cfqueryparam
351
cfqueryparam
Description
Verifies the data type of a query parameter and, for DBMSs that support bind variables, enables
ColdFusion to use bind variables in the SQL statement. Bind variable usage enhances
performance when executing a
cfquery
statement multiple times.
This tag is nested within a
cfquery
tag, embedded in a query SQL statement. If you specify
optional parameters, this tag performs data validation.
Macromedia recommends that you use the
cfqueryparam
tag within every
cfquery
tag, to help
secure your databases from unauthorized users. For more information, see Security Bulletin
ASB99-04, “
Multiple SQL Statements in Dynamic Queries
,” at
www.macromedia.com/devnet/security/security_zone/asb99-04.html
, and Chapter 20,
“Accessing and Retrieving Data” in
ColdFusion MX Developer’s Guide
.
Category
Database manipulation tags
Syntax
<cfquery
name = "query_name"
dataSource = "ds_name"
...other attributes...
SQL STATEMENT column_name =
<cfqueryparam value = "parameter value"
CFSQLType = "parameter type"
maxLength = "maximum parameter length"
scale = "number of decimal places"
null = "yes" or "no"
list = "yes" or "no"
separator = "separator character">
AND/OR ...additional criteria of the WHERE clause...
</cfquery>
See also
cfinsert
,
cfprocparam
,
cfprocresult
,
cfquery
,
cfstoredproc
,
cftransaction
,
cfupdate
;
“Enhancing security with cfqueryparam” in Chapter 20, “Accessing and Retrieving Data,” in
ColdFusion MX Developer’s Guide
Summary of Contents for COLFUSION MX 7 - INSTALLING AND USING COLDFUSION MX
Page 1: ...COLDFUSION MX7 CFML Reference...
Page 20: ...20 Chapter 1 Reserved Words and Variables...
Page 50: ...50 Chapter 2 ColdFusion Tags cfelse br Searching cfif cfloop cfif...
Page 101: ...cfdefaultcase 101 cfdefaultcase cfswitch cfoutput Your grade is grade cfoutput...
Page 115: ...cfdocumentsection 115 cfdocumentsection cfoutput cfdocument...
Page 411: ...cftable 411 cftable body html...
Page 515: ...Chr 515 maxlength 5 p input type Submit name input type RESET cfform...
Page 605: ...GetEncoding 605 WriteOutput The encoding is theEncoding cfscript cfif...
Page 629: ...GetProfileString 629 tr td input type Submit name Submit value Submit td td td tr table form...
Page 655: ...IIf 655 cfoutput IIf Hour Now GTE 12 DE It is afternoon or evening DE It is morning cfoutput b...
Page 664: ...664 Chapter 3 ColdFusion Functions cfelse h3 Conversion error h3 cfif...
Page 687: ...IsStruct 687 cfoutput cfquery cfif cfoutput hr Employee Add Complete cfoutput cfcase cfswitch...
Page 751: ...LSDateFormat 751 hr noshade cfoutput cfloop...
Page 861: ...StructFind 861 cfquery cfif cfoutput hr Employee Add Complete cfoutput cfcase cfswitch...
Page 903: ...Val 903 value Is the beginning numeric name form...
Page 932: ...932 Chapter 3 ColdFusion Functions...
Page 944: ...944 Chapter 4 ColdFusion MX Flash Form Style Reference...
Page 962: ...962 Chapter 5 Application CFC Reference...
Page 1054: ...1054 Chapter 6 ColdFusion MX Event Gateway Reference...