English 中文(简体)
发言稿
原标题:SQL Prepared Statement to Create Table

我想知道,根据用户投入(SQL编制声明)编制传单表格的方式有些。

CREATE TABLE ? (
  First_Name char(50),
  Last_Name char(50)
)

哪一个问题标志

问题回答

编造的地籍持有人不是为了列表名称或栏目,而只是为了实际的栏目价值。

因此,你必须主动提出(准备的)说明,这意味着你的申请将,可到Kall injection。 取决于申请如何使用,以及由谁使用,这可能是一个BIG问题。

Related question

正如其他答复指出的,由于大多数房舍管理事务部门不支持更换表名,你不能在此使用已准备好的说明。

然而,我要指出,选择基于用户投入的表格名称似乎是一种坏的想法。 您如何防止重复或无效姓名?

为什么表格名称问题?





相关问题
Spring Properties File

Hi have this j2ee web application developed using spring framework. I have a problem with rendering mnessages in nihongo characters from the properties file. I tried converting the file to ascii using ...

Logging a global ID in multiple components

I have a system which contains multiple applications connected together using JMS and Spring Integration. Messages get sent along a chain of applications. [App A] -> [App B] -> [App C] We set a ...

Java Library Size

If I m given two Java Libraries in Jar format, 1 having no bells and whistles, and the other having lots of them that will mostly go unused.... my question is: How will the larger, mostly unused ...

How to get the Array Class for a given Class in Java?

I have a Class variable that holds a certain type and I need to get a variable that holds the corresponding array class. The best I could come up with is this: Class arrayOfFooClass = java.lang....

SQLite , Derby vs file system

I m working on a Java desktop application that reads and writes from/to different files. I think a better solution would be to replace the file system by a SQLite database. How hard is it to migrate ...

热门标签