RE: [PHP-DEV] pdo: binding variables supplied to execute() is NotVeryUseful(tm)...
| From: | Jared Williams | Date: | Fri, 25 Mar 2005 13:36:52 +0000 |
| Subject: | RE: [PHP-DEV] pdo: binding variables supplied to execute() is NotVeryUseful(tm)... | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-15598@lists.php.net to get a copy of this message | ||
> $sql = "insert into $table ($col_list) values ($bind_list)";
Can I just point out that you've just negated the whole reason for having parameters in the
first place, imo.
$table is just as vulnerable to an SQL injection attack, as any of the parameters where before we
had parameter binding.
Jared