Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);

No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Problem Dereferencing
With these types and tables:

CREATE TYPE MANAGER AS OBJECT (
MGR_ID INTEGER,

db entry based on primary key
My "topics" table contains 10 entires
*--------------*
topicid topic
------

php require help needed
Ok i tried to use the search funtion but the word require is everywhere.

i'm really new to cr

Perplexing problem showing a .jpg
Please disregard..........I figured it out

help with mysql_error()
Hi,

I am trying to insert data into a table, but I am not able to insert it. I wanted to see

How to limit the calls to an API
Hello, in my simple script I call an api which effectively involves me getting an xml file.

H

mail with attachment problems
Hi. I have the following code:
Code: else if(file_exists("site".$timp.".zip")

Online Event Ticket Sales
Has anyone wrote a script for online tickets sales?

I have been googling and found lots of th

query help
Hi experts.

i have a table rep2 like this
PROD_COD ACCT_NO DUE_DAYS BALANCE

array empty
Hiya peeps,

Ok here is the codes.

order.php

Code:

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash