• ADADADADAD

    动态sql如何防止sql注入[ 建站问答 ]

    建站问答 时间:2024-12-01 19:11:10

    作者:文/会员上传

    简介:

    动态sql防止sql注入的示例:在对应的数据库中添加以下sql语句:DECLARE @variable NVARCHAR(100)DECLARE @SQLString NVARCHAR(1024)DECLARE @ParmDefinition NVARCHAR(500)SET

    以下为本文的正文内容,内容仅供参考!本站为公益性网站,复制本文以及下载DOC文档全部免费。

    动态sql防止sql注入的示例:

    在对应的数据库中添加以下sql语句:

    DECLARE @variable NVARCHAR(100)

    DECLARE @SQLString NVARCHAR(1024)

    DECLARE @ParmDefinition NVARCHAR(500)

    SET @SQLString = N'SELECT OEV.Name, OEV.Position, Base_Employee.Address, OEV.Telephone, OEV.MobilePhone, OEV.Email, OEV.RealDepID

    FROM Base_OrganizeEmployeeView AS OEV

    JOIN Base_Employee

    ON Base_Employee.Emp_ID = OEV.Emp_ID

    WHERE (OEV.Account LIKE ''%'' + @searchFilter + ''%'' OR OEV.Name LIKE ''%'' + @searchFilter + ''%'' OR OEV.Position LIKE ''%'' + @searchFilter + ''%'' ) AND STATE = 1'

    SET @parmDefinition = N'@searchFilter varchar(100)'

    SET @variable = N'k'

    EXECUTE sp_executesql @SQLString, @ParmDefinition, @searchFilter = @variable

    动态sql如何防止sql注入.docx

    将本文的Word文档下载到电脑

    推荐度:

    下载
    热门标签: sql注入动态sql