From 78d19c1c677a246f4a6dd963abf0497762c72111 Mon Sep 17 00:00:00 2001 From: Mobb autofixer Date: Mon, 25 Sep 2023 08:58:56 +0000 Subject: [PATCH 1/2] mobb fix commit: 5940036f-9698-452a-bd11-c6601539063f --- src/main/webapp/vulnerability/forum.jsp | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/src/main/webapp/vulnerability/forum.jsp b/src/main/webapp/vulnerability/forum.jsp index 6c71c00..5034d90 100644 --- a/src/main/webapp/vulnerability/forum.jsp +++ b/src/main/webapp/vulnerability/forum.jsp @@ -5,7 +5,7 @@ --%> <%@page import="java.sql.Connection"%> -<%@page import="java.sql.Statement"%> +<%@page import="java.sql.PreparedStatement"%> <%@page import="java.sql.SQLException"%> <%@page import="java.sql.ResultSetMetaData"%> @@ -29,7 +29,7 @@
Title :
Message:
- " size="50"/>
+ " size="50"/>
@@ -43,9 +43,12 @@ String title=request.getParameter("title"); if(con!=null && !con.isClosed()) { - Statement stmt = con.createStatement(); + PreparedStatement pstmt = con.prepareStatement("INSERT into posts(content,title,user) values (?,?,?)"); + pstmt.setString(1, content); + pstmt.setString(2, title); + pstmt.setString(3, user); //Posting Content - stmt.executeUpdate("INSERT into posts(content,title,user) values ('"+content+"','"+title+"','"+user+"')"); + pstmt.executeUpdate(); out.print("Successfully posted"); } } From 5bf99f26320a1444b22328c151891b9a8e005a0d Mon Sep 17 00:00:00 2001 From: Mobb autofixer Date: Mon, 25 Sep 2023 08:58:57 +0000 Subject: [PATCH 2/2] mobb fix commit: 6d578cde-0711-4f1a-9f12-f6f6c7b5079f --- src/main/java/org/cysecurity/cspf/jvl/controller/Register.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/main/java/org/cysecurity/cspf/jvl/controller/Register.java b/src/main/java/org/cysecurity/cspf/jvl/controller/Register.java index afa2f83..d3fe111 100644 --- a/src/main/java/org/cysecurity/cspf/jvl/controller/Register.java +++ b/src/main/java/org/cysecurity/cspf/jvl/controller/Register.java @@ -55,7 +55,7 @@ protected void processRequest(HttpServletRequest request, HttpServletResponse re { Statement stmt = con.createStatement(); - stmt.executeUpdate("INSERT into users(username, password, email, About,avatar,privilege,secretquestion,secret) values ('"+user+"','"+pass+"','"+email+"','"+about+"','default.jpg','user',1,'"+secret+"')"); + stmt.executeUpdate("INSERT into users(username, password, email, About,avatar,privilege,secretquestion,secret) values ('"+user+"','"+pass+"','"+email+"',"+stmt.enquoteLiteral(String.valueOf(about))+",'default.jpg','user',1,'"+secret+"')"); stmt.executeUpdate("INSERT into UserMessages(recipient, sender, subject, msg) values ('"+user+"','admin','Hi','Hi
This is admin of this page.
Welcome to Our Forum')"); response.sendRedirect("index.jsp");