4 ms·
I work on the security engineering team at Dropbox, and help manage our open source programmes. Note that we aren't doing ``.format()`` or ``%``, but passing t
by lwf 10y ago
I work on the security engineering team at Dropbox, and help manage our open source programmes.
Note that we aren't doing ``.format()`` or ``%``, but passing the fill text as the second parameter to ``.execute()`` — this is the correct way to protect against SQLi using MySQLdb.
I actually mistakenly thought this was SQLi when I was reviewing this code for release. Unfortunately, the MySQLdb documentation doesn't make that obvious.
See http://stackoverflow.com/a/7929438 http://stackoverflow.com/a/7929438