Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);
No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Function to extract email attachments using PHP IMAP
function extract_attachments($connection, $message_number) {

$attachments = array();

Two warning messages
Quote<b>Warning</b>: mysql_real_escape_string() expects parameter 1 to

Members Only
Hi all, for my website i have a members area only which on members can veiw, but at the moment anyon

MYSQL gen help
This is my Mysql gen. can anyone tell me why this echos

MID(networkset.networkid, 3, 3) AS &q

Adding delete feature to my forum
Hello I am currently trying to add a delete feature to my forum. I believe I have everything built r

How to calculate days from variable date?
This will be easy for one of you gurus. I want to fetch the date from a variable date, for example:<

please help me in this update statment
hi every one

if I have table and this data in it

id name
10

session checking in page load
hai all I have a web site is www.Mryas.com in this my login page is Page1.aspx its co

sql error
I have been looking at this code for 20mins and can't work out what I am doing wrong. There is somet

add text and number image
hi guys ..

ok see i want the user to add their name and pick a number then click get it and i

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash