السلام عليكم لدي كود صفحة عرض المنتجات بها ثغرة sql injection
ارجو حد يساعدنى فى ترقيع الثغره بالله
<?php
if (!isset($_GET['page'])) {
$page = 1;
} else {
$page = $_GET['page'];
}
$max_results =4;
$from = (($page * $max_results) - $max_results);
$to = $from + $max_results;
$i=0;
$result = mysql_query("select * from producta where cat_id='$_REQUEST[cat_id]'and active=1 order by prod_id desc limit $from,$max_results");
$up_save =mysql_query("UPDATE cat SET save_news=save_news+1 WHERE cat_id='$_REQUEST[cat_id]'");
if (mysql_num_rows($result) > 0)
{
$row=substr($note,1,100);
?>
<?
while ($row = mysql_fetch_array($result)) {
?>
<table class="inner-table" dir="ltr" width="100%" cellpadding="0" cellspacing="1">
<tr>
<td >
<div align="center">
<table border="0" width="100%" cellspacing="1" cellpadding="0" dir="rtl">
<tr>
<td bgcolor="#ECECEC" height="106">
<table border="0" width="100%" cellpadding="0" height="137" cellspacing="4">
<tr>
<td bgcolor="#F4F4F4">
<table border="0" width="100%" cellpadding="0" height="125">
<tr>
<td width="17%" rowspan="4">
<a href="pic/<?=$row['pic']?>" rel="lightbox[roadtrip]" >
<img border="2" src="pic/<?=$row['pic']?>" width="155" height="120" align="top" style="border: 1px solid #C0C0C0; "></a></td>
<td height="20" width="14%" bgcolor="#FFFFFF">
<p align="right">
<p align="center">
<span lang="ar-sa">
<font size="2" color="#666666" face="Tahoma">
تاريخ الاضافة :</font></span></td>
<td height="20" width="67%" bgcolor="#FFFFFF">
<p align="right">
<font face="Tahoma">
<font size="2" color="#FF0000">
<?=$row['postdate']?></font><font size="2">
</font></font></td>
</tr>
<tr>
<td height="16" bgcolor="#FFFFFF" align="center">
<span lang="ar-sa">
<font size="2" color="#666666" face="Tahoma">
الاسم :</font></span></td>
<td height="16" bgcolor="#FFFFFF">
<font color="#3487B7" size="2" face="Tahoma">
<?=$row['prod_name2']?></font></td>
</tr>
<tr>
<td height="19" bgcolor="#FFFFFF" align="center">
<font color="#666666" face="Tahoma">
<span lang="ar-sa">
<font size="2"> </font><span dir="ltr"><font size="2">:نوع
الخدمة</font></span></span></font></td>
<td height="19" bgcolor="#FFFFFF">
<font color="#008000" size="2" face="Tahoma">
<?=$row['ser']?> </font> </td>
</tr>
<tr>
<td height="21" bgcolor="#FFFFFF" align="center">
<span lang="ar-sa">
<font size="2" color="#666666" face="Tahoma">
رابط متضمن : </font> </span></td>
<td height="21" bgcolor="#FFFFFF" align="center">
<a target="_blank" href="<?=$row['link']?>">
<span dir="ltr">
<font face="Tahoma" size="2">
<?=$row['link']?> </font> </span> </a> </td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</div>
<p align="center">
<img border="0" src="images/1.png" width="900" height="7"></td>
</tr>
<?
$i++;
}//end while
?>
<tr>
<td height="77" dir="rtl" align="center">
<b><div id="Example">
<?php
$queryall = "select count(*) as count from producta where cat_id='$_REQUEST[cat_id]'and active=1";
$resultall = mysql_query($queryall);
$count_row = mysql_fetch_row($resultall);
$total_results = $count_row['0'];
$total_pages = ceil($total_results / $max_results);
echo"
<div class='navc'>
الصفحات من</div>";
// Build Previous Link
for($i = 1; $i <= $total_pages; $i++) {
if (($page) == $i) {
echo "<div class='navc'>$i</a></div>";
} else {
echo "<div class='nav'><a href=\"cat.php?page=$i&cat_id=$_REQUEST[cat_id]&cat_name=$_REQUEST[cat_name]\">$i</a></div> ";
}
}
}
else
echo "<center>
<font size='2' color='#FF0000'>
<table border='0' width='30%' cellpadding='0' height='41' dir='ltr' cellspacing='0'>
<tr>
<td bgcolor='#FFE6E6' width='202'>
<p align='center'>
<font size='2' color='#393939' face='Tahoma'>
لا يوجد اعمال فى هذا القسم
</font></td>
<td bgcolor='#FFE6E6'>
<p align='center'>
<img border='0' src='images/error_button.png' width='32' height='32'></td>
</tr>
</table> </font>
</p>
";
?>