What if we had a situation that effectively did something like the following (by entering appropriate value in a textbox in an entry screen)?
THISFORM.xVariable = "';drop table table1;"
I'm not sure if VFP interprets the query directly or if it simply passes it to the SQL backend. If it passes the query the backend you could be in for a nasty suprise.
Previous
Reply
View the map of this thread
View the map of this thread starting from this message only
View all messages of this thread
View all messages of this thread starting from this message only