28,406
社区成员
发帖
与我相关
我的任务
分享
<%
dim a
a=replace(rs8("tt"),"'","''")
sql="select top 1 * from abc where dd = 'ffcc' and hh = '" & a & "' order by id"
response.write(sql)
sql="select top 1 * from abc where dd = 'ffcc' and hh = '" & replace(rs8("tt"),"'","''") & "' order by id"
response.write(sql)
%>
话说你数的清楚几个单引号几个双引号不!
把单引号都变成2个单引号还是显示[高危]跨站脚本攻击漏洞,