[求助]关于sql防注入的问题
我使用了一段sql 防注入的代码,在使用化境无组件上传的时候,遇到了一点问题
我将代码由requst.form 改成upload后出现了错误
Microsoft VBScript 运行时错误 (0x800A01C2)
错误的参数个数或无效的参数属性值: 'upload.Form'
<%
set upload=new upload_5xsoft
Dim Fy_Post,Fy_Get,Fy_In,Fy_Inf,Fy_Xh,Fy_db,Fy_dbstr,Kill_IP,WriteSql
Fy_In = "'|;|and|(|)|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
Fy_Inf = split(Fy_In,"|")
'--------POST部份------------------
If upload.Form<>"" Then
For Each Fy_Post In upload.Form
For Fy_Xh=0 To Ubound(Fy_Inf)
If Instr(LCase(upload.Form(Fy_Post)),Fy_Inf(Fy_Xh))<>0 Then
Response.Write "<Script Language=JavaScript>window.close();</Script>"
Response.End
End If
Next
Next
End If
%>
谁能告诉我这是什么问题吗?