html源代码:document.write('123');<head id="Head1"><title>count</title></head><body> <form name="form1" method="get" action="count.aspx?aid=1" id="form1"><div><input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNzgzNDMwNTMzZGTWVtcqTYEb91haxOkTdojiVPJjyA==" /></div>
<div> </div> </form></body></html>
cs源代码:
protected void Page_Load(object sender, EventArgs e) { if (!Page.IsPostBack) { if (Request.QueryString["id"] != null) { if (Request.QueryString["id"].ToString().Trim() != "") { DBProvider db = new DBProviderFactory().Creater(Constant.GetConnStr()); DataTable dt = new DataTable(); dt = db.ExecuteSpDataTable("p_cqut_CMS_HitsUpdate", int.Parse(Request.QueryString["id"].ToString())); if (dt.Rows.Count == 1) { Count = dt.Rows[0][0].ToString(); Response.Write("document.write("+Count+");");
} } } } }