Re: pdo: binding variables supplied to execute() is NotVeryUseful(tm)...
| From: | Lukas Smith | Date: | Fri, 25 Mar 2005 13:41:59 +0000 |
| Subject: | Re: pdo: binding variables supplied to execute() is NotVeryUseful(tm)... | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-15599@lists.php.net to get a copy of this message | ||
Jared Williams wrote:
uhm the point of prepared queries is not to eliminate sql injection. thats just an added benefitCan I just point out that you've just negated the whole reason for having parameters in the first place, imo.$sql = "insert into $table ($col_list) values ($bind_list)";
$table is just as vulnerable to an SQL injection attack, as any of the parameters where before we had parameter binding.you are assuming that $table has not bee sanitized, which seems quite unlikely to me that its even going to be a variable controled by user input in the first place. regards, Lukas