python注入sql_Python--sql注入

import pymysql

conn = pymysql.connect(host='211.149.218.16', user='jxz', password='123456', db='jxz', port=3306, charset='utf8')

cur = conn.cursor(cursor=pymysql.cursors.DictCursor)

name = 'zdq'

sex = 0

cur.execute('select * from bt_stu where real_name=%s and sex=%s', (name, sex)) # 可以防止sql注入

print(cur.fetchall())

def test(a, b):

print(a, b)

li = [1, 2]

test(*li)

d = {'a': '123', 'b': '456'}

test(**d)

def op_mysql_new(sql1, *data):

# 利用*data可变参数,就能防止sql注入

print(sql1)

print(data)

cur.execute(sql1, data)

print(cur.fetchall())

sql = 'select * from user where username=%s and id=%s'

name = 'haha'

id1 = 140

op_mysql_new(sql, name, id1)

# 同时执行多个sql executemany

sql = 'insert into seq (blue,red,date) values (%s,%s,%s)'

all_res = [

['16', '01,02,03,05,09,06', '2018-01-28'],

['15', '01,02,03,05,09,06', '2018-01-28'],

['14', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

['13', '01,02,03,05,09,06', '2018-01-28'],

]

cur.executemany(sql, all_res)

conn.commit()

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值