db_escape
#1

db_escape e folosit pentru a impiedica SQL injection. Dar daca eu am scriptul asa:

Code:
"SELECT * FROM users WHERE name = '%s' LIMIT 0, 1"
%s e pus intre ghilimele, deci nu mai poti sa iti pui numele 'x OR 1=1'. Mai trebuie db_escape acum?
Reply


Messages In This Thread
db_escape - by GaByM - 21.03.2017, 16:04
Re: db_escape - by Jessyy - 21.03.2017, 17:51
Re: db_escape - by wanted2013 - 25.03.2017, 12:52

Forum Jump:


Users browsing this thread: 1 Guest(s)