4 ms·
> He even shows up sometimes with a builder Something I’ve ran into a lot over the years is people not realising that (at least in MySQL) prepared statement pl
by deergomoo 2y ago
> He even shows up sometimes with a builder
Something I’ve ran into a lot over the years is people not realising that (at least in MySQL) prepared statement placeholders can only be used for values, not identifiers like column names.
Because many query builders abstract away the creation of a prepared statement, people pass variables directly into column fields and introduce injection vulns.
Number one place I see this is data tables: you have some fancy table component where the user can control which columns to see and which to sort by. If you’re not checking these against a known good allow list, you’re gonna have a bad time.
- RadiozRadioz 2y agoYes, it varies by database whether placeholders can be used for table names. Personally I find table names sufficiently non-dynamic that an enum of accepted values & string concatenation works. Whenever I've wanted to template user input into table names, I've realised that I should probably refactor my schema or add some views.