View Single Post
Old June 27th, 2008, 8:29 PM   #2 (permalink)
gmax21
Registered User
Seasoned Poster
 
gmax21's Avatar
 
Joined in Jun 2008
Lives in UK
68 posts
Gave thanks: 5
Thanked 8 times
What sort of form is it that your using, and do you perform correct sanitation of the code to prevent SQL injections?

They could also be using the url field and writing a string query.

I say could, but it might not be so serious. Perhaps request your server log and see if you can track how it's done.

Last edited by gmax21; June 27th, 2008 at 8:31 PM..
gmax21 is offline   Reply With Quote
This user thanks gmax21 for this great post!
hunna03 (July 1st, 2008)