Timeline for answer to How does a PreparedStatement avoid or prevent SQL injection? by jack
Current License: CC BY-SA 3.0
Post Revisions
3 events
| when toggle format | what | by | license | comment | |
|---|---|---|---|---|---|
| Jul 24, 2018 at 15:10 | comment | added | Héctor Álvarez |
If I'm not mistaken, The part CAST(‘Robert’); from CAST(‘Robert’); DROP TABLE students; –‘ AS varchar(30)) would break, then it would proceed to drop the table if that was the case. It does stop the injection, so I believe the example is just not complete enough to explain the scenario.
|
|
| Jan 10, 2018 at 14:23 | review | Late answers | |||
| Jan 10, 2018 at 14:30 | |||||
| Jan 10, 2018 at 14:05 | history | answered | jack | CC BY-SA 3.0 |