开发者

ADOdb sanitizing queries

开发者 https://www.devze.com 2022-12-27 13:06 出处:网络
Just trying to make sure all my queries are sanitized.We\'re using ADOdb (it\'s already in place, so no talking me out of it).

Just trying to make sure all my queries are sanitized. We're using ADOdb (it's already in place, so no talking me out of it).

Is there something in ADOdb like mysql_real_esca开发者_C百科pe_string?


Use parameterized queries.

MySqlCommand cmd = new MySqlCommand();
string usernName = ...;
cmd.CommandText = "select userid,age from Users where username=@username)"
cmd.Parameters.AddWithValue("@username", userName);;
MySqlDataReader reader =  smd.ExecuteReader();
0

精彩评论

暂无评论...
验证码 换一张
取 消