Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
WestWind/database filter help
Message
Information générale
Forum:
Visual FoxPro
Catégorie:
Codage, syntaxe et commandes
Divers
Thread ID:
01516279
Message ID:
01516358
Vues:
67
>>Look at SQLEXEC() function.
>>
>>Also, it's bad practice to embed parameters into your sql query. It opens you up to SQL injection attacks.
>
>http://xkcd.com/327/

I have always loved this XKCD.

Technically he's wrong. He should say parameterize but sanitize fits in the space better :)

http://select-into.blogspot.com/2011/01/little-bobby-tables.html
Brandon Harker
Sebae Data Solutions
Précédent
Suivant
Répondre
Fil
Voir

Click here to load this message in the networking platform