核对xml里面的sql语句是否出现了”<”、”>”、”&”等字符,如果出现了需要进行转义。
< <
> >
& &
' &aops;
" "
修改前的sql语句
select sum(A.sum_yhzcjz)/count(*) from (
select @rownum:=@rownum+1,dj_yhzc.*
from (select @rownum:=0) t1 ,
(select * from dj_yhzc where sum_yhzcjz is not null order by dj_yhzc.sum_yhzcjz desc) dj_yhzc
where @rownum < (select round((count(*)-1)/2) from dj_yhzc where sum_yhzcjz is not null ))A
修改后的sql语句
select sum(A.sum_yhzcjz)/count(*) from (
select @rownum:=@rownum+1,dj_yhzc.*
from (select @rownum:=0) t1 ,
(select * from dj_yhzc where sum_yhzcjz is not null order by dj_yhzc.sum_yhzcjz desc) dj_yhzc
where @rownum <(select round((count(*)-1)/2) from dj_yhzc where sum_yhzcjz is not null ))A