How can prepared statements protect from SQL injection attacks?

前端 未结 9 2036
予麋鹿
予麋鹿 2020-11-21 05:40

How do prepared statements help us prevent SQL injection attacks?

Wikipedia says:

Prepared statements are resilient against SQL injection, because

9条回答
  •  慢半拍i
    慢半拍i (楼主)
    2020-11-21 05:59

    The key phrase is need not be correctly escaped. That means that you don't to worry about people trying to throw in dashes, apostrophes, quotes, etc...

    It is all handled for you.

提交回复
热议问题