note 82602 added to book.pdo

From: Date: Thu, 17 Apr 2008 20:57:59 +0000
Subject: note 82602 added to book.pdo
Groups: php.notes 
Request: Send a blank email to php-notes+get-138423@lists.php.net to get a copy of this message
Hello! I just wanted to make sure. If using PDO, is there absolutely no chance of SQL Injection or is the chance just greatly reduced. For example: <?php // This uses a PDO wrapper, nothing too advanced // prepare(QUERY, DATA); // is the same as // prepare() // bind() ... $st = $db->prepare("INSERT INTO foo SET x = ?", $_POST["raw_data"]); $st->execute(); ?> How safe is this code actually? I know this is heaven for XSS exploits but what about SQL Injections? Can I be absolutely positively 100% sure that this will not get exploited by a SQL injection attack? Thanks for any input! Michael. ---- Server IP: 91.185.195.14 Probable Submitter: 89.212.25.208 ---- Manual Page -- http://www.php.net/manual/en/book.pdo.php Edit -- https://master.php.net/note/edit/82602 Del: integrated -- https://master.php.net/note/delete/82602/integrated Del: useless -- https://master.php.net/note/delete/82602/useless Del: bad code -- https://master.php.net/note/delete/82602/bad+code Del: spam -- https://master.php.net/note/delete/82602/spam Del: non-english -- https://master.php.net/note/delete/82602/non-english Del: in docs -- https://master.php.net/note/delete/82602/in+docs Del: other reasons-- https://master.php.net/note/delete/82602 Reject -- https://master.php.net/note/reject/82602 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#138423) next »