Linked by Thom Holwerda on Mon 28th Apr 2008 19:22 UTC, submitted by Hakime
Permalink for comment 311789
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.





Member since:
2006-02-05
whats sad is that you don't even have to. Use parameterized queries or stored procs and the framework will do the checking for you.
There is simply no excuse in the asp world for "SELECT " + fields + " FROM Tables" anymore.