Re: C5 MySQL injection attack ("Union Select")

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 03/24/2016 10:13 AM, Always Learning wrote:
I have never (not once) used non-prepared SQL statements, nor string
concatenation, nor sprintf.

Perfect!

mysql_real_escape_string() is useful for storing in tables words with
apostrophes.

You shouldn't need to escape anything if you're using prepared statements.

_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
https://lists.centos.org/mailman/listinfo/centos



[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux