问题描述
<%'----------防止SQL注入-----------dimSQL_InjdataSQL_Injdata="'|;|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"SQL_inj=split(SQL_Injdata,"|")IfRequest.QueryString<>""ThenForEachSQL_GetInRequest.QueryStringForSQL_Data=0ToUbound(SQL_inj)ifinstr(Request.QueryString(SQL_Get),Sql_Inj(Sql_Data))>0ThenResponse.Redirect("/index.asp")endifnextNextEndIf'----------连接数据库----------Dimconn,connstrSetconn=Server.CreateObject("ADODB.Connection")connstr="Provider=Microsoft.Jet.OLEDB.4.0;UserID=admin;Password=;DataSource="&Server.MapPath("/DataBase/db_Ebusiness.mdb")&";"conn.openconnstr%>
时间: 2024-10-28 16:04:04