123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147 |
- 2021-03-26 12:51:56
- [ERROR]-[Thread: XNIO-1 task-4]-[com.jfinal.core.ActionHandler.handle()]: com.jfinal.club._admin.data.wxuser.AdminWxUserController.export() : /admin/wxuser/export?all=0&ids=1000
- com.jfinal.plugin.activerecord.ActiveRecordException: java.sql.SQLException: sql injection violation, syntax error: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id : select * from wx_user where nickname is not null id in (1000) order by create_time desc
- at com.jfinal.plugin.activerecord.Model.find(Model.java:690)
- at com.jfinal.plugin.activerecord.Model.find(Model.java:703)
- at com.jfinal.plugin.activerecord.Model.find(Model.java:710)
- at com.jfinal.club._admin.data.wxuser.AdminWxUserController.export(AdminWxUserController.java:93)
- at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
- at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
- at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
- at java.lang.reflect.Method.invoke(Method.java:498)
- at com.jfinal.aop.Invocation.invoke(Invocation.java:97)
- at com.jfinal.club._admin.admin_interface.ContentPathInterface.intercept(ContentPathInterface.java:20)
- at com.jfinal.aop.Invocation.invoke(Invocation.java:91)
- at com.jfinal.club._admin.admin_interface.AdminSessionInterface.intercept(AdminSessionInterface.java:40)
- at com.jfinal.aop.Invocation.invoke(Invocation.java:91)
- at com.jfinal.core.ActionHandler.handle(ActionHandler.java:89)
- at com.jfinal.core.JFinalFilter.doFilter(JFinalFilter.java:90)
- at io.undertow.servlet.core.ManagedFilter.doFilter(ManagedFilter.java:61)
- at io.undertow.servlet.handlers.FilterHandler$FilterChainImpl.doFilter(FilterHandler.java:131)
- at io.undertow.servlet.handlers.FilterHandler.handleRequest(FilterHandler.java:84)
- at io.undertow.servlet.handlers.security.ServletSecurityRoleHandler.handleRequest(ServletSecurityRoleHandler.java:62)
- at io.undertow.servlet.handlers.ServletChain$1.handleRequest(ServletChain.java:68)
- at io.undertow.servlet.handlers.ServletDispatchingHandler.handleRequest(ServletDispatchingHandler.java:36)
- at io.undertow.servlet.handlers.RedirectDirHandler.handleRequest(RedirectDirHandler.java:68)
- at io.undertow.servlet.handlers.security.SSLInformationAssociationHandler.handleRequest(SSLInformationAssociationHandler.java:132)
- at io.undertow.servlet.handlers.security.ServletAuthenticationCallHandler.handleRequest(ServletAuthenticationCallHandler.java:57)
- at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
- at io.undertow.security.handlers.AbstractConfidentialityHandler.handleRequest(AbstractConfidentialityHandler.java:46)
- at io.undertow.servlet.handlers.security.ServletConfidentialityConstraintHandler.handleRequest(ServletConfidentialityConstraintHandler.java:64)
- at io.undertow.security.handlers.AuthenticationMechanismsHandler.handleRequest(AuthenticationMechanismsHandler.java:60)
- at io.undertow.servlet.handlers.security.CachedAuthenticatedSessionHandler.handleRequest(CachedAuthenticatedSessionHandler.java:77)
- at io.undertow.security.handlers.AbstractSecurityContextAssociationHandler.handleRequest(AbstractSecurityContextAssociationHandler.java:43)
- at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
- at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
- at io.undertow.servlet.handlers.SessionRestoringHandler.handleRequest(SessionRestoringHandler.java:119)
- at io.undertow.servlet.handlers.ServletInitialHandler.handleFirstRequest(ServletInitialHandler.java:269)
- at io.undertow.servlet.handlers.ServletInitialHandler.access$100(ServletInitialHandler.java:78)
- at io.undertow.servlet.handlers.ServletInitialHandler$2.call(ServletInitialHandler.java:133)
- at io.undertow.servlet.handlers.ServletInitialHandler$2.call(ServletInitialHandler.java:130)
- at io.undertow.servlet.core.ServletRequestContextThreadSetupAction$1.call(ServletRequestContextThreadSetupAction.java:48)
- at io.undertow.servlet.core.ContextClassLoaderSetupAction$1.call(ContextClassLoaderSetupAction.java:43)
- at io.undertow.servlet.handlers.ServletInitialHandler.dispatchRequest(ServletInitialHandler.java:249)
- at io.undertow.servlet.handlers.ServletInitialHandler.access$000(ServletInitialHandler.java:78)
