This is incorrect.  Using <cfquery> in conjunction with <cfqueryparam> correctly is perfectly fine.

----- Original Message -----
From: Adrocknaphobia <[EMAIL PROTECTED]>
Date: Tuesday, March 23, 2004 9:22 am
Subject: Re:  Securing CF Apps.

> Yes, but you shouldnt put SQL code in your CFM pages!
>
> <cfquery> != secure code
>
> -adam
>
> > -----Original Message-----
> > From: Matt Robertson [EMAIL PROTECTED]
> > Sent: Tuesday, March 23, 2004 03:59 PM
> > To: 'CF-Talk'
> > Subject: RE: Securing CF Apps.
> >
> > >Does anybody use the CFQUERYPARAM tag
> >
> > I think a LOT of us here do.  If you need to take a first step, make
> > using cfqueryparam it (and I suppose next encrypt your url parms?)
> >
> > --------------------------------------------
> >  Matt Robertson       [EMAIL PROTECTED]
> >  MSB Designs, Inc.  http://mysecretbase.com
> >
>
>
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to