RE: [PHP] SQL Injection check (mysql)

From: Date: Tue, 23 Mar 2004 19:53:07 +0000
Subject: RE: [PHP] SQL Injection check (mysql)
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-181303@lists.php.net to get a copy of this message
On Tue, 23 Mar 2004 09:27:29 -0800, Chris Shiflett wrote: > > This argument still makes no sense to me. Originally, you stated that a > better option to filtering and escaping data was to use a prepared > statement. Some of us have decided that you are referring to stored > procedures. > > You still have yet to defend your original statement in my mind. If there > is no foreign data of any kind in a query, it doesn't really matter how > the query is processed. For every other case (not as rare as you seem to > think), data filtering is a must. > See my reply to Pablo Gosse. -- Hilsen/Regards Michael Rasmussen -------------------------------------------------------------- It was all so different before everything changed.

« previous php.general (#181303) next »