in reply to Re^2: DBH Insert of Binary Data
in thread DBH Insert of Binary Data
1) SELECT x FROM FROM y WHERE $myquoted_value =z 2a) SELECT x FROM y WHERE ? = 1 2b) $value_to_insertWith #1, the RDBMS sees everything at once and has to separate out $myquoted_value, possibly being tricked about what to spearate if $myquoted_value contains SQL injection. With #2, the SQL statement and the value are passed sparately and the RDBMS does not need to separate them again. Placeholders are better for security and often better for performance.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: DBH Insert of Binary Data
by Joost (Canon) on Mar 18, 2005 at 22:28 UTC | |
by jZed (Prior) on Mar 18, 2005 at 22:55 UTC | |
by Joost (Canon) on Mar 19, 2005 at 01:36 UTC | |
by jZed (Prior) on Mar 19, 2005 at 01:39 UTC | |
by Joost (Canon) on Mar 19, 2005 at 01:44 UTC | |
|