in reply to Quick DBI do question
Yes. The methods you use in 1a and 2b are potentially very dangerous - see SQL_injection. It's better (particularly if you plan to perform a task repeatedly) to use place holders, both from a security and efficiency stand point. For more details on placeholder technology, check out placeholders.
As well, in place of a single do statement, it's probably a good idea to parse it out into a prepare and execute set, possibly with prepare statements, as described in DBI.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Quick DBI do question
by lostjimmy (Chaplain) on Feb 13, 2009 at 16:17 UTC | |
by kennethk (Abbot) on Feb 13, 2009 at 16:21 UTC | |
by doom (Deacon) on Feb 15, 2009 at 03:23 UTC | |
|
Re^2: Quick DBI do question
by Anonymous Monk on Feb 17, 2009 at 13:16 UTC | |
by kennethk (Abbot) on Feb 17, 2009 at 14:27 UTC | |
by Anonymous Monk on Feb 17, 2009 at 16:03 UTC |