in reply to Re^3: cleaning up sql from file
in thread cleaning up sql from file
Your approach fails if I you need to insert the following data:
O\'Hara
Your routine will expand that to
O\\'Hara </c>... which is, again, invalid. SQL injection is hard to prevent if you're interpolating arbitrary data.
|
|---|