|
What sort of form is it that your using, and do you perform correct sanitation of the code to prevent SQL injections?
They could also be using the url field and writing a string query.
I say could, but it might not be so serious. Perhaps request your server log and see if you can track how it's done.
Last edited by gmax21; June 27th, 2008 at 8:31 PM..
|