From what do sql parameters protect you?

前端 未结 6 1021
佛祖请我去吃肉
佛祖请我去吃肉 2020-12-04 00:26

Parameters are used to protect you from malicious user input.

But if the parameter expects a string, is it possible to write input that will be interpreted as sql, s

6条回答
  •  臣服心动
    2020-12-04 01:03

    The only risk would be if you perform an exec on a parameterized string.

    In all other cases, parameterized queries are safe.

提交回复
热议问题