Since we're talking about filters, make sure you also use a filter for semicolons (at the minimum) on any input that is going directly into an SQL statement to prevent your entire database from being deleted.
See SQL Injection Attack.
Admin Edit.
This discussion was split off from the original thread, which can be found at Force .DefaultValue to be a string.
See SQL Injection Attack.
Admin Edit.
This discussion was split off from the original thread, which can be found at Force .DefaultValue to be a string.
Comment