- at io.undertow.servlet.handlers.ServletInitialHandler$1.handleRequest(ServletInitialHandler.java:99)
- at io.undertow.server.Connectors.executeRootHandler(Connectors.java:376)
- at io.undertow.server.HttpServerExchange$1.run(HttpServerExchange.java:830)
- at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
- at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
- at java.lang.Thread.run(Thread.java:748)
- Caused by: java.sql.SQLException: sql injection violation, syntax error: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id : select * from wx_user where nickname is not null id in (1000) order by create_time desc
- at com.alibaba.druid.wall.WallFilter.check(WallFilter.java:725)
- at com.alibaba.druid.wall.WallFilter.connection_prepareStatement(WallFilter.java:253)
- at com.alibaba.druid.filter.FilterChainImpl.connection_prepareStatement(FilterChainImpl.java:448)
- at com.alibaba.druid.proxy.jdbc.ConnectionProxyImpl.prepareStatement(ConnectionProxyImpl.java:342)
- at com.alibaba.druid.pool.DruidPooledConnection.prepareStatement(DruidPooledConnection.java:346)
- at sun.reflect.GeneratedMethodAccessor6.invoke(Unknown Source)
- at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
- at java.lang.reflect.Method.invoke(Method.java:498)
- at com.jfinal.plugin.activerecord.SqlReporter.invoke(SqlReporter.java:58)
- at com.sun.proxy.$Proxy5.prepareStatement(Unknown Source)
- at com.jfinal.plugin.activerecord.Model.find(Model.java:676)
- at com.jfinal.plugin.activerecord.Model.find(Model.java:688)
- ... 46 more
- Caused by: com.alibaba.druid.sql.parser.ParserException: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id
- at com.alibaba.druid.sql.parser.SQLParser.printError(SQLParser.java:239)
- at com.alibaba.druid.sql.parser.SQLStatementParser.parseStatementList(SQLStatementParser.java:362)
- at com.alibaba.druid.sql.parser.SQLStatementParser.parseStatementList(SQLStatementParser.java:79)
- at com.alibaba.druid.wall.WallProvider.checkInternal(WallProvider.java:620)
- at com.alibaba.druid.wall.WallProvider.check(WallProvider.java:574)
- at com.alibaba.druid.wall.WallFilter.check(WallFilter.java:712)
- ... 57 more
- 2021-03-26 12:52:02
- [ERROR]-[Thread: XNIO-1 task-2]-[com.jfinal.core.ActionHandler.handle()]: com.jfinal.club._admin.data.wxuser.AdminWxUserController.export() : /admin/wxuser/export?all=0&ids=1000
- com.jfinal.plugin.activerecord.ActiveRecordException: java.sql.SQLException: sql injection violation, syntax error: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id : select * from wx_user where nickname is not null id in (1000) order by create_time desc
- at com.jfinal.plugin.activerecord.Model.find(Model.java:690)
- at com.jfinal.plugin.activerecord.Model.find(Model.java:703)
- at com.jfinal.plugin.activerecord.Model.find(Model.java:710)
- at com.jfinal.club._admin.data.wxuser.AdminWxUserController.export(AdminWxUserController.java:93)
- at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
- at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
- at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
- at java.lang.reflect.Method.invoke(Method.java:498)
- at com.jfinal.aop.Invocation.invoke(Invocation.java:97)
- at com.jfinal.club._admin.admin_interface.ContentPathInterface.intercept(ContentPathInterface.java:20)
- at com.jfinal.aop.Invocation.invoke(Invocation.java:91)
- at com.jfinal.club._admin.admin_interface.AdminSessionInterface.intercept(AdminSessionInterface.java:40)
- at com.jfinal.aop.Invocation.invoke(Invocation.java:91)
- at com.jfinal.core.ActionHandler.handle(ActionHandler.java:89)
- at com.jfinal.core.JFinalFilter.doFilter(JFinalFilter.java:90)
- at io.undertow.servlet.core.ManagedFilter.doFilter(ManagedFilter.java:61)
- at io.undertow.servlet.handlers.FilterHandler$FilterChainImpl.doFilter(FilterHandler.java:131)
- at io.undertow.servlet.handlers.FilterHandler.handleRequest(FilterHandler.java:84)
- at io.undertow.servlet.handlers.security.ServletSecurityRoleHandler.handleRequest(ServletSecurityRoleHandler.java:62)
- at io.undertow.servlet.handlers.ServletChain$1.handleRequest(ServletChain.java:68)
- at io.undertow.servlet.handlers.ServletDispatchingHandler.handleRequest(ServletDispatchingHandler.java:36)
- at io.undertow.servlet.handlers.RedirectDirHandler.handleRequest(RedirectDirHandler.java:68)
