Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);
No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

retrieving images from mysql database using php
So I've been trying to figure out how to store images in a mysql database, and as far as i can tell

Automatic Webpage ??
I have a page www.mysite.com/test.php with a
<form>
<textarea name=&q

Help with some dates
I have a list of dates in an array:

$mondays = array(
strtotime("October 12, 2009

How could I do this?
Ive got a simple lottery game, and am using an sql database to keep track of the numbers bought. But

Creation of Raw Exposure manually
SAP Gurus

I am creating Raw Exposure ( Hedge management ) thru T Code TEM10 with followin

default SAP userid
hi,, I just like to know if it is ok to use the default SAP user id (SAP*)?

Default TimeZone
The server I'm working with is hosted in America so all times inserted into the database are coming

Email logic not working
I would like to send an email using the php email() function then if it does execute i.e sends i wou

=> and <=
So I was digging through some code when I came across the <= operator. This is the first tim

Strip Slashes Help
I've got a script that i've downloaded of the net to edit multiple fields from my sql database, and

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash