Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);
No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

array & querys help/advice.
Ok so here goes , I have a mysql database and basically here's what I need to do.

// foreach

ctype() validation - allowing illegal characters
Hello,
I use ctype() to filter and validate a user form. However, I am trying to allow certain c

EU VAT Package 2010
Does any one know whether SAP will be developing new reporting functionality due the new VAT rules t

I have a parse error in this query help..
Code: $query1="INSERT INTO `rating` (`item_name`, `rating`, `ip_address`, `date_rated`) VALUES

extract a file from zip file
hi,
i know how to unzip a zip file in php, but is there a way to just extract a certain file only

How do I send data using an html link
Hi

If I have
<a href="main_file.php">

How do I send data t

order by date not ID number help php
I am trying to orginize the following code to order by date not id number.
any help would be grea

Sending CC Info by email
I am a little bit less knowledgable in the security area as most developers and I know I have a lot

Feed Maker
Hi all.
First of all I must say I am not a php developer so I am afraid I don't know much about i

selectbox+database connection retrive problem
Code: [Select]
<tr>
<th align="left" scope="c

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash