Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - RTE Mod error using ’
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Forum LockedRTE Mod error using ’

 Post Reply Post Reply
Author
shabrawy911 View Drop Down
Newbie
Newbie


Joined: 05 June 2004
Status: Offline
Points: 7
Post Options Post Options   Thanks (0) Thanks(0)   Quote shabrawy911 Quote  Post ReplyReply Direct Link To This Post Topic: RTE Mod error using ’
    Posted: 28 June 2004 at 7:12am
b4 send it to the database replace every ' wiz "
and it will work
Back to Top
sergi_gil_calvo View Drop Down
Newbie
Newbie


Joined: 16 December 2004
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote sergi_gil_calvo Quote  Post ReplyReply Direct Link To This Post Posted: 18 January 2005 at 3:26am
where can i do this?
 
Thanks


Edited by sergi_gil_calvo - 18 January 2005 at 3:26am
Back to Top
djlurch View Drop Down
Groupie
Groupie
Avatar

Joined: 05 January 2005
Location: United States
Status: Offline
Points: 58
Post Options Post Options   Thanks (0) Thanks(0)   Quote djlurch Quote  Post ReplyReply Direct Link To This Post Posted: 19 January 2005 at 10:15am
Go to the boards at 4guysfromrolla.com and post your ASP questions.  This is a discussion board for borg's ASP components.
 
That being said...the apostrophe/SQL issue is one of the fundamental issues in terms of security of an ASP application and the proper design of a working ASP application.
 
When using a SQL statement like that...always replace one apostrophe with two.
foo = Replace(variable,"'","''")
 
In SQL the apostrophe denotes the opening and closing of a quoted section.  You can see that the apostrophe in the word don't is wreaking havoc with your SQL statement.
 
This simple oversight has led to what I estimate to be a MAJOR security flaw in 5% of ASP applications.  Look up "SQL Injection" for all the gory details.
 
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.