, cf newbs, . cfqueryparam!
:
<cfquery name="getSome" datasource="myDB">
select * from users
where userID = '#url.userID#'
</cfquery>
:
<cfquery name="getSome" datasource="myDB">
select * from users
where userID = <cfqueryparam value="#url.userID#" cfsqltype="CF_SQL_INTEGER">
</cfquery>
(cfqueryparam scanner), , - .
, , , , Hack My CF , . ( - , fyi)