Posted by Gordon Burditt on 05/11/07 23:02
>I set the default user for my connection to the read-only account and have
>to purposefully change the account being used if I want to do anything
>other than just read.
>
>You can't inject SQL if the account you're using doesn't have rights to
>write to the database.
There are plenty of people who would love to inject
select * from credit_card_account_list;
even if the account you're using has no rights to write to the database.
Navigation:
[Reply to this message]
|