Hi, all:

This is At@. I am here to tell you that the website is not perfect, as it can be SQL injected so that I can basically dump EVERYTHING from the database.

I have a list of users info about your name, telephone, email and even MAILING ADDRESS and of course, a list of the site managers username and password.

The weakness appeared to be the GET parameter ID.

Hope you can upgrade the website security level.

No offence, just a simple test and a notice here.

Have a nice day.




P.S. This information can be seen in 3 sections of the website: FAQ, News and About us.