<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Comments on snippet: 'Inserting from a form into a database'</title>
    <description>Snipplr comments feed</description>
    <link>https://snipplr.com/</link>
    <lastBuildDate>Sun, 05 Apr 2026 21:19:59 +0000</lastBuildDate>
    <item>
      <title>deepdown said on 17/Apr/2009</title>
      <link>https://snipplr.com/view/3427/inserting-from-a-form-into-a-database</link>
      <description>&lt;p&gt;You should use cfqueryparam to avoid SQL injection.&#13;
Furthermore if #form.msg# contains a single quote it breaks the code.&#13;
&#13;
The cfsqltype attribute in cfqueryparam is optional by the way :)&#13;
&#13;
`&#13;
INSERT INTO comment(poster, email, msg)&#13;
VALUES (, , )&#13;
&#13;
`&lt;/p&gt;</description>
      <pubDate>Fri, 17 Apr 2009 11:25:55 UTC</pubDate>
      <guid>https://snipplr.com/view/3427/inserting-from-a-form-into-a-database</guid>
    </item>
    <item>
      <title>deepdown said on 17/Apr/2009</title>
      <link>https://snipplr.com/view/3427/inserting-from-a-form-into-a-database</link>
      <description>&lt;p&gt;&lt;code&gt;&#13;
&#13;
INSERT INTO comment(poster, email, msg)&#13;
VALUES (, , )&#13;
&#13;
&#13;
&lt;code&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 17 Apr 2009 11:27:29 UTC</pubDate>
      <guid>https://snipplr.com/view/3427/inserting-from-a-form-into-a-database</guid>
    </item>
  </channel>
</rss>
