Sameep wrote:
On 19-Aug-09, at 10:17 PM, Shirish Padalkar wrote:
This feedback.asp file is prone to SQL injection. The asp file isn't checking for the special characters in feedback or not escaping it.
Malicious users can exploit this thing to destroy the database. :(
Didn't they get a good programmer?
Its the government.. which of their websites have ever used a good programmer..?