3 ms·
I would have said that SQL injection is caused by emitting unescaped user input to your SQL server
by halomru 10y ago
I would have said that SQL injection is caused by emitting unescaped user input to your SQL server
- tlrobinson 10y agoIf I call eval(string) am I emitting unescaped user input to the eval function? I guess the definition of "injest" here is reading bytes off the wire?
- john_reel 10y agoIf string is unescaped user input, then yes, you are.