Check out qForms:

http://www.pengoworks.com/qForms/

I got this from another post on this list. It might help.  

-----Original Message-----
From: joachim [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, January 02, 2002 11:24 AM
To: CF-Talk
Subject: Validating forms (security)


Hi,

I'm tuning a forum (as in security checks) but i'm quite confused about 
how
one would handle form input.

I know that one should always validate data before doing any operations 
with
it,
eg validating numbers (see also url hack).

But how does one handle "plain text"  ?
For the "<", ">" characters would it be correct,
If I state that replacing them with there html equivalent (&lt; ) would 
be
enough ?

I've been searching the cf-talk archive and spitted out some forums 
(devex)
(where btw I didn't even found number validation *cough* ) but to no
success.

I've never seen/found a way to pass in additional sql statements(or 
anything
other for that matter) by filling out a form (aka plain text).

And there's also the fact that for  "SQL forum" it would be obvious 
that one
would enter "drop table, create table,...."
So what do you do then ?

If anybody has any insights on this please enlighten me.

BTW, I'm already using cfqueryparam in all my sql statements.


Thanks alot,
Joachim


______________________________________________________________________
Why Share?
  Dedicated Win 2000 Server · PIII 800 / 256 MB RAM / 40 GB HD / 20 GB MO/XFER
  Instant Activation · $99/Month · Free Setup
  http://www.pennyhost.com/redirect.cfm?adcode=coldfusionc
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

Reply via email to