<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>Comments on snippet: 'Inserting from a form into a database'</title>
<link>http://snipplr.com</link>
<description>Snipplr comments feed'</description>
<language>en-us</language>
<pubDate>Fri, 24 May 2013 21:45:13 GMT</pubDate>
<item>
<title>deepdown said on 4/17/09</title>
<link>http://snipplr.com/view/3427/inserting-from-a-form-into-a-database/</link>
<description><![CDATA[ <code>

INSERT INTO comment(poster, email, msg)
VALUES (, , )


<code> ]]></description>
<pubDate>Fri, 17 Apr 2009 11:27:29 GMT</pubDate>
<guid>http://snipplr.com/view/3427/inserting-from-a-form-into-a-database/</guid>
</item>
<item>
<title>deepdown said on 4/17/09</title>
<link>http://snipplr.com/view/3427/inserting-from-a-form-into-a-database/</link>
<description><![CDATA[ You should use cfqueryparam to avoid SQL injection.
Furthermore if #form.msg# contains a single quote it breaks the code.

The cfsqltype attribute in cfqueryparam is optional by the way :)

`
INSERT INTO comment(poster, email, msg)
VALUES (, , )

` ]]></description>
<pubDate>Fri, 17 Apr 2009 11:25:55 GMT</pubDate>
<guid>http://snipplr.com/view/3427/inserting-from-a-form-into-a-database/</guid>
</item>
</channel>
</rss>