RE: [PHP] SQL Injection check (mysql)
| From: | Michael Rasmussen | Date: | Tue, 23 Mar 2004 19:53:07 +0000 |
| Subject: | RE: [PHP] SQL Injection check (mysql) | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-181303@lists.php.net to get a copy of this message | ||
On Tue, 23 Mar 2004 09:27:29 -0800, Chris Shiflett wrote:
>
> This argument still makes no sense to me. Originally, you stated that a
> better option to filtering and escaping data was to use a prepared
> statement. Some of us have decided that you are referring to stored
> procedures.
>
> You still have yet to defend your original statement in my mind. If there
> is no foreign data of any kind in a query, it doesn't really matter how
> the query is processed. For every other case (not as rare as you seem to
> think), data filtering is a must.
>
See my reply to Pablo Gosse.
--
Hilsen/Regards
Michael Rasmussen
--------------------------------------------------------------
It was all so different before everything changed.