user/buybag.asp
40行开始 
if request.Form("action")="makeorder" then   
Dim productIDS,OrderRs,BagRs,OrderDetail,OrderNumber,ExpressCompany
productIDS=DelHeadAndEndDot(request.Form("productIDS"))//这个函数功能是去掉头尾的逗号 
Set OrderRs=Server.CreateObject(G_FS_RS)
Set BagRs=Server.CreateObject(G_FS_RS)
Set OrderDetail=Server.CreateObject(G_FS_RS) 
OrderRs.open "Select * From FS_ME_Order where 1=2",User_Conn,1,3
BagRs.open "Select mid,BuyType,AddTime,UserNumber,BuyMoney,BuyNumber from FS_ME_BuyBag where MID in("&productIDS&")",User_Conn,1,1
in()中注射发生!!
user/buybag.asp?action=makeorder&productIDS=1 and 1=1)and(1=1
posted on 2007-08-22 15:52  %5C  阅读(257)  评论(0编辑  收藏  举报