Am I doing the right things?
Concerning SQL injection there was a discussion recently: Format to save and display.
I think (and hope to be proven right) that you don't need to mutilate the English words that are SQL keywords if you are careful about semicolons and quote characters.
Use DBI's quote() method/function to escape your data.
Cheers, Sören
In reply to Re: CGI (in)security
by Happy-the-monk
in thread CGI (in)security
by kiat
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |