> <QUOTE>Macromedia recommends that you use the cfqueryparam
> tag within every cfquery tag, to help secure your databases
> from unauthorized users.</QUOTE>
>
> Macromedia clearly think it is relevant, would you care to
> elaborate on why you think it isn't?

They're using the phrase "unauthorized users" pretty loosely within their
documentation. What they really mean is that people who can legitimately run
SQL queries that you've written, may also be able to rewrite those queries
using SQL injection attacks.

Dave Watts, CTO, Fig Leaf Software
http://www.figleaf.com/
phone: 202-797-5496
fax: 202-797-5444
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings] [Donations and Support]

Reply via email to