note 82602 added to book.pdo
| From: | vann80 at gmail dot com | Date: | Thu, 17 Apr 2008 20:57:59 +0000 |
| Subject: | note 82602 added to book.pdo | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-138423@lists.php.net to get a copy of this message | ||
Hello!
I just wanted to make sure. If using PDO, is there absolutely no chance of SQL Injection or is the
chance just greatly reduced. For example:
<?php
// This uses a PDO wrapper, nothing too advanced
// prepare(QUERY, DATA);
// is the same as
// prepare()
// bind() ...
$st = $db->prepare("INSERT INTO foo SET x = ?", $_POST["raw_data"]);
$st->execute();
?>
How safe is this code actually? I know this is heaven for XSS exploits but what about SQL
Injections? Can I be absolutely positively 100% sure that this will not get exploited by a SQL
injection attack?
Thanks for any input!
Michael.
----
Server IP: 91.185.195.14
Probable Submitter: 89.212.25.208
----
Manual Page -- http://www.php.net/manual/en/book.pdo.php
Edit -- https://master.php.net/note/edit/82602
Del: integrated -- https://master.php.net/note/delete/82602/integrated
Del: useless -- https://master.php.net/note/delete/82602/useless
Del: bad code -- https://master.php.net/note/delete/82602/bad+code
Del: spam -- https://master.php.net/note/delete/82602/spam
Del: non-english -- https://master.php.net/note/delete/82602/non-english
Del: in docs -- https://master.php.net/note/delete/82602/in+docs
Del: other reasons-- https://master.php.net/note/delete/82602
Reject -- https://master.php.net/note/reject/82602
Search -- https://master.php.net/manage/user-notes.php