It’s been recommended but perhaps not forcefully enough. SQL work without placeholders is tragically, criminally insecure. I know just getting things working is sometimes a necessary first step but placeholders are not something to file under, Hmmm, interesting, but, Say, I could destroy my company with one line of this code.
See also: Exploits of a mom and bobby-tables.com.
In reply to Re^3: Writing NULL values to a MySQL record via DBI
by Your Mother
in thread Writing NULL values to a MySQL record via DBI
by ureco
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |