English 中文(简体)
是否Zentd_DB/ Doctrine保护我免受排斥?
原标题:Does Zend_DB / Doctrine protect me from SQL injection?

是否利用Zend_DB或Doctrine的准备发言保护我不受q的注射?

例如:

$stmt = $db->prepare( SELECT * FROM users WHERE name = ? AND password = ? );
$rs = $stmt->execute( peter ,  secret );

或者,我是否必须检查一下自我描述和类型?

另一 quick: 两者中哪些是最好的? 我只需要银的抽象(w/ 声明、程序和交易)。

最佳回答

www.un.org/Depts/DGACM/index_french.htm

编写声明,无论是与Zentd_Db、Doctrine或平原老的神话,都通过将问询结构与数据分开来保护你免受注射。 这意味着,如果你根据用户的名称和密码起草一份选择用户的声明,那么任何黑客都无法提供数据,使该声明变成另一种数据。

Just ensure that the query is a string persistent.

关于您的第二个问题,Doctrine和Zend_ Db 采用不同的办法,适合不同的情况和不同的假设选择。 在这个问题上已经存在几个问题。

问题回答

暂无回答




相关问题
SQL SubQuery getting particular column

I noticed that there were some threads with similar questions, and I did look through them but did not really get a convincing answer. Here s my question: The subquery below returns a Table with 3 ...

难以执行 REGEXP_SUBSTR

I m 查询Oracle 10g。 我有两张表格(样本数据见下文)。 i m 试图提取一些领域

SQL Query Shortcuts

What are some cool SQL shorthands that you know of? For example, something I learned today is you can specify to group by an index: SELECT col1, col2 FROM table GROUP BY 2 This will group by col2

PHP array callback functions for cleaning output

I have an array of output from a database. I am wondering what the cleanest way to filter the values is example array Array ( [0] => Array ( [title] => title 1 ...

OracleParameter and DBNull.Value

we have a table in an Oracle Database which contains a column with the type Char(3 Byte). Now we use a parameterized sql to select some rows with a DBNull.Value and it doesn t work: OracleCommand ...

Running numbers in SQL

I have a SQL-statement like this: SELECT name FROM users WHERE deleted = 0; How can i create a result set with a running number in the first row? So the result would look like this: 1 Name_1 2 ...

How to get SQL queries for each user where env is production

I’m developing an application dedicated to generate statistical reports, I would like that user after saving their stat report they save sql queries too. To do that I wrote the following module: ...

热门标签