Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);
No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Storing user data help?
Hey Guys,

I'm not use if this question is to broad but I can always give you more informatio

user administration
Dear @all,

what I have to do to set the user defaults for new users. At the moment I woul

How would I protect......
I have a from, actually, a good amount of forms. How can I make it so you can't type the characters:

button help
i originally had this but realised it is much easier to have a button.

Code: <?php

Socket problem
Hello,

Earlier I posted about my problem with my socket script. It took up to 100% CPU usage.

Just a white page
Okay so, my website, when I click SignUp on it it takes me to /join.php but its a complete white pag

problem when runing a funciton
I am trying to connect to database using a funciton in a functions.php

<?php
funct

Multiple upload and Resize
I would like some help on my script I have the for my index.php

////

<html&

Rounding a number queried from a database
I know that to display a rounded number you just do echo "round($number)";. But how would

why does my session end?
my connect.php starts the session just so you know
i can navigate arround my site fine except whe

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash