修复漏洞
1./proshow.asp?classname=
<%
classname=replace(request("classname"),"'","")
if classname="" then
set rs=server.CreateObject("adodb.recordset")
rs.open "select * from products order by proid desc",conn,1,1
%>
/newlist.asp?newid=
<%
Set res=Server.CreateObject("ADODB.RecordSet")
sql="select * from news where newid="&Cint(request("newID"))
res.Open sql,conn,1,1
%>
/prolist.asp?proid=
<%
Set res=Server.CreateObject("ADODB.RecordSet")
sql="select * from products where proid="&Cint(request("proID"))
res.Open sql,conn,1,1
%>
/order.asp?proid=
<%
Set res=Server.CreateObject("ADODB.RecordSet")
sql="select * from products where proid="&Cint (request("proID"))