1 Comments
- Scott2, on 04/28/2008, -0/+1To be fair, the whole point of SQL injection is to take advantage of improperly secured applications - not the application server software.
itpro.co.uk — Microsoft has denied that there is any vulnerability in its Internet Information Services (IIS) or SQL server after reports of a massive SQL injection infecting hundreds of thousands of web pages.