    I have some ASP where I build up a query something like this...<BR><BR>"SELECT * FROM someTable WHERE someField=&#039;" & Request("field") & "&#039;"<BR><BR>problem comes if someone enters a char like &#039; in field. Is there anything I can do to clean up incoming request params... or what is the complete list of things I shouldnt allow?<BR><BR>thanks

    J. Paul Schmidt Guest

    Here is a relevant link:<BR><BR>How to Deal with Apostrophes in your SQL String - 5/18/1999<BR><BR>Just uses a Replace function.<BR><BR>Best regards,<BR>-Paul<BR><BR>J. Paul Schmidt, MBA<BR>Databases on the Web<BR><BR><BR>

