{"id":346,"date":"2011-08-20T10:56:27","date_gmt":"2011-08-20T10:56:27","guid":{"rendered":"http:\/\/www.sitekickr.com\/blog\/?p=346"},"modified":"2011-08-20T10:58:21","modified_gmt":"2011-08-20T10:58:21","slug":"cfqueryparam-order-by-group-by","status":"publish","type":"post","link":"https:\/\/www.sitekickr.com\/blog\/cfqueryparam-order-by-group-by\/","title":{"rendered":"cfqueryparam in order by, group by, etc"},"content":{"rendered":"<p>I&#39;ve seen quite a few posts on this, many come to the same conclusion that using a (possibly length) switch statement is the best way to protect against your SQL query being injected with unwanted statements.<\/p>\n<p>If your primary goal is to prevent SQL Injection, then you might consider simply using the List Function to strip the first word from a user specified parameter.<\/p>\n<p>Example:<\/p>\n<p><code>SELECT field1, field2<br \/>\n\tFROM mytable<br \/>\n\tORDER BY #ListFirst(url.sort, &quot; &quot;)#<\/code><\/p>\n<p>I have not gone through all of the possibilities on this one, so if someone sees a way that the above statement might still allow SQL Injections, please comment.<\/p>\n<p>Of course, a malicious user would be able to inject a one word statement into the order by clause, but I have difficulty seeing what harm that can cause.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#39;ve seen quite a few posts on this, many come to the same conclusion that using a (possibly length) switch statement is the best way&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"amp_status":""},"categories":[34,13],"tags":[119],"_links":{"self":[{"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/posts\/346"}],"collection":[{"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/comments?post=346"}],"version-history":[{"count":1,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/posts\/346\/revisions"}],"predecessor-version":[{"id":347,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/posts\/346\/revisions\/347"}],"wp:attachment":[{"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/media?parent=346"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/categories?post=346"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/tags?post=346"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}