my datasources are locked down in CFIDE to only allow stored procedure calls.
-adam
> -----Original Message-----
> From: Tony Weeg [mailto:[EMAIL PROTECTED]
> Sent: Tuesday, March 23, 2004 04:28 PM
> To: 'CF-Talk'
> Subject: RE: Securing CF Apps.
>
> adam....
>
> you wrote:
> Yes, but you shouldnt put SQL code in your CFM pages!
>
> <cfquery> != secure code
>
> how do you do sql stuff in your cfm pages if not?
>
>
>
>
> -----Original Message-----
> From: Adrocknaphobia [mailto:[EMAIL PROTECTED]
> Sent: Tuesday, March 23, 2004 11:22 AM
> To: CF-Talk
> Subject: Re: Securing CF Apps.
>
> Yes, but you shouldnt put SQL code in your CFM pages!
>
> <cfquery> != secure code
>
> -adam
>
> > -----Original Message-----
> > From: Matt Robertson [mailto:[EMAIL PROTECTED]
> > Sent: Tuesday, March 23, 2004 03:59 PM
> > To: 'CF-Talk'
> > Subject: RE: Securing CF Apps.
> >
> > >Does anybody use the CFQUERYPARAM tag
> >
> > I think a LOT of us here do. If you need to take a first step, make
> > using cfqueryparam it (and I suppose next encrypt your url parms?)
> >
> > --------------------------------------------
> > Matt Robertson [EMAIL PROTECTED]
> > MSB Designs, Inc. http://mysecretbase.com
> >
>
>
>
>
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

