Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);
No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Chat Box in PHP
I was thinking in doing a Chat Box in PHP. For that I would use a form with two fields, Nick and Mes

PHP using IF to display error
i have a MySQL query and i want to display 1 thing only if the number of affected rows is >=1

help with image upload code
Hello,

right now this code I have resizes images and then places them into the uploads folder

Cron Job and Output
I have php codes running under a cron job.
But everytime i output (echo) , it comes out as comple

how to transport the Query and insfoset
Hi

I have created the query using SQ01........
How to created T-code for query..

how to make database item unique
Hey guys,

is it possible to do this:

I have the database item $title being pulled for

Batch Session SM35 stuck in status 'in Background
Hi Experts,

I am facing a problem with Batch Input session SM35.

The batch se

PHP Error
On my .php page I have a drop down box that has several names in it. When a user clicks the name &am

Does design fit in FPGA ?
Hi all,

I've made a large HCC-Design. Because of the program-size the compile process with th

Class not found error
I am getting Class 'index' not found in Eval function:

//write config

$pat

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash