
 |
³§É̲éѯ |
 |
 |
°´²úÆ·²éѯ³§ÉÌ |
 |
<%
'------------------sql zhuru
'-----------·À×¢Èë´úÂë----------------
'--------¶¨Ò岿·Ý------------------
'Dim Fy_Post,Fy_Get,Fy_In,Fy_Inf,Fy_Xh,Fy_db,Fy_dbstr
'×Ô¶¨ÒåÐèÒª¹ýÂ˵Ä×Ö´®,Óà "|||" ·Ö¸ô
Fy_In = "'|||;|||and|||exec|||insert|||select|||delete|||update|||count|||*|||%|||chr|||mid|||master|||truncate|||char|||declare"
'----------------------------------
Fy_Inf = split(Fy_In,"|||")
'--------POST²¿·Ý------------------
If Request.Form<>"" Then
For Each Fy_Post In Request.Form
For Fy_Xh=0 To Ubound(Fy_Inf)
If Instr(LCase(Request.Form(Fy_Post)),Fy_Inf(Fy_Xh))<>0 Then
response.redirect "http://www.it168.com"
End If
Next
Next
End If
'----------------------------------
'--------GET²¿·Ý-------------------
If Request.QueryString<>"" Then
For Each Fy_Get In Request.QueryString
For Fy_Xh=0 To Ubound(Fy_Inf)
If Instr(LCase(Request.QueryString(Fy_Get)),Fy_Inf(Fy_Xh))<>0 Then
response.redirect "http://www.it168.com"
End If
Next
Next
End If
''''''''''-----------sql end
%>
|
|
| ÖÐÎÄÆ·ÅÆ |
Ó¢ÎÄÆ·ÅÆ |
Ïà¹Ø²úÆ· |
LOGO |
|
|
| |