0

我正在编写一个代码,它可以很好地在输出屏幕上显示输出。但是当我将数据库链接到它时,它会给出某种类型的错误,我在 Google 上搜索了很多但无法获得帮助。

import java.net.URL;
import java.io.*;
import java.util.ArrayList;
import java.sql.Connection;
import java.sql.DriverManager;

import java.sql.SQLException;
import java.sql.Statement;

public class Test{
    public ArrayList lines=new ArrayList();// global list contain <item>.......</item>

    public static void main(String[] args) throws Exception {
        Test obj= new Test();

       /* String proxy="172.16.4.7";    //proxy address
        String port= "1117";    //proxy port
        System.setProperty("http.proxyHost" , proxy);   //setting proxy
        System.setProperty("http.proxyPort", port); //setting proxy port
       */ 
        URL url = new URL("http://feeds.feedburner.com/geo/GiKR");  //geo url
        BufferedReader in = new BufferedReader(new InputStreamReader(url.openStream()));
        String line;
        line=in.readLine(); //skiping first line of xml version
        line= in.readLine();

        if (line.contains("<item>")) {
           while(line.contains("<item>")) {
              line = obj.extractItem(line); //extraction <item>a nd </item> from origional news feed

           }

        }
    }
String extractItem(String line){
    int start=0, end=0,length=0;
    start= line.indexOf("<item>");
    end= line.indexOf("</item>");
    length= line.length();
    try{
    String host = "jdbc:derby://localhost:1527/NewsFinal";
    String uName="ashfaq";
    String pass="pakistan";
    Connection con = DriverManager.getConnection( host, uName, pass );
    Statement stmt= con.createStatement();

    //lines.add(line.substring(start+6, end));
    String item=line.substring(start+6, end+7);
    //System.out.println(item);
    //String query="INSERT INTO ITEMS2(ITEM) VALUES(" + "'"+item+"'"+")";
    String query="insert into ITEMS(ITEMDATA) values("+"'" + item + "'"+")";
     stmt.executeUpdate(query);
    }
    catch(SQLException err)
    {System.out.println(err.getMessage());}

   //System.out.println(line.substring(start+6, end+7)); //strat+6 to remove item tag, start+13 removes item and title tag
    return line.substring(0,start) + line.substring(end+6,length);
    }

}

这是它生成的输出:

run:
Syntax error: Encountered "1" at line 1, column 318.
Syntax error: Encountered "1" at line 1, column 330.
Syntax error: Encountered "1" at line 1, column 342.
Syntax error: Encountered "1" at line 1, column 318.
Syntax error: Encountered "1" at line 1, column 330.
Syntax error: Encountered "1" at line 1, column 326.
Syntax error: Encountered "1" at line 1, column 351.
Syntax error: Encountered "1" at line 1, column 319.
Syntax error: Encountered "1" at line 1, column 299.
Syntax error: Encountered "1" at line 1, column 328.
Syntax error: Encountered "1" at line 1, column 307.
Syntax error: Encountered "1" at line 1, column 331.
Syntax error: Encountered "1" at line 1, column 334.
Syntax error: Encountered "1" at line 1, column 319.
Syntax error: Encountered "1" at line 1, column 334.
Syntax error: Encountered "1" at line 1, column 307.
Syntax error: Encountered "1" at line 1, column 325.
Syntax error: Encountered "1" at line 1, column 301.
Syntax error: Encountered "1" at line 1, column 312.
Syntax error: Encountered "1" at line 1, column 306.
Syntax error: Encountered "1" at line 1, column 327.
Syntax error: Encountered "1" at line 1, column 342.
Syntax error: Encountered "1" at line 1, column 333.
Syntax error: Encountered "1" at line 1, column 338.
Syntax error: Encountered "1" at line 1, column 329.
BUILD SUCCESSFUL (total time: 3 seconds)

在函数extractItem(String line)中,当我取消注释时

System.out.println(item);

它可以很好地显示输出,但无法插入我用它创建的数据库中。

数据库运行良好,我从 gui 向其中插入数据,它可以工作,也可以通过执行命令工作,但不知道为什么会出现此错误。

4

1 回答 1

0

如果它包含另一个引号并让您对SQL 注入攻击敞开大门,那么仅在任意字符串周围加上引号不足以使其作为 VALUE 有效。

使用 aPreparedStatement并在其中设置值。

您还为每个项目创建了一个新的ConnectionStatement,而不是关闭它们中的任何一个。

于 2013-11-16T09:32:26.887 回答