÄ£¬ºÚ¿ÍÃÇͨ¹ý¾«ÇɵĹ¹Ô죬¿ÉÒÔ´ïµ½ÈÆ¹ýÃÜÂëÈÏÖ¤£¬ÐÞ¸ÄÆÆ»µ¹Ø¼üÊý¾Ý£¬ÄËÖÁ»ñȡϵͳÍêÈ«¿ØÖÆÈ¨µÄÄ¿µÄ¡£ÕâÀïÄãÒ²Ðí»áÎʹ¥»÷ÕßÈçºÎµÃµ½Êý¾Ý¿âÖеıíÃûºÍ×ֶΣ¬ÕâÀïÒ»ÖÖ·½·¨ÊDZ©Á¦ÆÆ½â£¬¸ù¾Ý¹æÂɳ¢ÊÔ£¬±ÈÈçϵͳ¶à´æÔÚuser±í£¬ÓÃÀ´´æ·ÅÓû§ÐÅÏ¢¡£ÁíÍâÒ»ÖÖ·½·¨ÊÇÀûÓÃSQL×¢Èë¹¥»÷²Â½â£¬Í¨¹ý¹¹ÔìһЩÄܹ»Ê¹Êý¾Ý¿â²úÉú´íÎóÐÅÏ¢µÄSQLÓï¾ä£¬»ñÈ¡Êý¾Ý¿âµÄÃô¸ÐÐÅÏ¢£¬½øÐбíÃûºÍ×ֶεIJ½⣬ÃÜÂëÆÆ½âµÈ¡£
½â¾ö·½·¨
1. ±ÜÃâʹÓö¯Ì¬Éú³ÉµÄSQLÓï¾ä
ͨ¹ý×Ö·û´®Ïà¼ÓµÄ·½Ê½¶¯Ì¬Éú³ÉµÄSQLÓï¾äÕýÊÇSQL×¢ÈëµÄÍò¶ñÖ®Ô´£¬
Ïà¹ØÎĵµ£º
declare @XML XML
SET @XML='<root>
<OLDVALUE>
<H_Action id="1130">030</H_Action>
<D_Action>030</D_Action>
<OrderCompany>00220</OrderCompany>
<OrderNumber>10004035</OrderNumber> ......
Creating a CLR user define aggregate (part 2). Use multiple columns in the aggregation function
In part 1 we created a nice user defined aggregate. Now we are going to make it more sophisticated and let its value depend on two parameters ShipCountry and ShipShipCity. You might try having two parame ......
sql ²éÑ¯ÖØ¸´¼Ç¼2
http://blog.csdn.net/tobeistdo/archive/2009/11/11/4797545.aspx
========µÚһƪ=========
ÔÚÒ»ÕűíÖÐij¸ö×Ö¶ÎÏÂÃæÓÐÖØ¸´¼Ç¼£¬Óкܶ෽·¨£¬µ«ÊÇÓÐÒ»¸ö·½·¨£¬ÊDZȽϸßЧµÄ£¬ÈçÏÂÓï¾ä£º
select data_guid from adam_entity_datas a where a.rowid > (select min(b.rowid) from adam_entity_datas ......
½ñÌìÔÚµ÷ÊԵĹý³ÌÖз¢ÏÖ ÔÚvbÖÐÆ´SQLµÄʱºò·¢ÏÖ"()" ×÷Óúܴó
eg: table: T_TEST col : T_KB int ,S_CD int ,Z_SU int
dim gcstrT_1 ,gcstrT_3 as integer
gcstrT_1 = 1
gcstrT_3 = 3
strWhere = strWhere & "……"
strWhere = strWhere & "AND ((T_K ......
ÔÚÍøÉÏÕÒµÄÒ»¸ö·½·¨£¬¾ÍÒòΪһ¸öhostNameûÅäÖöԣ¬º¦µÃÎÒ»¨ÁË3¸öСʱ²Å¸ã¶¨
²âÊÔ»·¾³:
oracle·þÎñÆ÷: windowsXPϵͳ£¬ oracle9.2.0.7£¬Ö÷»úÃû£ºoracleHost
sqlserver·þÎñÆ÷:windows2003 r2ϵͳ£¬sqlserver 2000,Ö÷»úÃû£ºsqlHost
Ä¿µÄ£ºÔÚOracleÊý¾ÝÖзÃÎÊsqlserverÖеÄNorthwindÊý¾Ý¿â
1¡¢ÔÚ°²×°ORACLE9iʱ, Ò ......