4 ms·
This article does not provide a good pattern for protecting against SQL injections. You can protect against all possible input vectors by using placeholders. Co
by btbuilder 15y ago
This article does not provide a good pattern for protecting against SQL injections. You can protect against all possible input vectors by using placeholders. Constructing SQL queries with string formatting or concatenation should be avoided. When executing bulk queries it is also more efficient.
$stmt = $dbh->prepare("SELECT user,password FROM admins WHERE user=? AND password=? AND ip_adr=?");
$stmt->execute($_POST['user'], md5($_POST['password']), ip_adr())
The above approach does not require that you think about what data you are accepting, and if done through-out your code, others who may not be so pre-disposed to think about escaping will not make mistakes if they copy you.