House of Fusion
Home of the ColdFusion Community

Search cf-ot

November 22, 2008

<<   <   Today   >   >>
Su Mo Tu We Th Fr Sa
             1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30             

Search over 2,500 ColdFusion resources here  >>>      
Home /  Groups /  ColdFusion Off Topic (CF-OT)

Something other than "SQL injection attack on House of Fusion"

  << Previous Post |  RSS |  Sort Oldest First |  Sort Latest First |  Subscribe to this Group Next >> 
Top  |   Reply  |   Original Post  |   RSS Feed  |   Subscribe to this Group
Author:
Andy Matthews
08/26/2008 04:51 PM

Can someone PLEASE change the title of this thread??? > It doesn't work with stored procedures (which shouldn't matter, 'cause > I think they are type-checked by the DB first > anyways) Well, not necessarily. As Mark pointed out when this thread started - it feels like it was long, long ago - if you're calling a stored procedure from CFQUERY you have to check your variables there too. If you're using CFSTOREDPROC, that builds a prepared statement that calls the stored procedure for you, and you don't have to worry about it. Dave Watts, CTO, Fig Leaf Software http://www.figleaf.com/ Fig Leaf Software provides the highest caliber vendor-authorized instruction at our training centers in Washington DC, Atlanta, Chicago, Baltimore, Northern Virginia, or on-site at your location. Visit http://training.figleaf.com/ for more information!

Top  |   Parent  |   Reply  |   Original Post  |   RSS Feed  |   Subscribe to this Group
Author:
Bobby Hartsfield
08/26/2008 09:22 PM

Why? So everyone can create more filters? .:.:.:.:.:.:.:.:.:.:. Bobby Hartsfield http://acoderslife.com http://cf4em.com Can someone PLEASE change the title of this thread??? > It doesn't work with stored procedures (which shouldn't matter, 'cause > I think they are type-checked by the DB first > anyways) Well, not necessarily. As Mark pointed out when this thread started - it feels like it was long, long ago - if you're calling a stored procedure from CFQUERY you have to check your variables there too. If you're using CFSTOREDPROC, that builds a prepared statement that calls the stored procedure for you, and you don't have to worry about it. Dave Watts, CTO, Fig Leaf Software http://www.figleaf.com/ Fig Leaf Software provides the highest caliber vendor-authorized instruction at our training centers in Washington DC, Atlanta, Chicago, Baltimore, Northern Virginia, or on-site at your location. Visit http://training.figleaf.com/ for more information!

Top  |   Parent  |   Reply  |   Original Post  |   RSS Feed  |   Subscribe to this Group
Author:
denstar
08/27/2008 12:00 AM

> Why? So everyone can create more filters? Filters?!?!  If you've been filtering, you've been missing out! There's been action, adventure, intrigue! We've been working on it this whole time.  Has a nice little narrative... a beginning, middle, and end... some friends become enemies, some enemies become friends... at the end, we are all richer from the experience. -- They talk like angels but they live like men. St. Jerome


<< Previous Thread Today's Threads Next Thread >>

Mailing Lists