Please start any new threads on our new
site at https://forums.sqlteam.com. We've got lots of great SQL Server
experts to answer whatever question you can come up with.
| Author |
Topic |
|
Sven2006
Starting Member
2 Posts |
Posted - 2006-07-11 : 06:30:57
|
| Hi,I am trying to pass the folloiwng to a stored procedure so that it can be executed using EXECselect candidateid from rc_cvdata where contains(*,'"Trainee Accounts*" and "Financial*"')This errors all over the place, I think it is down to the single and double quotes. Can anybody give me any ideas on this one please?Regards |
|
|
nr
SQLTeam MVY
12543 Posts |
Posted - 2006-07-11 : 06:54:37
|
| select candidateid from rc_cvdata where contains(*,'"Trainee Accounts*" and "Financial*"')trycreate proc x@s varchar(1000)asexec (@s)goexec x 'select candidateid from rc_cvdata where contains(*,''"Trainee Accounts*" and "Financial*"'')'Do you control what is sent to the sp? Means a caller can execute anything on your server.==========================================Cursors are useful if you don't know sql.DTS can be used in a similar way.Beer is not cold and it isn't fizzy. |
 |
|
|
|
|
|