28,406
社区成员
发帖
与我相关
我的任务
分享<%
'On Error Resume Next
Function ValidSQL()
ValidSQL = True
Dim Invalid
Dim Server_From
Dim Server_Now
Dim Collection
Invalid = split( "'|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare","|")
Server_From = Cstr(Request.ServerVariables("HTTP_REFERER"))
Server_Now = Cstr(Request.ServerVariables("SERVER_NAME"))
Set Collection = Request.QueryString
If Len(Collection)>4 Then
For Each Arg In Collection
For I=0 To Ubound(Invalid)
If Instr(Collection(Arg),Invalid(I))>0 Then
ValidSQL = false
Exit For
End If
Next
If ValidSQL = False Then
Response.Write( "输入中包含非法字符,请重新输入! ")
Response.End()
Exit For
End If
Next
End If
End Function
Call ValidSQL()
DataURL = "E:\*****\*****\Jx_House@=DB.mdb"
'Strsql = "Provider=Microsoft.Jet.OLEDB.4.0;Data Source=" & DataURL
Strsql = "driver={Microsoft Access Driver (*.mdb)};dbq=" & DataURL
set dbconn=server.createobject("ADODB.CONNECTION")
dbconn.open Strsql
%>