<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>[Help] Patch SQL injection</title>
        <description>here script thats vuln: ( var id= )
...

&amp;lt;%
id=cekal(trim(request.querystring(&amp;quot;id&amp;quot;)))

tp=cekal(trim(request.querystring(&amp;quot;tp&amp;quot;)))
if tp&amp;lt;&amp;gt;&amp;quot;&amp;quot; then
%&amp;gt;

&amp;lt;%
end if
set conn=server.createobject(&amp;quot;adodb.connection&amp;quot;)
conn.open dbcon
set rst = server.createobject(&amp;quot;ADODB.recordset&amp;quot;)
rst.open &amp;quot;select * from news where id=&amp;quot; &amp;amp; id,conn,1,2
...
set rst = server.createobject(&amp;quot;ADODB.recordset&amp;quot;)
rst.open sqllain,conn,1,2
if not rst.eof then
	do
	idsbl=trim(rst(&amp;quot;id&amp;quot;))
	subjudulsbl=trim(rst(&amp;quot;subjudul&amp;quot;))
	judulsbl=trim(rst(&amp;quot;judul&amp;quot;))
	tanggalsbl=trim(rst(&amp;quot;tanggal&amp;quot;))
	jenissbl=trim(rst(&amp;quot;jenis&amp;quot;))
		%&amp;gt;
                                        &amp;lt;tr&amp;gt; 
                                          &amp;lt;td width=&amp;quot;1&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;span class=&amp;quot;style1&amp;quot;&amp;gt;&amp;amp;#149;&amp;lt;/span&amp;gt;&amp;lt;/td&amp;gt;
                                          &amp;lt;td&amp;gt; 
                                            &amp;lt;div class=news-date&amp;gt;&amp;lt;%=rubahtglx(tanggalsbl)%&amp;gt;&amp;lt;/div&amp;gt;
                                            &amp;lt;%
						  if subjudulsbl&amp;lt;&amp;gt;&amp;quot;&amp;quot; then
						  %&amp;gt;
                                            &amp;lt;span class=news&amp;gt;&amp;lt;%=subjudulsbl%&amp;gt;&amp;lt;/span&amp;gt; 
                                            &amp;lt;br&amp;gt;
                                            &amp;lt;% end if %&amp;gt;
											&amp;lt;% if jenissbl=&amp;quot;Pemilu 2009&amp;quot; then %&amp;gt;
		&amp;lt;b&amp;gt;&amp;lt;a href=&amp;quot;pemilu/read.htm?id=&amp;lt;%=idsbl%&amp;gt;&amp;quot; class=news target=&amp;quot;_blank&amp;quot;&amp;gt;&amp;lt;%=judulsbl%&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/b&amp;gt;
		&amp;lt;% elseif jenissbl=&amp;quot;Olah Raga&amp;quot; then %&amp;gt;
		&amp;lt;b&amp;gt;&amp;lt;a href=&amp;quot;readjadwal.htm?id=&amp;lt;%=idsbl%&amp;gt;&amp;quot; class=news&amp;gt;&amp;lt;%=judulsbl%&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/b&amp;gt;
		&amp;lt;% elseif jenissbl=&amp;quot;Piala Dunia&amp;quot; then %&amp;gt;
		&amp;lt;b&amp;gt;&amp;lt;a href=&amp;quot;bola2010/read.htm?id=&amp;lt;%=idsbl%&amp;gt;&amp;quot; class=news target=&amp;quot;_blank&amp;quot;&amp;gt;&amp;lt;%=judulsbl%&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/b&amp;gt;
		&amp;lt;% elseif jenissbl=&amp;quot;Fokus Piala Dunia&amp;quot; then %&amp;gt;
		&amp;lt;b&amp;gt;&amp;lt;a href=&amp;quot;bola2010/read.htm?id=&amp;lt;%=idsbl%&amp;gt;&amp;quot; class=news target=&amp;quot;_blank&amp;quot;&amp;gt;&amp;lt;%=judulsbl%&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/b&amp;gt;
		&amp;lt;% else %&amp;gt;
        &amp;lt;b&amp;gt;&amp;lt;a href=&amp;quot;readnews.htm?id=&amp;lt;%=idsbl%&amp;gt;&amp;quot; class=news&amp;gt;&amp;lt;%=judulsbl%&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/b&amp;gt;
&amp;lt;%  end if %&amp;gt;
	&amp;lt;br&amp;gt;
                                            &amp;lt;br&amp;gt;                                          &amp;lt;/td&amp;gt;
                                        &amp;lt;/tr&amp;gt;
                                        &amp;lt;%	
	rst.movenext
	loop while not rst.eof	
end if
rst.close
set rst=nothing
...

