Does this code prevent SQL injection?

后端 未结 7 1195
無奈伤痛
無奈伤痛 2020-11-29 08:40

Background

I\'ve been contracted to analyze an existing Data Provider and I know the following code is faulty; but in order to point out how bad it is, I need to pr

相关标签:
7条回答
  • 2020-11-29 09:24

    I think it is unhackable if you just replace ' with ''. I have heard that it is possible to change the escape quote character, which could potentially break this, however I am not sure. I think you are safe though.

    0 讨论(0)
提交回复
热议问题