韩小末 发表于 2010-2-7 12:01:54

构造.net注入

using System.Data;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using System.Data.SqlClient;
public partial class Default2 : System.Web.UI.Page
{
   
protected void Page_Load(object sender, EventArgs e)
    {
      SqlConnection conn = new SqlConnection();
      conn.ConnectionString = ConfigurationManager.ConnectionStrings["StudyConnectionString"].ToString();
      conn.Open();
      SqlCommand cmd = new SqlCommand("select *from where id= " + this.Page.Request.Params["getid"], conn);
      cmd.ExecuteNonQuery();
      this.Page.RegisterClientScriptBlock("script", "<script>alert('注射成功')</script>");
    }
}

构造在cs文件里

寂寞在炒作 发表于 2010-5-10 01:14:51

学习啦!很有启发
页: [1]
查看完整版本: 构造.net注入