in reply to SQL Injection myths under DBI?

Even if an attacker can't drop your database or corrupt your data, I'd rather they not be able to do a resource sucking cartesian join on tables in my database (mysql doesn't allow subqueries, so you may be safe from that).

Update: I, um, meant old versions of MySQL...yeah, that's it :-) (Ok, so I need to update my own mental database :)

Replies are listed 'Best First'.
Re^2: SQL Injection myths under DBI
by dragonchild (Archbishop) on Apr 12, 2005 at 12:44 UTC