here script thats vuln: ( var id= )
...
<%
id=cekal(trim(request.querystring("id")))
tp=cekal(trim(request.querystring("tp")))
if tp<>"" then
%>
<%
end if
set conn=server.createobject("adodb.connection")
conn.open dbcon
set rst = server.createobject("ADODB.recordset")
rst.open "select * from news where id=" & id,conn,1,2
...
set rst = server.createobject("ADODB.recordset")
rst.open sqllain,conn,1,2
if not rst.eof then
do
idsbl=trim(rst("id"))
subjudulsbl=trim(rst("subjudul"))
judulsbl=trim(rst("judul"))
tanggalsbl=trim(rst("tanggal"))
jenissbl=trim(rst("jenis"))
%>
<tr>
<td width="1" valign="top"><span class="style1">•</span></td>
<td>
<div class=news-date><%=rubahtglx(tanggalsbl)%></div>
<%
if subjudulsbl<>"" then
%>
<span class=news><%=subjudulsbl%></span>
<br>
<% end if %>
<% if jenissbl="Pemilu 2009" then %>
<b><a href="pemilu/read.htm?id=<%=idsbl%>" class=news target="_blank"><%=judulsbl%></a></b>
<% elseif jenissbl="Olah Raga" then %>
<b><a href="readjadwal.htm?id=<%=idsbl%>" class=news><%=judulsbl%></a></b>
<% elseif jenissbl="Piala Dunia" then %>
<b><a href="bola2010/read.htm?id=<%=idsbl%>" class=news target="_blank"><%=judulsbl%></a></b>
<% elseif jenissbl="Fokus Piala Dunia" then %>
<b><a href="bola2010/read.htm?id=<%=idsbl%>" class=news target="_blank"><%=judulsbl%></a></b>
<% else %>
<b><a href="readnews.htm?id=<%=idsbl%>" class=news><%=judulsbl%></a></b>
<% end if %>
<br>
<br> </td>
</tr>
<%
rst.movenext
loop while not rst.eof
end if
rst.close
set rst=nothing
...
please help for patch this script..
thanks before
added code taqs - id
Edited 1 time(s). Last edit at 06/21/2011 11:50AM by sla_admin.