Am I immune to SQL injections if I use stored procedures?

前端 未结 7 944
别那么骄傲
别那么骄傲 2020-12-09 09:36

Lets say on MySQL database (if it matters).

7条回答
  •  予麋鹿
    予麋鹿 (楼主)
    2020-12-09 09:52

    nope. If you're constructing SQL that invokes a stored procedure you're still a target.

    You should be creating parametized queries on the client side.

提交回复
热议问题