Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
SQL injection (no single quotes used) Dec 09 2004 03:53PM
Juan Carlos Calderon (johnccr yahoo com)
Hi all

While in Oracle escaping apostrophe (') character
seems to be enough protection for Sql Injection (I
think is not), this is not true for Sql Server. Here a
little example I think many of you will find useful.

For an on-the-fly query like:
Query = "select field1, field2... from table where i...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus