Can I protect against SQL injection by escaping single-quote and surrounding user input with single-quotes?

后端 未结 18 2272
忘了有多久
忘了有多久 2020-11-22 14:03

I realize that parameterized SQL queries is the optimal way to sanitize user input when building queries that contain user input, but I\'m wondering what is wrong with takin

18条回答
  •  情歌与酒
    2020-11-22 14:44

    Patrick, are you adding single quotes around ALL input, even numeric input? If you have numeric input, but are not putting the single quotes around it, then you have an exposure.

提交回复
热议问题