4 ms·
if they escape variables: danger! Escaping is not sufficient to prevent SQL Injection Attacks. You must used Parameterized Queries. http://bobby-tables.com/ h
by jacksoncarter 16y ago
if they escape variables: danger!
Escaping is not sufficient to prevent SQL Injection Attacks. You must used Parameterized Queries.
http://bobby-tables.com/ http://bobby-tables.com/
- chime 16y ago> Escaping is not sufficient to prevent SQL Injection Attacks. Do you have an example or idea of how a SQL injection could occur despite using http://php.net/manual/en/function.mysql-real-escape-string.php http://php.net/manual/en/function.mysql-real-escape-string.p... ?
- deleted 16y ago[deleted]
- deleted 16y ago[deleted]
- code_duck 16y agoI'm pretty sure the audience on HN understands sql injection without having to refer to a cartoon.