quote and quote_identifier are both database handle methods.
They have to be, because escaping is handled differently in the various DBs out there. But it's the only safe method that I know of, which is why I recommend it, and recommend refactoring as much as possible at the same time.
If you know another secure methods feel free to offer it.
In reply to Re^3: untainting or encoding for shelled sqlplus update
by moritz
in thread untainting or encoding for shelled sqlplus update
by goibhniu
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |