SQL injection on Classic ASP pages with parameterized queries: text fields

前端 未结 2 1633
孤城傲影
孤城傲影 2021-01-14 15:35

I\'ve parameterized my queries in my Classic ASP app, but am unsure whether I need to sanitize or scrub free text fields or if the parameterization is sufficient to prevent

2条回答
  •  情话喂你
    2021-01-14 16:03

    If you use parametrized queries, you're safe against SQL injection attacks.

    But not for XSS attacks; some user could to insert HTML content (think about

提交回复
热议问题