4 ms·
My guess would be that this was a mis-quote, probably meant to be "there's no way to 100% prevent SQL injection via sanitization". Possibly followed by advice
by danielbarla 7y ago
My guess would be that this was a mis-quote, probably meant to be "there's no way to 100% prevent SQL injection via sanitization". Possibly followed by advice to use parametrized queries. Alternatively, the lecturer could have just been wrong.
If someone does have a counter example for parametrized queries, I'd be curious.
- DeathArrow 7y agoThat's right, that's what I wanted to say.