Can I protect against SQL injection by escaping single-quote and surrounding user input with single-quotes?

后端 未结 18 2270
忘了有多久
忘了有多久 2020-11-22 14:03

I realize that parameterized SQL queries is the optimal way to sanitize user input when building queries that contain user input, but I\'m wondering what is wrong with takin

18条回答
  •  北海茫月
    2020-11-22 14:51

    If you have parameterised queries available you should be using them at all times. All it takes is for one query to slip through the net and your DB is at risk.

提交回复
热议问题