3 ms·
I've tried to write a program (https://gist.github.com/392445 https://gist.github.com/392445) which would be affected by this. It seems it should be `'); DROP T
by banthar 15y ago
I've tried to write a program (https://gist.github.com/392445 https://gist.github.com/392445) which would be affected by this. It seems it should be `'); DROP TABLE servertypes; --` to actually drop any tables. All I was able to get now is syntax error.
- dangrossman 15y agoThis is a valid syntax for MySQL: INSERT INTO servertypes SET server = 'Apache'
- mkopinsky 15y agoI recently learned about the INSERT SET syntax, and have started to use it across the board. Sooooo much more readable when column names and values are next to each other rather than separated. </offtopic>
- dave1010uk 15y agoI had the same idea: https://gist.github.com/913402 https://gist.github.com/913402
- dangrossman 15y agoThat's not a valid syntax for INSERT in MySQL. When you use the VALUE or VALUES keyword, it must be followed by a set of parentheses.