我的代码中有这个 sql 漏洞吗?因为我已经参数化了 SQL,所以没有 sql 注入?任何人提出一些建议将不胜感激!如果是,如何修复?
ASP.NET 代码:
public DataTable CompanySearchUser(int pageSize, int currentPage, string whereCondition)
{
DbParameter[] parms = {
DbHelper.MakeInParam("@PageSize",(DbType)SqlDbType.Int,4,pageSize),
DbHelper.MakeInParam("@PageNumber",(DbType)SqlDbType.Int,4,currentPage),
DbHelper.MakeInParam("@where",(DbType)SqlDbType.NVarChar,500,whereCondition)
};
DataTable userlist = DbHelper.ExecuteDataset(CommandType.StoredProcedure, "spCompanySearchUser", parms).Tables[0];
return userlist;
}
SQL 代码:
ALTER PROC [dbo].[spCompanySearchUser]
@PageSize INT
@PageNumber INT,
@where nvarchar(550)--like 'and a=1 '
AS
DECLARE @RowStart INT
DECLARE @RowEnd INT
DECLARE @SQL NVARCHAR(4000)
IF @PageNumber > 0
BEGIN
SET @PageNumber = @PageNumber - 1
SET @RowStart = @PageSize * @PageNumber + 1;
SET @RowEnd = @RowStart + @PageSize - 1;
SET @SQL='
WITH AllUsers
AS (SELECT
UB.UserBaicInfoID,
UB.UserName,
UB.HighestEducation,
UB.Age,
UB.Sex,
UB.WorkExperience,
UB.PositionDesired,
UB.UpdateTime,
Row_number() OVER (ORDER BY UB.UpdateTime DESC) AS RowNumber
From UserBasicInfo UB
WHERE ResumeState=1 '+@where+')
SELECT * FROM AllUsers WHERE RowNumber >=' + Str(@RowStart) + ' AND RowNumber <= ' + Str(@RowEnd) + ''
EXEC sp_executesql @SQL
END
我的代码中有这个 sql 漏洞吗?因为我已经参数化了 SQL,所以没有 sql 注入?任何人提出一些建议将不胜感激!如果是,如何修复?