SQL注入漏洞
作者:cmscn 日期:2008-12-24
防SQL注入检测
作者:cmscn 日期:2008-12-24
'--- 防SQL注入检测
Public Sub ChkSQLInWord()
If int(Format_Mid_Num(44))=0 or NoChkSqlInFiles=True Then Exit Sub
Dim InWordStr,NameStrPost,NameStrGet,NameStrCookie,i
Dim FormWord,QueryStringWord,CookiesWord,ReChkSQLIn
Web_SqlInword = Trim(Web_SqlInword)
If Web_SqlInword="" then Exit Sub
Public Sub ChkSQLInWord()
If int(Format_Mid_Num(44))=0 or NoChkSqlInFiles=True Then Exit Sub
Dim InWordStr,NameStrPost,NameStrGet,NameStrCookie,i
Dim FormWord,QueryStringWord,CookiesWord,ReChkSQLIn
Web_SqlInword = Trim(Web_SqlInword)
If Web_SqlInword="" then Exit Sub
论坛实现单贴屏蔽的完整修改方法
作者:cmscn 日期:2008-12-21
①在数据库的bbs_data表中加字段pb,类型为 逻辑型(是/否)
或者执行SQL语句 alter table bbs_data add pb bit null
②修改forum_view.asp文件
先定义变量 pb(dim pb)
再找到sql="select bbs_data.id,bbs...这句,在user_data.popedom后面加,bbs_data.pb
找到: if v_i>1 and forum_power_true(forumpower)=true then temp1=temp1&" <a href='forum_isaction.asp?forum_id="&forumid&"&sel_id="&viewid&"&re_id="&v_id&"&action=del'><img src='"&joekoe_cms.web_dir_skin&"small/del2.gif' alt='删除此回贴' align=absMiddle border=0></a> "
或者执行SQL语句 alter table bbs_data add pb bit null
②修改forum_view.asp文件
先定义变量 pb(dim pb)
再找到sql="select bbs_data.id,bbs...这句,在user_data.popedom后面加,bbs_data.pb
找到: if v_i>1 and forum_power_true(forumpower)=true then temp1=temp1&" <a href='forum_isaction.asp?forum_id="&forumid&"&sel_id="&viewid&"&re_id="&v_id&"&action=del'><img src='"&joekoe_cms.web_dir_skin&"small/del2.gif' alt='删除此回贴' align=absMiddle border=0></a> "