%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%>
<% dim conn,connstr,dbstr dbstr="../db/bottom.asp" connstr="provider=microsoft.jet.oledb.4.0;data source="& server.MapPath(dbstr) On Error Resume Next Set conn = Server.CreateObject("ADODB.Connection") conn.open connstr If Err Then err.Clear Set Conn = Nothing Response.Write "Data Connection Error!" Response.End End If %> <% dim sql_leach,sql_leach_0,Sql_DATA,SQL_Get,Sql_Post sql_leach = "',or,and,exec,insert,select,delete,update,count,*,%,chr,mid,master,truncate,char,declare" sql_leach_0 = split(sql_leach,",") If Request.QueryString<>"" Then For Each SQL_Get In Request.QueryString For SQL_Data=0 To Ubound(sql_leach_0) if instr(Request.QueryString(SQL_Get),sql_leach_0(Sql_DATA))>0 Then 'Response.Write " Ҫ SQL " 'Response.end end if next Next End If If Request.Form<>"" Then For Each Sql_Post In Request.Form For SQL_Data=0 To Ubound(sql_leach_0) if instr(Request.Form(Sql_Post),sql_leach_0(Sql_DATA))>0 Then 'Response.Write " Ҫ SQL " 'Response.end end if next next end if %> <% Function sql_check(str) if str <> "" then str=replace(str,"'","''") str=replace(str,"""","''") sql_check=str end if end function Function changechr(str) if str <> "" then changechr = replace(str," "," ") changechr = replace(changechr,chr(13),"|
|
|
|
|
|
|
|
||||
| |||||||