<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: CFTextMate - Which Version Do I Download?</title>
	<atom:link href="http://www.cftextmate.com/2008/12/17/cftextmate-which-version-do-i-download/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cftextmate.com/2008/12/17/cftextmate-which-version-do-i-download/</link>
	<description>ColdFusion meets Textmate, a developers dream come true</description>
	<pubDate>Wed, 08 Sep 2010 02:09:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: rob</title>
		<link>http://www.cftextmate.com/2008/12/17/cftextmate-which-version-do-i-download/#comment-25594</link>
		<dc:creator>rob</dc:creator>
		<pubDate>Tue, 27 Jan 2009 05:24:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.cftextmate.com/?p=22#comment-25594</guid>
		<description>Thanks Chris, that's actually bill though not me :-), and I think it was just for demo purposes not actually running anywhere.

However, you can never be too careful.  Thanks for pointing it out</description>
		<content:encoded><![CDATA[<p>Thanks Chris, that&#8217;s actually bill though not me :-), and I think it was just for demo purposes not actually running anywhere.</p>
<p>However, you can never be too careful.  Thanks for pointing it out</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.cftextmate.com/2008/12/17/cftextmate-which-version-do-i-download/#comment-25593</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 27 Jan 2009 04:59:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.cftextmate.com/?p=22#comment-25593</guid>
		<description>Hi Rob,

I tried to email but the contact link doesn't work.

Just wanted to let you know that you've got a SQL injection vulnerability in your demo:

http://cftextmate.com/coldfusion-textmate-screencast-1.html

"select email from newsletter where email = '#trim(form.email)#'"

If someone puts a string with ' in it for their email, it'll break your SQL and they can do nasty things.

You should be using  to get around this. It's also faster.</description>
		<content:encoded><![CDATA[<p>Hi Rob,</p>
<p>I tried to email but the contact link doesn&#8217;t work.</p>
<p>Just wanted to let you know that you&#8217;ve got a SQL injection vulnerability in your demo:</p>
<p><a href="http://cftextmate.com/coldfusion-textmate-screencast-1.html" rel="nofollow">http://cftextmate.com/coldfusion-textmate-screencast-1.html</a></p>
<p>&#8220;select email from newsletter where email = &#8216;#trim(form.email)#&#8217;&#8221;</p>
<p>If someone puts a string with &#8216; in it for their email, it&#8217;ll break your SQL and they can do nasty things.</p>
<p>You should be using  to get around this. It&#8217;s also faster.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
