是否利用Zend_DB或Doctrine的准备发言保护我不受q的注射?
例如:
$stmt = $db->prepare( SELECT * FROM users WHERE name = ? AND password = ? );
$rs = $stmt->execute( peter , secret );
或者,我是否必须检查一下自我描述和类型?
另一 quick: 两者中哪些是最好的? 我只需要银的抽象(w/ 声明、程序和交易)。
是否利用Zend_DB或Doctrine的准备发言保护我不受q的注射?
例如:
$stmt = $db->prepare( SELECT * FROM users WHERE name = ? AND password = ? );
$rs = $stmt->execute( peter , secret );
或者,我是否必须检查一下自我描述和类型?
另一 quick: 两者中哪些是最好的? 我只需要银的抽象(w/ 声明、程序和交易)。
www.un.org/Depts/DGACM/index_french.htm
编写声明,无论是与Zentd_Db、Doctrine或平原老的神话,都通过将问询结构与数据分开来保护你免受注射。 这意味着,如果你根据用户的名称和密码起草一份选择用户的声明,那么任何黑客都无法提供数据,使该声明变成另一种数据。
Just ensure that the query is a string persistent.
关于您的第二个问题,Doctrine和Zend_ Db 采用不同的办法,适合不同的情况和不同的假设选择。 在这个问题上已经存在几个问题。
I noticed that there were some threads with similar questions, and I did look through them but did not really get a convincing answer. Here s my question: The subquery below returns a Table with 3 ...
I m 查询Oracle 10g。 我有两张表格(样本数据见下文)。 i m 试图提取一些领域
We have a restaurant table that has lat-long data for each row. We need to write a query that performs a search to find all restaurants within the provided radius e.g. 1 mile, 5 miles etc. We have ...
What are some cool SQL shorthands that you know of? For example, something I learned today is you can specify to group by an index: SELECT col1, col2 FROM table GROUP BY 2 This will group by col2
I have an array of output from a database. I am wondering what the cleanest way to filter the values is example array Array ( [0] => Array ( [title] => title 1 ...
we have a table in an Oracle Database which contains a column with the type Char(3 Byte). Now we use a parameterized sql to select some rows with a DBNull.Value and it doesn t work: OracleCommand ...
I have a SQL-statement like this: SELECT name FROM users WHERE deleted = 0; How can i create a result set with a running number in the first row? So the result would look like this: 1 Name_1 2 ...
I’m developing an application dedicated to generate statistical reports, I would like that user after saving their stat report they save sql queries too. To do that I wrote the following module: ...