Preventing SQL Injection


Posted on 16th Feb 2014 07:03 pm by admin

I have a question about SQL Injection, In some of our code we use this: view plaincopy to clipboardprint?Replace(inString, "'", "''") Replace(inString, "'", "''") does this prevent all forms of SQL Injection? Also what exactly does parameterized statements do?view plaincopy to clipboardprint?myCommand.Parameters.AddWithValue("@username", user); myCommand.Parameters.AddWithValue("@password", pass);

No comments posted yet

Your Answer:

Login to answer
202 Like 50 Dislike
Previous forums Next forums
Other forums

Update not working ... please help
Hi,

I am trying to update a row using an edit form by passing id of the row .. but it is not

SCO Unix
I know this might not be the place to ask, but, can anyone tell me if SCO Unix comes with PHP built

need help about
i store the value of my select statement result to an array and stored it to a variable named $fname

Where am I going wrong
Been trying to work this out for hours

I have two tables called 'Genres' and 'Films'. Genre

image upload, resize THEN submit form
Ok so I have a form that requires the user to upload an image, and then do something with that image

PHP and SMS
Hi all forum members. I am new here and am unsure what category shoild I post this in.
Moderator

timed header image rotation
I have a joomla site and I was trying to setup a rotating image based on timing NOT just refreshing

exclude characters from counting?
Hello, I wanted to ask if you have a string like:
Code: $my_s='ASRGREGTGTR----REGREGRE+++RRRRRR..

mr8m - reverse document
Friends,

I'm trying to reverse a document held by MIRO, but it reports the message balan

. and .. appearing instead of pictures
First of all, thanks very much for providing this forum. It is very much appreciated!

My son

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash