Can I protect against SQL injection by escaping single-quote and surrounding user input with single-quotes?

后端 未结 18 2441
忘了有多久
忘了有多久 2020-11-22 14:03

I realize that parameterized SQL queries is the optimal way to sanitize user input when building queries that contain user input, but I\'m wondering what is wrong with takin

18条回答
  •  刺人心
    刺人心 (楼主)
    2020-11-22 14:47

    It might work, but it seems a little hokey to me. I'd recommend verifing that each string is valid by testing it against a regular expression instead.

提交回复
热议问题