Hello I recently wrote my own search facility (classic ASP) for a property website. Unfortunately, it failed a SQL injection test, so I have had to look for alternatives. I purchased your Advanced Search extension and got my form set up and working just great, but I just wanted to know if it is safe from future SQL Injections? ie, does it use parameterized queries - in particular in the 'IN' operator?
Also, is there a way I can implement a 'sort by' option in the search form?
Many thanks, and great work by the way!
Robert |
|
|