注册 登录
编程论坛 ASP技术论坛

asp脚本有注入点,这段代码应该如何修改呀?

稀饭。 发布于 2009-11-11 16:11, 577 次点击
<!--#include file="head.asp"-->
<style>
body{background:#fff;}
</style>
<%if Session("Usr_Username")<>"" then response.Redirect("user_index.asp")%>
<br>
<br>
<TABLE width=404 border=0 align="center" cellPadding=0 cellSpacing=1 bgcolor="#FF7E00" id=table3>
  <TBODY>
    <TR>
      <TD width=770 vAlign=top bgcolor="#FFE6CB"><table width="100%" height="80" border="0" cellpadding="5" cellspacing="0">
  <form action="login.asp" method="post">
          <tr>
            <td colspan="3" bgcolor="#FFBF79" class="font_4">商户登陆</td>
            </tr>
          <tr>
            <td width="29%"><div align="center"><span style="font-size: 12px; letter-spacing:2px">用户名</span></div></td>
            <td colspan="2"><input type="text" name="Usr_name" size="20" style="font-family: Verdana; font-size: 12px; width: 128; height: 21; border: 1px solid #82C5FA; padding-left: 3px; padding-right: 3px; padding-top: 2px" /></td>
          </tr>
          <tr>
            <td><div align="center"><span style="font-size: 12px; letter-spacing:2px">密  码</span></div></td>
            <td colspan="2"><input type="password" name="Usr_pass" size="20" style="font-family: Verdana; font-size: 12px; width: 128; height: 21; border: 1px solid #82C5FA; padding-left: 3px; padding-right: 3px; padding-top: 2px" /></td>
          </tr>
          <tr>
            <td><div align="center"><span style="font-size: 12px; letter-spacing:2px">验证码</span></div></td>
            <td width="26%"><input type="text" name="Usr_check" size="20" style="font-family: Verdana; font-size: 12px; width: 41; height: 21; border: 1px solid #82C5FA; padding-left: 3px; padding-right: 3px; padding-top: 2px" maxlength="4" /></td>
            <td width="45%"><img src="code.asp" border="0" /></td>
          </tr>
          <tr>
            <td colspan="3"><TABLE width="39%"
                          border=0 align="center" cellPadding=0 cellSpacing=0>
              <TBODY>
                <TR>
                  <TD><INPUT type=image
                              src="images/pay_index04.jpg" value="登 录"
                              name=submit></TD>
                  <TD align=right><A
                              href="web_regFloder.asp"><IMG
                              height=22 src="images/pay_index05.jpg"
                              width=64
                    border=0></A></TD>
                </TR>
              </TBODY>
            </TABLE></td>
          </tr></form>
      </table></TD>
    </TR>
  </TBODY>
</TABLE>
<!--#include file="foot.asp"-->




就是以上脚本!!!!!!!
2 回复
#2
风吹过b2009-11-11 16:40
注入,体现在你操作数据库部分,并不体现 在 HTML 表单部分.
#3
chenguoxing5172009-11-11 16:50
在login.asp这个页面进行改,也就是在你获取表单数据保存到数据库之前进行处理
1