Foxhole Atheist
Wednesday, August 16, 2017
Like not vulnerable to injection
create
table
#test
(
name
varchar
(
100
))
insert
into
#test
values
(
'fgdgfdfg'
),(
'cxvxbcvb'
),(
'tryuryry'
)
declare
@like
varchar
(
100
)
=
'f; select * from #test --'
select
*
from
#test
where
name
like
@like
+
'%'
drop
table
#test
Newer Posts
Older Posts
Home
Subscribe to:
Posts (Atom)