in reply to Re: Preventing SQL injection attacks: are -T and placeholders not enough?
in thread Preventing SQL injection attacks: are -T and placeholders not enough?

Yes, it is unfortunate that FreeTDS doesn't support placeholders in their Client Library implementation - because they do support placeholders in their ODBC implementation.

The FreeTDS team is quite active, so I'm hoping that this support will eventually be added. Of course I'm sure they'd be more than happy if someone had the time and the energy to lend a hand and try to add this functionality...

Michael

  • Comment on Re^2: Preventing SQL injection attacks: are -T and placeholders not enough?