It is of course a very unsecure way of allowing users to delete records from your database. Anyone can just type the URL into the address-bar and change the value in the name=.... parameter and thus delete someone else's records.
CountZero
A program should be light and agile, its subroutines connected like a string of pearls. The spirit and intent of the program should be retained throughout. There should be neither too little or too much, neither needless loops nor useless variables, neither lack of structure nor overwhelming rigidity." - The Tao of Programming, 4.1 - Geoffrey James
In reply to Re: CGI and Database
by CountZero
in thread CGI and Database
by mccolgst
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |