本文摘自 xixi's blog
Sub main()
Select Case request("action")
Case "add"
If request("Vote")="" then
Response.Write "错误:" & Err.Description
Call LZ8.ShowTmpInfo(0,PageTemplateType,1)
else
Response.Write "错误:" & Err.Description
Call AddVote()
end if
...
Function AddVote()
dim rs,i
dim VoteNums,VoteStr,TitleNums,VoteUsers
dim Tmp
Set rs = LZ8.Execute("Select Top 1 VoteContent,VoteNums,VoteUsers From [LZ8_Vote] Where VoteId = "&Request("SelectID"))
...
在投票中 SelectID 存在注射