in reply to Secure Regular Expression Check
A better protection is the usage of placeholders, as demonstrated in the DBI documentation:
my $query = $dbh->prepare(= "select name, pass from unpw where name = +?"); # no checking needed here: $query->execute($entered_un);
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Secure Regular Expression Check
by jettero (Monsignor) on Sep 09, 2008 at 14:21 UTC | |
|
Re^2: Secure Regular Expression Check
by jvector (Friar) on Sep 09, 2008 at 17:23 UTC | |
by moritz (Cardinal) on Sep 09, 2008 at 17:26 UTC | |
by Lawliet (Curate) on Sep 09, 2008 at 19:18 UTC | |
by jvector (Friar) on Sep 10, 2008 at 09:07 UTC |