• This is very dangerous as it allows SQL Injection, and as parameters can be passed by URL this is very very risky.

    Using a split function is the safer option.


    Simon Sabin
    SQL Server MVP

    http://sqlblogcasts.com/blogs/simons