View Single Post
  #11 (permalink)  
Old 09-10-09, 04:36
gvee gvee is offline
www.gvee.co.uk
 
Join Date: Jan 2007
Location: UK
Posts: 10,156
I suggest you change it to a stored procedure or at the very least a parameterised query! That is very easy to SQL Inject
__________________
George
Twitter | Blog
Reply With Quote