我的网站遭受 SQL 注入攻击。我的 Web 开发人员拒绝承认参数化查询,说他的转义脚本就足够了。有人可以通过展示如何将以下用经典 asp 编写的查询转换为参数化查询来提供帮助吗?
conn.Execute "insert into tblGROUPcomments ([thecomment], [date_of_entry], [groupid], [submittedby]) " _
& "values ('" _
& Server.HTMLEncode(cleanuptext(request.form("txtcomments"))) & _
"','" & FormatMediumDate(date()) & _
"','" & session("groupid") & _
"','" & session("userid") & "')"
session("errmessageT") = ""
session("varcommentT") = ""
response.redirect("../showallcommentsGROUPS.asp?gid=" & session("groupid")) & "#comments"