Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Search Error - SQl Inject Attack Detected
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Search Error - SQl Inject Attack Detected

 Post Reply Post Reply
Author
DomitianX View Drop Down
Newbie
Newbie


Joined: 28 January 2008
Status: Offline
Points: 32
Post Options Post Options   Thanks (0) Thanks(0)   Quote DomitianX Quote  Post ReplyReply Direct Link To This Post Topic: Search Error - SQl Inject Attack Detected
    Posted: 16 October 2008 at 7:29pm
If you search for the word "keywords" the links in the results pages trigger a SQL Injection attack message:

http://forums.webwiz.net/forum_posts.asp?TID=26413&KW=keywords

Looks like it has something to do with the "KW=keywords" part. Take that off and it works fine. Looks like some more tweaking of the SQL Injection detections scripts is in order.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 17 October 2008 at 6:50am
This will be looked into s there doesn't appear to be a quick fix for this if your keywords to highlight contain syntax that could be used in an SQL Injection.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.