On Tuesday 27 Mar 2007, Max Hamby wrote:
> I haven't tested anything yet, but after looking at some of the code
> available, I suggest you have someone look over BobbyJay's code for
> ColdFusion ("#'s inside cfscript tags and he uses functions that don't
> exist... looks like he'smixing javascript and CF together).

Yup, you need some sort of peer review/approval/score system.
Anyone who writes:

<cfargument name="ID" type="string" required="Yes" default="#url.ID#">

<cfquery datasource="datasource" name=content>
Select * 
>From table
where ID like '#arguments.ID#' 
</cfquery>

needs shooting for leaving the obvious SQL injection attack open-
cfqueryparam, cfqueryparam, cfqueryparam :-)

-- 
Tom Chiverton
Helping to synergistically lead performance-oriented information
on: http://thefalken.livejournal.com

****************************************************

This email is sent for and on behalf of Halliwells LLP.

Halliwells LLP is a limited liability partnership registered in England and 
Wales under registered number OC307980 whose registered office address is at St 
James's Court Brown Street Manchester M2 2JF.  A list of members is available 
for inspection at the registered office. Any reference to a partner in relation 
to Halliwells LLP means a member of Halliwells LLP. Regulated by the Law 
Society.

CONFIDENTIALITY

This email is intended only for the use of the addressee named above and may be 
confidential or legally privileged.  If you are not the addressee you must not 
read it and must not use any information contained in nor copy it nor inform 
any person other than Halliwells LLP or the addressee of its existence or 
contents.  If you have received this email in error please delete it and notify 
Halliwells LLP IT Department on 0870 365 8008.

For more information about Halliwells LLP visit www.halliwells.com.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Upgrade to Adobe ColdFusion MX7
The most significant release in over 10 years. Upgrade & see new features.
http://www.adobe.com/products/coldfusion?sdid=RVJR

Archive: 
http://www.houseoffusion.com/groups/CF-Talk/message.cfm/messageid:273952
Subscription: http://www.houseoffusion.com/groups/CF-Talk/subscribe.cfm
Unsubscribe: 
http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.4

Reply via email to