1Anley C. Advanced SQL injection in SQL Server applications [EB/OL]. http://www.creangel.com/papers/advanced sql_inj ec- tion.pdf, An NGS Software Insight Security Research (NISR) Pub- lication, 2002.
2Litchfield D. Web application disassembly with ODBC error messages [EB/OL]. http://81.cgisecurity.com/lib/webappdis.doc.
8Anley C.Advanced SQL injection in SQL server Applications [EB/OL] .http://www.creangel.com/papers/advanced sql inj ec- tion.pdf, An NGSSoftware Insight Security Research (NISR) Publication,2002.
9Cerrudo C.Manipulating Microsoft SQL server using SQL injection [EB/OL] .http://injection.rulezz.ru/Manipulating_SQL_Server_Using_SQL lnj ection.pdf.
10[1]Su Z,Wassermann G.The Essence of Command Injection Attacks in Web Applications[c].The 33rd Annual Symposium on Principles of Programming Languages(POPL 2006).2006,1:372~382.