I may not have been clear.  My global error handler sends the emails to my 
address.  My sites throw errors, I fix them.  In this case, I noticed the 
WHERE i.uniqueID = '' IDArray[index] '' within the error message that I 
rec'd.  I am assuming that the site visitor substituted IDArray[index] where 
the url.id would have been, something like

mypage.cfm?id=40

mypage.cfm?id=IDArray[index]

I have added a <cfqueryparam> to the sql statement, but am inquiring as to 
wheter this was an attempted hack....

charlie



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Message: http://www.houseoffusion.com/lists.cfm/link=i:4:231123
Archives: http://www.houseoffusion.com/cf_lists/threads.cfm/4
Subscription: http://www.houseoffusion.com/lists.cfm/link=s:4
Unsubscribe: 
http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.4
Donations & Support: http://www.houseoffusion.com/tiny.cfm/54

Reply via email to