Can I protect against SQL injection by escaping single-quote and surrounding user input with single-quotes?

后端 未结 18 2434
忘了有多久
忘了有多久 2020-11-22 14:03

I realize that parameterized SQL queries is the optimal way to sanitize user input when building queries that contain user input, but I\'m wondering what is wrong with takin

18条回答
  •  自闭症患者
    2020-11-22 14:40

    What ugly code all that sanitisation of user input would be! Then the clunky StringBuilder for the SQL statement. The prepared statement method results in much cleaner code, and the SQL Injection benefits are a really nice addition.

    Also why reinvent the wheel?

提交回复
热议问题