|
存在问题文件: user/buybag.asp
40行开始 if request.Form("action")="makeorder" then Dim productIDS,OrderRs,BagRs,OrderDetail,OrderNumber,ExpressCompany " productIDS=DelHeadAndEndDot(request.Form("productIDS"))//这个函数功能是去掉头尾的逗号 Set orderRs=Server.CreateObject(G_FS_RS) Set BagRs=Server.CreateObject(G_FS_RS) ' Set orderDetail=Server.CreateObject(G_FS_RS) orderRs.open "Select * From FS_ME_Order where 1=2",User_Conn,1,3 BagRs.open "Select mid,BuyType,AddTime,UserNumber,BuyMoney,BuyNumber from FS_ME_BuyBag where MID in("&productIDS&")",User_Conn,1,1 ; in()中注射发生!!
user/buybag.asp?action=makeorder&productIDS=1 and 1=1)and(1=1
|
|