in reply to Re^11: CGI Action call
in thread CGI Action call
You say: Interpolating user-supplied data into SQL statements is a problematic thing and best avoided.
How do you avoid having a user (administrator only in this case) enter a user supplied search term like a last name?
Perhaps I don't understand your statement.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^13: CGI Action call
by poj (Abbot) on Mar 20, 2018 at 11:41 UTC | |
|
Re^13: CGI Action call
by davies (Monsignor) on Mar 20, 2018 at 12:59 UTC |