Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);
No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Disable html within defined tags
I have a mysql database that allows users to enter content with html, but I also want to have a tag

How to limit the calls to an API
Hello, in my simple script I call an api which effectively involves me getting an xml file.

H

Displaying pictures
i have worked my way through storing images in directory and storing the location in mySQL db.Now i

Redirect not working after making a POST/GET
Hi Everyone,

I am a novice in PHP. Here I have 2 pages, one page with a textbox and button an

Significance of BPM
Hi Experts,
I am a novice in BPM , I just want to know how BPM as permenant department is

php wont update my db
hello,

sorry for posting in mysql forum but i dont know where exactly is the problem but here

Mail form doesn't send Russian/Cyrillic characters correctly?
When someone enters foreign characters (like Cyrillic text, and Japanese/Chinese probably gives the

a function to check directory depth
I'm working on a php script to upload files in to a set directory.
the user can select to upload

Encrypt php code?
Is it possible to encrypt php code in files,
so that it displays a load of unreadable characters

Secure FTP
Hi experts,
There is no SFTP action in MII workbench.
This means it needs developing custo

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash