Well an string would work but... that could be quite dangerous, it's quite easy to make injection attacks with that technique. I would limit that free querying to the final user. HTH Braulio
/// ------------------------- Braulio Díez DBSchemaEditor.com Free Silverlight based DB Schema Modeling Tool /// -------------------------