Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);

No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Month String to Numeric?
Hi guys,

Given a month as a string, is there a simple way to find the numeric representation

fopen() security
As i understood the usage of fopen() for it to function correctly the Dir you write to has to be rw

Preg_match unknown modifyer
Hello,

Im trying to write a little script for my forums i need to get the reply from my forum

rand() function
just a general question guys a girls, is the rand() function 100% random or is it based on time?

Rand() help needed
Hi all,

Can someone explain and give me a quick example of how I would go about this?

Show message after entering data
Hello Colleagues

I would like to display messages after entering the data example: "
dat

VAT
how should I deal with VAT?

if I have a product that costs £5.00 and VAT @ 17.5% (£0.87

C++ API to Oracle dB
I need to perform a select command to the Oracle dB to obtain information from a table.
What libr

Multiple includes losing variables
Hey all,

just starting out w php and ran into a problem pretty quickly. I'm
including seve

please, need help coding this voting for your favorite car polling system.
hi, my code needs a lot of work, but i want to be able to let users vote on their favorite car, upda

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash