How does MongoDB avoid the SQL injection mess?

前端 未结 5 1208
无人共我
无人共我 2020-12-04 17:33

I was reading my trusty O\'Reilly book and came across a passage about how Mongo, by nature, avoids the morass of SQL injection-like flaws.

In my gut, I think I unde

5条回答
  •  北荒
    北荒 (楼主)
    2020-12-04 18:14

    The database might not parse the content but there are other areas of the code that are vulnerable.

    https://www.owasp.org/index.php/Testing_for_NoSQL_injection

提交回复
热议问题