UniWebDude wrote:
> I have tried to submit this in a non-forum fashion, but
being as this attack is
> well published on the internet I thought here is fine.
>
> We are running linux and CF7 into a MSSQL 2000 backend
and we have been on the
> recieving end of several SQL injection attacks. We have
taken action to
> prevent this specific attack but I wondered if there
is/will be a patch to
> remove this vulnerablility from CF7 ?
>
>
http://www.houseoffusion.com/groups/cf-talk/thread.cfm/threadid:57065
>
> Cheers,
> Matt.
>
Other then the proper usage of the existing
<cfqueryparam...> tag. I do
not and would not expect a patch to come along.