3 ms·
Yes. Even in places where people use prepared statement and things like LINQ to build queries, somewhere someone will end up wanting or needing a query that is
by bitexploder 9y ago
Yes. Even in places where people use prepared statement and things like LINQ to build queries, somewhere someone will end up wanting or needing a query that is hard to express so they will start string building a raw SQL query and forget or not know to use prepared statements. We see this /all/ the time on our assessment of our customer's software.
It is markedly less common, but still quite common, if not pervasive like it used to be. PHP apps are dramatically more likely to have security vulnerabilities of any sort. It is a running joke we have that one of our recommendations to remediate security issues with PHP is to "rewrite in a different language". For whatever reason PHP has a history of encouraging vulnerable code. Even in good shops. PHP itself isn't really to blame (it is, of course much less likely for an experienced shop to write crappy PHP... but they probably wouldn't pick PHP to begin with).
- duskwuff 9y agoWhat deserves a lot of the blame is the awful mysql_* API, which didn't support query placeholders. (The mysqli and PDO APIs weren't available until much later, and weren't reliably available on many web hosts for even longer.) This forced PHP developers to become comfortable with constructing SQL queries as strings -- a habit which proved hard to break for many of them.