English 中文(简体)
Sanity Check - Concatenating Annual Values - 注射
原标题:Sanity Check - Concatenating Date Values - SQL Injection

我们现在收到价值参数,即<代码>VARCHAR,然后从这些数值中确定一个日期。 我愿确认,以下方法将阻止在声明中注入库克的可能性:

select CONVERT(datetime,  2010  +  -  +  02  +  -  +  21  +     +  15:11:38.990 )




select CONVERT(datetime, @Year +  -  + @Month +  -  + @Day+     + @Time)

那么,由于目标数据类型<代码> 日期将只收到有效的日期指示,你应当被罚款。


EXEC ( select CONVERT(datetime, @Year+  -  +@Month+  -  +@Day+     + @Time) )




例如,如果用一种语言—— php——来发表这一声明,那么,仅仅确保你逃脱在路上(用我方言或用ms)的扼杀,以避免注射攻击。

How to write this T-SQL WHERE condition?

I ve got two tables: TableA Col1 Col2 TableB Col3 Col4 I want to join them together: SELECT * from TableA join TableB ON (...) Now, in place of ... I need to write an expression ...

Customer and Order Sql Statement

TSQL query to select all records from Customer that has an Order and also select all records from customer that does not have an Order. The table Customer contains a primary key of CustomerID. The ...

Recommended way of querying multiple Versioned tables

Have a win 2003 box with MSSQL 2005 running on it. There is a database which is populated every morning with new/modified SalesOrder made the previous day. The database has several tables: SalesOrder, ...

update duplicate record

I have a table with the following fields Id Name IsPublic i need to write a sql query that updates IsPublic to false where name has a duplicate. Only one of the duplicates should have IsPublic = ...

Define variable to use with IN operator (T-SQL)

I have a Transact-SQL query that uses the IN operator. Something like this: select * from myTable where myColumn in (1,2,3,4) Is there a way to define a variable to hold the entire list "(1,2,3,4)"? ...

Selecting records during recursive stored procedure

I ve got a content management system that contains a hierarchical structure of categories, with sub-categories subject to different ordering options at each level. Currently, that s retrieved by a (...
