Oh and in both cases, since this is user-supplied form data you must use 
cfqueryparam to protect the database.

Like this:

SELECT stuff FROM somewhere
WHERE id IN (<cfqueryparam list="true" value="#Form.ListOfIds#" 
cfsqltype="cf_sql_integer"/>)

And again the same for doing NOT. 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Want to reach the ColdFusion community with something they want? Let them know 
on the House of Fusion mailing lists
Archive: 
http://www.houseoffusion.com/groups/cf-talk/message.cfm/messageid:328775
Subscription: http://www.houseoffusion.com/groups/cf-talk/subscribe.cfm
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.4

Reply via email to