Yes, it’s true. Another Massive SQL injection on the network, performing a Google search results in over 510,000 modified pages.
From F-Secure WeBlog:
Check it out directly on Google page
Unless that data is sanitized before it gets saved you can’t control what the website will show to the users. This is what SQL injection is all about, exploiting weaknesses in these controls. In this case the injection code starts off like this (note, this is not the complete code):
Which decoded became:
That’s another big security issue present inside ASP pages, really dangerous:
For more details check out here.