您的位置:首页 > 数据库

国内一个网站居然把SQL直接贴在源代码里面了

2011-03-10 00:00 555 查看
工作需要,对一些网站进行研究,发现国内某招聘网站的源代码真NB,居然把SQL语句贴在源代码的末尾,真危险哦,看看:

</body>
</html>
<div style="display:none;">02.04688 秒
select top 1000 id from new_search_job_result_data where Job_state=0 and datediff(month,Job_renovate_date,getdate()) < 3  and ( left(Job_work_city_id1,2)=11 or left(Job_work_city_id2,2)=11 or left(Job_work_city_id3,2)=11 ) and ( left(Job_station_id1,2)=10 or left(Job_station_id2,2)=10 or left(Job_station_id3,2)=10 ) and Job_issue_date >=datediff(dd,30,getdate()) and Com_serviceStatus=1  and Com_memberStatus<>0 order by Job_renovate_date desc
</div>

select top 1000 id from new_search_job_result_data where Job_state=0 and datediff(month,Job_renovate_date,getdate()) < 3  and ( left(Job_work_city_id1,2)=11 or left(Job_work_city_id2,2)=11 or left(Job_work_city_id3,2)=11 ) and ( left(Job_station_id1,2)=10 or left(Job_station_id2,2)=10 or left(Job_station_id3,2)=10 ) and Job_issue_date >=datediff(dd,30,getdate()) and Com_serviceStatus=1  and Com_memberStatus<>0 order by Job_renovate_date desc

太NB了,佩服的五体投地,而且还是放在</html>标签后面
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: 
相关文章推荐