in reply to untainting or encoding for shelled sqlplus update
Even if you don't manipulate the data you can use DBI's ->quote and ->quote_identifier methods to do the escaping.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: untainting or encoding for shelled sqlplus update
by runrig (Abbot) on May 15, 2008 at 19:07 UTC | |
by Herkum (Parson) on May 15, 2008 at 19:22 UTC | |
by runrig (Abbot) on May 15, 2008 at 19:42 UTC | |
by goibhniu (Hermit) on May 15, 2008 at 21:05 UTC | |
by runrig (Abbot) on May 15, 2008 at 21:28 UTC | |
by moritz (Cardinal) on May 15, 2008 at 19:18 UTC | |
by ikegami (Patriarch) on May 15, 2008 at 19:26 UTC |