– Common Function Library Project


Last updated July 1, 2002

Version: 1 | Requires: ColdFusion 5 | Library: DatabaseLib

Rated 14 time(s). Average Rating: 2.1

This security-related function is intended to test for strings that users intentionally or otherwise may pass in form fields that may cause SQL injection to occur. SQL injection is an event in which a malicious or unknowing user inserts arbitrary SQL statements into queries without the knowledge of the programmer. This UDF mainly relates to those using SQLServer, I am not sure if the test I use protects against the same vulnerabilities on other database platforms.

Return Values:
Returns a boolean.


view plain print about
<cfset sqlString1 = "Chicken soup with rice">
<cfset sqlString2 = "Chicken soup with' drop table soups--">

sqlString1 = #sqlString1# IsSQLInject? #IsSQLInject(sqlString1)#<br>
sqlString2 = #sqlString2# IsSQLInject? #IsSQLInject(sqlString2)#<br>


Name Description Required
input String to check. Yes

Full UDF Source:

view plain print about
 * Tests a string, one-dimensional array, or simple struct for possible SQL injection.
 * @param input      String to check. (Required)
 * @return Returns a boolean. 
 * @author Will Vautrain ( 
 * @version 1, July 1, 2002 

function IsSQLInject(input) {
    * The SQL-injection strings were used at the suggestion of Chris Anley []
    * in his paper "Advanced SQL Injection In SQL Server Applications" available for downloat at

    var listSQLInject = "select,insert,update,delete,drop,--,'";
    var arraySQLInject = ListToArray(listSQLInject);
    var i = 1;
    for(i=1; i lte arrayLen(arraySQLInject); i=i+1) {
        if(findNoCase(arraySQLInject[i], input)) return true;
    return false;
blog comments powered by Disqus


Latest Additions

CF Ninja CF Ninja added
8 day(s) ago

Stephen Withington Stephen Withington added
8 day(s) ago

Adam Cameron Adam Cameron added
a while ago

Ray Ford Ray Ford added
a while ago

Top Rated

Darwan Leonardo Sitepu backupDatabase
Rated 5.0, 48 time(s)

Barney Boisvert indentXml
Rated 5.0, 12 time(s)

Rachel Lehman deAccent
Rated 5.0, 9 time(s)

Darwan Leonardo Sitepu splitNumber
Rated 5.0, 8 time(s)

Created by Raymond Camden / Design by Justin Johnson