Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);

No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Problem with passing variables
I'm not really a php programmer so I'm really struggling with this issue.

I have a banner s

PHP using IF to display error
i have a MySQL query and i want to display 1 thing only if the number of affected rows is >=1

need help in dynamic select menu in php
hi i have created a dynamic select menu using php. i have a problem in that which is when the user s

displaying email without attracting a ton of spam
Hello,

this is maybe the wrong place to ask.
How would you display an email address on a w

Search function
I am looking for some guidance from the experts.

I am trying to create a search function. It

Remove letter from numeric textbox
I have a textbox that will search the employee database by entering in the employee ID and it will r

if statements problems
Hi. I'm trying to make a web form, but I kind of hit a dead end trying to figure out why it doesn't

send message to the java application
Oracle 10g with Windows platform.

I have a java application that periodically pings the d

help with multi-update
Now sure how to ask this really....
10g database if that matters.

I have a customer

Convert Binary String to Decimal
Trying to Get:
Decimal: 305419896

Out of:
Binary String: xV4

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash