<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ColdFusion SQL Injection</title>
	<atom:link href="http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/</link>
	<description>Web Application Engineers</description>
	<lastBuildDate>Mon, 05 Dec 2011 17:24:52 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Patrick Quinn</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-43058</link>
		<dc:creator>Patrick Quinn</dc:creator>
		<pubDate>Fri, 24 Jun 2011 13:35:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-43058</guid>
		<description>Thanks a ton, Mike!</description>
		<content:encoded><![CDATA[<p>Thanks a ton, Mike!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Henke</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-43025</link>
		<dc:creator>Mike Henke</dc:creator>
		<pubDate>Fri, 24 Jun 2011 01:39:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-43025</guid>
		<description>Here is the github repository if anyone has any updates/fixes/enhancements https://github.com/mhenke/WebApper-ColdFusion-SQL-Injection</description>
		<content:encoded><![CDATA[<p>Here is the github repository if anyone has any updates/fixes/enhancements <a href="https://github.com/mhenke/WebApper-ColdFusion-SQL-Injection" rel="nofollow">https://github.com/mhenke/WebApper-ColdFusion-SQL-Injection</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Quinn</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-42951</link>
		<dc:creator>Patrick Quinn</dc:creator>
		<pubDate>Wed, 22 Jun 2011 19:59:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-42951</guid>
		<description>That&#039;d be great, Mike. Thanks for the effort. Keep us posted.</description>
		<content:encoded><![CDATA[<p>That&#8217;d be great, Mike. Thanks for the effort. Keep us posted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Henke</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-42949</link>
		<dc:creator>Mike Henke</dc:creator>
		<pubDate>Wed, 22 Jun 2011 18:41:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-42949</guid>
		<description>Patrick - I can throw up something like https://github.com/mhenke/CFML-in-100-minutes with a readme crediting and linking your this post. The repo would have the script for people to grab, tweak, and contribute back. Then if you guys create a github account eventually, I&#039;ll fork from yours.</description>
		<content:encoded><![CDATA[<p>Patrick &#8211; I can throw up something like <a href="https://github.com/mhenke/CFML-in-100-minutes" rel="nofollow">https://github.com/mhenke/CFML-in-100-minutes</a> with a readme crediting and linking your this post. The repo would have the script for people to grab, tweak, and contribute back. Then if you guys create a github account eventually, I&#8217;ll fork from yours.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Quinn</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-42946</link>
		<dc:creator>Patrick Quinn</dc:creator>
		<pubDate>Wed, 22 Jun 2011 17:51:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-42946</guid>
		<description>Hey Mike. That&#039;s a good thought, but, in all honesty I&#039;m not sure we&#039;d have time to give proper attention to an open source project right now. It&#039;s great to be &lt;em&gt;this&lt;/em&gt; busy!</description>
		<content:encoded><![CDATA[<p>Hey Mike. That&#8217;s a good thought, but, in all honesty I&#8217;m not sure we&#8217;d have time to give proper attention to an open source project right now. It&#8217;s great to be <em>this</em> busy!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Henke</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-42906</link>
		<dc:creator>Mike Henke</dc:creator>
		<pubDate>Wed, 22 Jun 2011 02:14:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-42906</guid>
		<description>Have you thought of placing this on github for people to help with?</description>
		<content:encoded><![CDATA[<p>Have you thought of placing this on github for people to help with?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Quinn</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-26895</link>
		<dc:creator>Patrick Quinn</dc:creator>
		<pubDate>Sun, 24 Oct 2010 17:55:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-26895</guid>
		<description>Sure thing, Peter!</description>
		<content:encoded><![CDATA[<p>Sure thing, Peter!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: buy kinect</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-26868</link>
		<dc:creator>buy kinect</dc:creator>
		<pubDate>Sun, 24 Oct 2010 09:50:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-26868</guid>
		<description>Hello,
	
	I have a inquiry for the webmaster/admin here at www.webapper.com.

May I use part of the information from this blog post above if I give a backlink back to this site?

Thanks,
Peter</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>	I have a inquiry for the webmaster/admin here at <a href="http://www.webapper.com" rel="nofollow">http://www.webapper.com</a>.</p>
<p>May I use part of the information from this blog post above if I give a backlink back to this site?</p>
<p>Thanks,<br />
Peter</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clement Huge</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-22838</link>
		<dc:creator>Clement Huge</dc:creator>
		<pubDate>Mon, 28 Jun 2010 18:41:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-22838</guid>
		<description>As a DBA, I still believe you should lean your SQL code towards the use of stored procedures. This way, you will be able to separate your application tier from your database tier.
Also, Sql server will reuse compiled plans and will also check for the data type integrity of the parameters.
Finally it will remove the dynamic sql that makes the sql injection you fear about.</description>
		<content:encoded><![CDATA[<p>As a DBA, I still believe you should lean your SQL code towards the use of stored procedures. This way, you will be able to separate your application tier from your database tier.<br />
Also, Sql server will reuse compiled plans and will also check for the data type integrity of the parameters.<br />
Finally it will remove the dynamic sql that makes the sql injection you fear about.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shannon Hicks</title>
		<link>http://www.webapper.com/blog/index.php/2008/07/22/coldfusion-sql-injection/comment-page-1/#comment-6860</link>
		<dc:creator>Shannon Hicks</dc:creator>
		<pubDate>Tue, 21 Jul 2009 20:38:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.webapper.net/blog/index.cfm/2008/6/30/ColdFusion-SQL-Injection#comment-6860</guid>
		<description>I just checked, and it seems to work. Just remove the .html to make it into a cfm file.</description>
		<content:encoded><![CDATA[<p>I just checked, and it seems to work. Just remove the .html to make it into a cfm file.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

