I'm finishing up on a site and the owner has asked that users be allowed to
upload news articles into a form page.

The form page has a DHTML text editor on it that submits to the Access
database.

I was curious to know if it was possible for a user to upload malicious code
into the database this way.

The field being utilized is a memo field with a 30K character limit set on
it.

Using: FrontPage2003/Access & Win2K server

Thanks

Re: Security & DHTML Editors by FP2003

FP2003
Sat Apr 23 16:22:05 CDT 2005

Clarification: the owner has asked that users be allowed to upload news
articles into the database using a form page.




Re: Security & DHTML Editors by clintonG

clintonG
Sat Apr 23 23:06:59 CDT 2005

Google: form cross site scripting
Google: form sql injection attack


<%= Clinton Gallagher
METROmilwaukee (sm) "A Regional Information Service"
NET csgallagher AT metromilwaukee.com
URL http://metromilwaukee.com/
URL http://clintongallagher.metromilwaukee.com/


"FP2003" <FP2003@ms.net> wrote in message
news:J72dnS1wfKjgIfffRVn-uQ@centurytel.net...
> Clarification: the owner has asked that users be allowed to upload news
> articles into the database using a form page.
>
>
>



Re: Security & DHTML Editors by FP2003

FP2003
Sun Apr 24 23:12:26 CDT 2005

WOW !

Great lesson...thanks

"clintonG" <csgallagher@REMOVETHISTEXTmetromilwaukee.com> wrote in message
news:#vPASMISFHA.204@TK2MSFTNGP15.phx.gbl...
> Google: form cross site scripting
> Google: form sql injection attack
>
>
> <%= Clinton Gallagher
> METROmilwaukee (sm) "A Regional Information Service"
> NET csgallagher AT metromilwaukee.com
> URL http://metromilwaukee.com/
> URL http://clintongallagher.metromilwaukee.com/
>
>
> "FP2003" <FP2003@ms.net> wrote in message
> news:J72dnS1wfKjgIfffRVn-uQ@centurytel.net...
> > Clarification: the owner has asked that users be allowed to upload news
> > articles into the database using a form page.
> >
> >
> >
>
>