Ok, I'll admit it, you're right there.<BR><BR>But that's also a pretty extreme example, requiring the injector to know that you're passing that parameter, as a string, and using OpenQuery with ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results