【发布时间】:2014-05-30 05:18:25
【问题描述】:
我想使用 Linq 而不是下面的硬编码 Sql Injection 从 SqlServer DATABASE TABLES 中搜索。如何在C#Linq中检索动态生成的web控件输入文本并替换Linq中整个Sql注入进行搜索。
我的 C# 代码:
protected void Search_Button_Click(object sender, EventArgs e)
{
try
{
Table maintable = Select.FindControl("dynamic_filter_table_id") as Table;
int rc = maintable.Rows.Count;
if (rc == 1)
{
DropDownList D1 = maintable.FindControl("MainDDL") as DropDownList;
if (D1.SelectedValue.Contains("decimal"))
{
TextBox T1 = maintable.FindControl("txtbox1") as TextBox;
TextBox T2 = maintable.FindControl("txtbox2") as TextBox;
SqlDataAdapter sql = new SqlDataAdapter("SELECT F.Col1,F.Col2,V.COL1, col2,col3, col4 , col5, cl6 FROM TABLE1 as V , TABL2 as F WHERE V.Col1 = F.Col1 AND " + DDL1.SelectedItem.Text + " >= " + T1.Text + " AND " + DDl1.SelectedItem.Text + " <= " + T2.Text, con);
DataSet data = new DataSet();
sql.Fill(data);
con.Close();
Session["DataforSearch_DDL"] = data.Tables[0];
}
}
}
catch
{
ImproperSearch();
}
}
【问题讨论】:
-
将所有查询更改为 LINQ 非常耗时,并且最终取决于项目的大小。要修复代码以从 sql 注入中保存,更好的选择是使用参数化查询。参考这两个链接 1) aspsnippets.com/Articles/… 2) stackoverflow.com/questions/5468425/…
标签: c# asp.net linq search sql-injection