Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - SQL Injection Attack Detected
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

SQL Injection Attack Detected

 Post Reply Post Reply
Author
jwmagno View Drop Down
Groupie
Groupie


Joined: 11 October 2008
Status: Offline
Points: 33
Post Options Post Options   Thanks (0) Thanks(0)   Quote jwmagno Quote  Post ReplyReply Direct Link To This Post Topic: SQL Injection Attack Detected
    Posted: 18 November 2008 at 12:40pm
A user reported the following error while doing a search on our forum. Any ideas what this means?
 
 
Server Error in Forum Application
WARNING: SQL Injection attack detected
Please contact the forum administrator.
 
Support Error Code: -err_SQLServer_SqlInjectionTest()
File Name: functions_common.asp
 
Error details:
Back to Top
123Simples View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 July 2007
Location: United Kingdom
Status: Offline
Points: 1192
Post Options Post Options   Thanks (0) Thanks(0)   Quote 123Simples Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 12:46pm
This was briefly touched upon here which may help explain why this happened. It would seem to do with what words that user typed into the search criteria
Back to Top
jwmagno View Drop Down
Groupie
Groupie


Joined: 11 October 2008
Status: Offline
Points: 33
Post Options Post Options   Thanks (0) Thanks(0)   Quote jwmagno Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 12:57pm
Thank you for the quick response. The user was searching for something with the word key in their search. Perhaps that did it.
Back to Top
123Simples View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 July 2007
Location: United Kingdom
Status: Offline
Points: 1192
Post Options Post Options   Thanks (0) Thanks(0)   Quote 123Simples Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 1:00pm
I would assume so Wink
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 18 November 2008 at 2:55pm
This has been fixed for the next release and is to do with the SQL Injection test being working to well and checking the keywords to be highlighted in the page a bit to well.
Back to Top
jwmagno View Drop Down
Groupie
Groupie


Joined: 11 October 2008
Status: Offline
Points: 33
Post Options Post Options   Thanks (0) Thanks(0)   Quote jwmagno Quote  Post ReplyReply Direct Link To This Post Posted: 19 November 2008 at 2:07pm
Here is how to reproduce the error on my forum
 
Click Search then advanced search
Search all forums for the following keywords this key is already associated
Click one of the search results and the error occurs.
 
How do I get this patch? This is a common error message produced by our software.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 19 November 2008 at 5:52pm
Originally posted by WebWiz-Bruce WebWiz-Bruce wrote:

This has been fixed for the next release
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.