Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);
No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Help with lottery style system?
I'm working on a currency system for forums and it is going to have a type of lottery system built i

Echo-ing MySQL content and Keep Formatting?
I have data in my MySQL such as:

QuoteBlah blah

Blah blah

etc
but when i ech

How to form a xml form table with a single sql statement..?
Hi everyone,
I don't know if this is going to be a duplicate thread but i couldn't

mod_rewrite.c on windows ??
why it's not working on windows while it's working on other hosts???

this is the code i got

blank page.... nothing is happening.
I'm new to a lot of this but in the last 24hrs have learned a lot.
Installed latest version of my

Storing user data help?
Hey Guys,

I'm not use if this question is to broad but I can always give you more informatio

mr8m - reverse document
Friends,

I'm trying to reverse a document held by MIRO, but it reports the message balan

PHP Blog help
Need help with posting comments in a word press blog? I have a comments page where the comments are

INSERT data problem!
After having an string with apostrophes ', double quotes " or any other special characters, suc

php code generators
All

Whilst enjoying learning a new language i have come accross a number of free code generat

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash