in reply to Using-T and Untainting SQL
The risk you run by doing my $SQL = "SELECT * FROM table WHERE " . param('whereClause'); is that someone will pass in 0; drop table; And *poof*, you're out of business.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Using-T and Untainting SQL
by sdyates (Scribe) on Apr 29, 2002 at 17:09 UTC | |
by PotPieMan (Hermit) on Apr 29, 2002 at 18:55 UTC | |
by sdyates (Scribe) on Apr 30, 2002 at 20:02 UTC | |
by PotPieMan (Hermit) on Apr 30, 2002 at 23:48 UTC |