note 82602 rejected from book.pdo by felipe
| From: | felipe@php.net | Date: | Fri, 18 Apr 2008 01:30:01 +0000 |
| Subject: | note 82602 rejected from book.pdo by felipe | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-138432@lists.php.net to get a copy of this message | ||
Note Submitter: vann80 at gmail dot com
----
Hello!
I just wanted to make sure. If using PDO, is there absolutely no chance of SQL Injection or is the
chance just greatly reduced. For example:
<?php
// This uses a PDO wrapper, nothing too advanced
// prepare(QUERY, DATA);
// is the same as
// prepare()
// bind() ...
$st = $db->prepare("INSERT INTO foo SET x = ?", $_POST["raw_data"]);
$st->execute();
?>
How safe is this code actually? I know this is heaven for XSS exploits but what about SQL
Injections? Can I be absolutely positively 100% sure that this will not get exploited by a SQL
injection attack?
Thanks for any input!
Michael.