can i include query in URL?

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • D R E

    can i include query in URL?

    I have a list of names, and upon clicking the list, want each list item to
    go to a different url. Is it safe to put the urls's like this?

    <A HREF="resultsPg ?rownumber=1">S elect row 1</A>
    <A HREF="resultsPg ?rownumber=2">S elect row 2</A>
    <A HREF="resultsPg ?rownumber=3">S elect row 3</A>

    resultsPg is a servlet. I want to return a page based on the row selected
    from the list (rownumber).

    Thanks.


  • Tony Morris

    #2
    Re: can i include query in URL?

    You are compromising the security of the entire application.
    Look up "SQL Injection".

    --
    Tony Morris



    Comment

    • D R E

      #3
      Re: can i include query in URL?

      so how would i go about doing it? You know how in some websites, when you
      click the column heading it re-sorts by that column that you clicked....


      "Tony Morris" <dibblego@optus net.com.au> wrote in message
      news:ccvofg$jai $1@news.btv.ibm .com...[color=blue]
      > You are compromising the security of the entire application.
      > Look up "SQL Injection".
      >
      > --
      > Tony Morris
      > http://www.xdweb.net/~dibblego/
      >
      >[/color]


      Comment

      • Virgil Green

        #4
        Re: can i include query in URL?

        "Tony Morris" <dibblego@optus net.com.au> wrote in message
        news:ccvofg$jai $1@news.btv.ibm .com...[color=blue]
        > You are compromising the security of the entire application.
        > Look up "SQL Injection".[/color]

        Based upon the OPs post, how so?

        - Virgil


        Comment

        Working...