|
Posted by Nicholas Sherlock on 11/18/05 08:09
www.douglassdavis.com wrote:
> I have an idea for preventing sql injection attacks, however it would
> have to be implemented by the database vendor. Let me know if I am on
> the right track, this totally off base, or already implemented
> somewhere...
They already exist. In some languages, AFAICS, they are called
"Parameterized queries". Very neat.
Cheers,
Nicholas Sherlock
Navigation:
[Reply to this message]
|