I'm sure there's more.. but you sacrifice protection from SQL Injection
by not using cfqueryparam..

Brian Gilbert

Wesley College, Melbourne Australia
Position:  Web Architect
Ph:          +61 (0)3 9881 5459
Fx:           +61 (0)3 9802 0142

Personal Website: http://www.realityloop.com/ 

>>> [EMAIL PROTECTED] 09/11/03 10:06pm >>>
Hi,

Could someone please let me know if by not using cfqueryparam in my
sql
statements I am being a bad coder?

What are the benefits of using it? My applications seem to work fine
with
out it.

Thanks

Gareth.



---
You are currently subscribed to cfaussie as:
[EMAIL PROTECTED] 
To unsubscribe send a blank email to
[EMAIL PROTECTED] 

MX Downunder AsiaPac DevCon - http://mxdu.com/

---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MX Downunder AsiaPac DevCon - http://mxdu.com/

Reply via email to