- at io.undertow.servlet.handlers.security.SSLInformationAssociationHandler.handleRequest(SSLInformationAssociationHandler.java:132)
- at io.undertow.servlet.handlers.security.ServletAuthenticationCallHandler.handleRequest(ServletAuthenticationCallHandler.java:57)
- at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
- at io.undertow.security.handlers.AbstractConfidentialityHandler.handleRequest(AbstractConfidentialityHandler.java:46)
- at io.undertow.servlet.handlers.security.ServletConfidentialityConstraintHandler.handleRequest(ServletConfidentialityConstraintHandler.java:64)
- at io.undertow.security.handlers.AuthenticationMechanismsHandler.handleRequest(AuthenticationMechanismsHandler.java:60)
- at io.undertow.servlet.handlers.security.CachedAuthenticatedSessionHandler.handleRequest(CachedAuthenticatedSessionHandler.java:77)
- at io.undertow.security.handlers.AbstractSecurityContextAssociationHandler.handleRequest(AbstractSecurityContextAssociationHandler.java:43)
- at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
- at io.undertow.server.handlers.PredicateHandler.handleRequest(PredicateHandler.java:43)
- at io.undertow.servlet.handlers.SessionRestoringHandler.handleRequest(SessionRestoringHandler.java:119)
- at io.undertow.servlet.handlers.ServletInitialHandler.handleFirstRequest(ServletInitialHandler.java:269)
- at io.undertow.servlet.handlers.ServletInitialHandler.access$100(ServletInitialHandler.java:78)
- at io.undertow.servlet.handlers.ServletInitialHandler$2.call(ServletInitialHandler.java:133)
- at io.undertow.servlet.handlers.ServletInitialHandler$2.call(ServletInitialHandler.java:130)
- at io.undertow.servlet.core.ServletRequestContextThreadSetupAction$1.call(ServletRequestContextThreadSetupAction.java:48)
- at io.undertow.servlet.core.ContextClassLoaderSetupAction$1.call(ContextClassLoaderSetupAction.java:43)
- at io.undertow.servlet.handlers.ServletInitialHandler.dispatchRequest(ServletInitialHandler.java:249)
- at io.undertow.servlet.handlers.ServletInitialHandler.access$000(ServletInitialHandler.java:78)
- at io.undertow.servlet.handlers.ServletInitialHandler$1.handleRequest(ServletInitialHandler.java:99)
- at io.undertow.server.Connectors.executeRootHandler(Connectors.java:376)
- at io.undertow.server.HttpServerExchange$1.run(HttpServerExchange.java:830)
- at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
- at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
- at java.lang.Thread.run(Thread.java:748)
- Caused by: java.sql.SQLException: sql injection violation, syntax error: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id : select * from wx_user where nickname is not null id in (1000) order by create_time desc
- at com.alibaba.druid.wall.WallFilter.check(WallFilter.java:725)
- at com.alibaba.druid.wall.WallFilter.connection_prepareStatement(WallFilter.java:253)
- at com.alibaba.druid.filter.FilterChainImpl.connection_prepareStatement(FilterChainImpl.java:448)
- at com.alibaba.druid.proxy.jdbc.ConnectionProxyImpl.prepareStatement(ConnectionProxyImpl.java:342)
- at com.alibaba.druid.pool.DruidPooledConnection.prepareStatement(DruidPooledConnection.java:346)
- at sun.reflect.GeneratedMethodAccessor6.invoke(Unknown Source)
- at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
- at java.lang.reflect.Method.invoke(Method.java:498)
- at com.jfinal.plugin.activerecord.SqlReporter.invoke(SqlReporter.java:58)
- at com.sun.proxy.$Proxy5.prepareStatement(Unknown Source)
- at com.jfinal.plugin.activerecord.Model.find(Model.java:676)
- at com.jfinal.plugin.activerecord.Model.find(Model.java:688)
- ... 46 more
- Caused by: com.alibaba.druid.sql.parser.ParserException: syntax error, error in :'null id in (1000) order by create_t',expect IDENTIFIER, actual IDENTIFIER id
- at com.alibaba.druid.sql.parser.SQLParser.printError(SQLParser.java:239)
- at com.alibaba.druid.sql.parser.SQLStatementParser.parseStatementList(SQLStatementParser.java:362)
- at com.alibaba.druid.sql.parser.SQLStatementParser.parseStatementList(SQLStatementParser.java:79)
- at com.alibaba.druid.wall.WallProvider.checkInternal(WallProvider.java:620)
- at com.alibaba.druid.wall.WallProvider.check(WallProvider.java:574)
- at com.alibaba.druid.wall.WallFilter.check(WallFilter.java:712)
- ... 57 more
|