in reply to Re: DBI/DBD::mysql placeholders and full text searches
in thread DBI:MYSQL placeholders and full text searches
Though I haven't used it, I gather that the "quote" function you suggested would offer the same sort of protection from sql injection attacks that using placeholders does.my $sql = qq{SELECT * FROM $table WHERE (MATCH(Author) AGAINST(? IN BO +OLEAN MODE)) order by Title}; my $executable = '+'. $melville . ' +' . $herman; $ding -> execute($executable) or die DBI->errstr;
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: DBI/DBD::mysql placeholders and full text searches
by ikegami (Patriarch) on Sep 29, 2008 at 02:04 UTC | |
|
Re^3: DBI/DBD::mysql placeholders and full text searches
by Tanktalus (Canon) on Sep 29, 2008 at 04:05 UTC | |
by Gnat53 (Novice) on Sep 29, 2008 at 11:46 UTC | |
by ikegami (Patriarch) on Sep 29, 2008 at 12:21 UTC | |
|
Re^3: DBI/DBD::mysql placeholders and full text searches
by ikegami (Patriarch) on Sep 29, 2008 at 02:06 UTC |