文件In/Class_UserCommand.asp :
strMonth=Request("month") //第63行
strDay=Request("day")
……
Case "month" //第84行
Dim LastDay
G_P_FileName = G_P_FileName & "month&month=" & strMonth
strDay=Left(strMonth,4) & "-" & Right(strMonth,2) & "-01"
mYear=Left(strMonth,4)
mMonth=Right(strMonth,2)
If InStr ("01,03,05,07,08,10,12",mMonth)> 0 Then
LastDay = "31"……
Else //第109行
SqlPart = " And Addtime >='"&strMonth&"01' AND Addtime < '"&strMonth&LastDay&"' "
构造合适的变量strMonth进行注射
Oblog 4.5-4.6 sql
暂无
<a href=www.oblog.cn target=_blank>www.oblog.cn</a>
暂无评论