Re: Effectiveness of pg_escape_string at blocking SQL injection

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



Volkan YAZICI wrote:

[snip]

If you think, they're not enough for SQL-Injection attacks, I'd advice
you to patch libpq code, not PHP.

This is very helpful information. My initial thinking is that this wouldn't be effective at catching SQL injections, but I'll need to bounce this off a few other folks.

Thanks!

--
Ed Finkler
Web and Security Archive Administrator
CERIAS - Purdue University
http://www.cerias.purdue.edu/
v: 765.496.6762  f: 764.496.3181


[Index of Archives]     [Postgresql General]     [Postgresql Admin]     [PHP Users]     [PHP Home]     [PHP on Windows]     [Kernel Newbies]     [PHP Classes]     [PHP Databases]     [Yosemite Backpacking]     [Postgresql Jobs]

  Powered by Linux