Home > Net >  Consult, SQL injection point in the file
Consult, SQL injection point in the file


Said a SQL injection point in the code, can you tell me how to modify?

The code is as follows:

<% @ page language="c #" autoeventwireup="true" inherits="swatmain_qseduserlist, wxxzInset enableEventValidation=" false "% & gt;

Anda & lt;/title> <br/><The link href="https://bbs.csdn.net/template/css/style.css" rel="stylesheet" type="text/CSS"/& gt; <br/><style type="text/CSS" & gt; <br/>* {margin: 0; padding:0; } <br/>Body {the font - size: 13 px; } <br/>Td {height: 24 px; } <br/></style> <br/></head> <br/><body> <br/><The form id="form1" runat="server" & gt; <br/><Table cellpadding="0" cellspacing="0" border="0" align="center" style="text - align: center; Width: 600 px;"> <br/><Tr> <Td style="height: 50 px; font-size:20px; The font - weight: bold;"> Sign after receiving STH situation & lt;/td> </tr> <br/><Tr> <br/><Td> <Fieldset> <br/><Legend> Have to sign for the user & lt;/legend> <Br/& gt; <br/><Asp: the GridView ID="QSData" runat="server" CellPadding="4" ForeColor="# 333333" GridLines="None" Width="600 px" AutoGenerateColumns="False" AllowPaging="True" OnPageIndexChanging="QSData_PageIndexChanging EmptyDataText"="temporarily no user sign for it!" PageSize="15" & gt; <br/><Columns> <br/><Asp: BoundField the HeaderText="has to sign for the unit" DataField="danwei"/& gt; <br/><Asp: BoundField the HeaderText="has to sign for the user" DataField="loginname"/& gt; <br/><Asp: BoundField the HeaderText="signed time" DataField="qstime"/& gt; <br/><Asp: BoundField the HeaderText="IP" DataField="IP"/& gt; <br/></Columns> <br/><FooterStyle BackColor="# 507 which cd1" the Font - Bold="True" ForeColor="White"/& gt; <br/><RowStyle BackColor="# EFF3FB"/& gt; <br/><EditRowStyle BackColor="# 2461 bf/& gt;" <br/><SelectedRowStyle BackColor="# D1DDF1" the Font - Bold="True" ForeColor="# 333333"/& gt; <br/><PagerStyle BackColor=# 2461 "bf" ForeColor="White" HorizontalAlign="Center"/& gt; <br/><HeaderStyle BackColor="# 507 which cd1" the Font - Bold="True" ForeColor="White" Height="24 px"/& gt; <br/><AlternatingRowStyle BackColor="White"/& gt; <br/></asp: GridView> <br/></fieldset> <br/></td> <br/></tr> <br/><Tr> <Td> <br/></td> </tr> <br/><Tr> <Td> <br/><Fieldset> <br/><Legend> Not to sign for the user & lt;/legend> <Br/& gt; <br/><Asp: the GridView ID="NoUserData" runat="server" AllowPaging="True" CellPadding="4" ForeColor="# 333333" <br/>GridLines="None" Width="600 px" AutoGenerateColumns="False" OnPageIndexChanging="NoUserData_PageIndexChanging EmptyDataText"="no user to sign for it!" PageSize="15" & gt; <br/><Columns> <br/><Asp: BoundField the HeaderText="not to sign for the unit" DataField="Depart"/& gt; <br/><Asp: BoundField the HeaderText="not to sign for the user" DataField="LoginName"/& gt; <br/></Columns> <br/><FooterStyle BackColor="# 507 which cd1" the Font - Bold="True" ForeColor="White"/& gt; <br/><RowStyle BackColor="# EFF3FB"/& gt; <br/><EditRowStyle BackColor="# 2461 bf/& gt;" <br/><SelectedRowStyle BackColor="# D1DDF1" the Font - Bold="True" ForeColor="# 333333"/& gt; <br/><PagerStyle BackColor=# 2461 "bf" ForeColor="White" HorizontalAlign="Center"/& gt; <br/><HeaderStyle BackColor="# 507 which cd1" the Font - Bold="True" ForeColor="White" Height="24 px"/& gt; <br/><AlternatingRowStyle BackColor="White"/& gt; <br/></asp: GridView> <br/><Asp: Label ID="lblnoqsuser" runat="server" & gt; </asp: Label> <br/><br/></fieldset> <br/></td> </tr> <br/></table> <br/></form> <br/></body> <br/></html> <br/><p class="article - content rp"> CodePudding user response: </p>No code no screenshots, injection is generally a parameterized can prevent flooding </div> <div class="th_page th_page_color"></div> <div class="umCopyright"> <p>Page link:<a href="/net/71465.html" target="_blank" style="color:#999">https//www.codepudding.com/net/71465.html</a></p> </div> <div class="detail-arr"> <div class="detail-arr-left">Prev:<a href='/net/71464.html'>C # write asynchronous? To achieve the popup window to invoke the web service</a></div> <div class="detail-arr-right">Next:<a href='/net/71466.html'>How to add text in ComboBox and values?</a></div> </div> </div> </div> </div> </div> <div class="container th_top"> <div class="row"> <div class="col-md-12"> <div class="hot-tags neitags"> <ul> <li><i class="iconfont icon-x-tags"></i> Tags:  </li> <a href='/e/tags/?tagname=ASP.NET' target='_blank'>ASP.NET</a> </ul> </div> </div> </div> </div> <div class="container th_top"> <div class="row"> <div class="col-md-12"> <div class="xiangguan"> <ul class="msg msghead"> <li class="tbname">Related</li> </ul> <ul><li><a href="/Backend/71387.html">Consult a web page for the question!</a></li><li><a href="/Backend/71359.html">LISTBOX contrast variable consult!</a></li><li><a href="/Backend/71326.html">Small white consult array related knowledge</a></li><li><a href="/Backend/71299.html">The novice consult</a></li><li><a href="/Backend/71272.html">TDBGrid consult</a></li><li><a href="/other/71179.html">Consult, huawei 9306 as the core switch, how to completely p</a></li><li><a href="/other/71170.html">Choose consulting about soft routing system</a></li><li><a href="/other/71169.html">Consult everybody a great god! About the router + gateway + </a></li><li><a href="/Softwareengineering/71101.html">Novice consult school league tables</a></li><li><a href="/database/71070.html">For penetrating a great god, and consult</a></li> </ul> </div> </div> </div> </div> <div class="container th_top"> <div class="row"> <div class="col-md-12"> <div class="flinks"> <ul> <li><i class="iconfont icon-x-tags"></i> Links:  </li> <li class="liflinks"><a target="_blank" href="/" title="CodePudding">CodePudding</a></li> </ul> </div> </div> </div> </div> <div class="footer"> <p><span style="font-size:16px;color:#666;font-weight: bold">About Us:</span>  <a href="https://www.codepudding.com/contact.html">Contact Us</a>      <a href="https://www.codepudding.com/service.html">Terms of Service</a>      <a href="https://www.codepudding.com/privacy.html"> Privacy Policy</a></p> <p class="foot_info">Copyright © 2010-2023,Powered By <a href="/" target="_blank">CodePudding</a> </p> </div> <script type="text/javascript" src="/skin/code/tianhu.js"></script> </body></html>