in reply to Preventing MySQL Injection
When you ask the database driver to quote your stuff (via either mechanism) you never add your own quotes. It won't work, it's not needed and even if it was, it would only add a new point of failure.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Preventing MySQL Injection
by gamache (Friar) on Jan 03, 2008 at 15:42 UTC | |
by Joost (Canon) on Jan 03, 2008 at 19:57 UTC | |
by dsheroh (Monsignor) on Jan 03, 2008 at 20:33 UTC |