HuwR
Forum Admin
United Kingdom
20584 Posts |
Posted - 08 October 2012 : 02:36:24
|
Sorry, but what version of the forum are you looking at ?
The first code line in pop_printer_friendly.asp does this Topic_ID = cLng(Request.QueryString("TOPIC_ID")) so you can't inject anything as it would error unless it was a valid long int
post.asp already checks TOPIC_ID, FORUM_ID, CAT__ID and REPLY_ID so your report and fix are both incorrect |
MVC .net dev/test site | MVC .net running on Raspberry Pi |
|
|