please help for patch this script..
thanks before

added code taqs - id</description>
        <link>http://sla.ckers.org/forum/read.php?16,36490,36490#msg-36490</link>
        <lastBuildDate>Wed, 22 May 2013 09:31:58 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,36490,36558#msg-36558</guid>
            <title>Re: [Help] Patch SQL injection</title>
            <link>http://sla.ckers.org/forum/read.php?16,36490,36558#msg-36558</link>
            <description><![CDATA[OK <br />
First thanks for your respond<br />
second this i share the link<br />
http://pastebin.com/bquLFi8T]]></description>
            <dc:creator>thejack</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Thu, 23 Jun 2011 00:26:19 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,36490,36512#msg-36512</guid>
            <title>Re: [Help] Patch SQL injection</title>
            <link>http://sla.ckers.org/forum/read.php?16,36490,36512#msg-36512</link>
            <description><![CDATA[paste it to pastebin.com so it's easier to read please]]></description>
            <dc:creator>peann</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Sat, 18 Jun 2011 15:03:58 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,36490,36490#msg-36490</guid>
            <title>[Help] Patch SQL injection</title>
            <link>http://sla.ckers.org/forum/read.php?16,36490,36490#msg-36490</link>
            <description><![CDATA[here script thats vuln: ( var id= )<br />
...<br />
<pre class="bbcode">
&lt;%
id=cekal(trim(request.querystring(&quot;id&quot;)))

tp=cekal(trim(request.querystring(&quot;tp&quot;)))
if tp&lt;&gt;&quot;&quot; then
%&gt;

&lt;%
end if
set conn=server.createobject(&quot;adodb.connection&quot;)
conn.open dbcon
set rst = server.createobject(&quot;ADODB.recordset&quot;)
rst.open &quot;select * from news where id=&quot; &amp; id,conn,1,2
...
set rst = server.createobject(&quot;ADODB.recordset&quot;)
rst.open sqllain,conn,1,2
if not rst.eof then
	do
	idsbl=trim(rst(&quot;id&quot;))
	subjudulsbl=trim(rst(&quot;subjudul&quot;))
	judulsbl=trim(rst(&quot;judul&quot;))
	tanggalsbl=trim(rst(&quot;tanggal&quot;))
	jenissbl=trim(rst(&quot;jenis&quot;))
		%&gt;
                                        &lt;tr&gt; 
                                          &lt;td width=&quot;1&quot; valign=&quot;top&quot;&gt;&lt;span class=&quot;style1&quot;&gt;&amp;#149;&lt;/span&gt;&lt;/td&gt;
                                          &lt;td&gt; 
                                            &lt;div class=news-date&gt;&lt;%=rubahtglx(tanggalsbl)%&gt;&lt;/div&gt;
                                            &lt;%
						  if subjudulsbl&lt;&gt;&quot;&quot; then
						  %&gt;
                                            &lt;span class=news&gt;&lt;%=subjudulsbl%&gt;&lt;/span&gt; 
                                            &lt;br&gt;
                                            &lt;% end if %&gt;
											&lt;% if jenissbl=&quot;Pemilu 2009&quot; then %&gt;
		&lt;b&gt;&lt;a href=&quot;pemilu/read.htm?id=&lt;%=idsbl%&gt;&quot; class=news target=&quot;_blank&quot;&gt;&lt;%=judulsbl%&gt;&lt;/a&gt;&lt;/b&gt;
		&lt;% elseif jenissbl=&quot;Olah Raga&quot; then %&gt;
		&lt;b&gt;&lt;a href=&quot;readjadwal.htm?id=&lt;%=idsbl%&gt;&quot; class=news&gt;&lt;%=judulsbl%&gt;&lt;/a&gt;&lt;/b&gt;
		&lt;% elseif jenissbl=&quot;Piala Dunia&quot; then %&gt;
		&lt;b&gt;&lt;a href=&quot;bola2010/read.htm?id=&lt;%=idsbl%&gt;&quot; class=news target=&quot;_blank&quot;&gt;&lt;%=judulsbl%&gt;&lt;/a&gt;&lt;/b&gt;
		&lt;% elseif jenissbl=&quot;Fokus Piala Dunia&quot; then %&gt;
		&lt;b&gt;&lt;a href=&quot;bola2010/read.htm?id=&lt;%=idsbl%&gt;&quot; class=news target=&quot;_blank&quot;&gt;&lt;%=judulsbl%&gt;&lt;/a&gt;&lt;/b&gt;
		&lt;% else %&gt;
        &lt;b&gt;&lt;a href=&quot;readnews.htm?id=&lt;%=idsbl%&gt;&quot; class=news&gt;&lt;%=judulsbl%&gt;&lt;/a&gt;&lt;/b&gt;
&lt;%  end if %&gt;
	&lt;br&gt;
                                            &lt;br&gt;                                          &lt;/td&gt;
                                        &lt;/tr&gt;
                                        &lt;%	
	rst.movenext
	loop while not rst.eof	
end if
rst.close
set rst=nothing</pre>
...<br />
<br />
please help for patch this script..<br />
thanks before<br />
<br />
added code taqs - id]]></description>
            <dc:creator>thejack</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Thu, 16 Jun 2011 05:10:47 -0500</pubDate>
        </item>
    </channel>
</rss>
