in reply to CGI (in)security
Am I doing the right things?
Concerning SQL injection there was a discussion recently: Format to save and display.
I think (and hope to be proven right) that you don't need to mutilate the English words that are SQL keywords if you are careful about semicolons and quote characters.
Use DBI's quote() method/function to escape your data.
Cheers, Sören
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: CGI (in)security
by amw1 (Friar) on Jun 15, 2004 at 13:36 UTC |