You say: Interpolating user-supplied data into SQL statements is a problematic thing and best avoided.
How do you avoid having a user (administrator only in this case) enter a user supplied search term like a last name?
Perhaps I don't understand your statement.
In reply to Re^12: CGI Action call
by tultalk
in thread CGI Action call
by tultalk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |