主要是对数据库sql比如:(网页有user_name输入框)sql = "select * from userTable where userName = '" & request.form("user_name") & "'"攻击的时候别人可以在user_name的text控件中输入abc and '1=1,那么后台就变成:sql = "select * from userTable where userName = 'abc and '1=1'"