<cfquery name="GetData" datasource="#APPLICATION.DataSource#">
DECLARE @param varchar(25),
SELECT @param=<cfqueryparam cfsqltype="cf_sql_varchar" value="#VARIABLES.orderby#">,
@dataID=<cfqueryparam cfsqltype="cf_sql_varchar" value="#VARIABLES.DataID#">,
@sql = 'SELECT ID,
FROM Table WITH (NOLOCK)
WHERE DataID = ' + @dataID + 'Order by ' + @param + ' asc';
EXEC sp_executesql @sql
Monday, August 18, 2008
Using CFQueryParam in Order By Clause
With all of the SQL Injection attacks going on in the ColdFusion world I thought that it may be beneficial to show everyone a way that I know of to have cfqueryparam'd 'Order By' clauses. If anyone knows of other ways to accomplish this, please feel free to post a comment on how to do so.
No idea what the actual error is and I couldn't find anything useful on the web, so hopefully this will help someone else. I assumed th...
Use your IDE of choice, I prefer Sublime Text because it uses the Perl Compatible Regular Expressions (PCRE) engine from the Boost library a...
For those who have gotten the following error: "java.awt.color.CMMException: Invalid image format" and tried the solutions post...
This multi-part post will be community comment driven, which basically means that in an effort to not spend too much time on details that mi...