A3:2021 | SQL Injection Mitigation (1) | Cycubics Docs
Immutable Queries
Static Queries
SELECT * FROM products;SELECT * FROM users WHERE user = "'" + session.getAttribute("UserID") + "'";Parameterized Queries
String query = "SELECT * FROM users WHERE last_name = ?";
PreparedStatement statement = connection.prepareStatement(query);
statement.setString(1, accountName);
ResultSet results = statement.executeQuery();Stored Procedures
Immutable Queries
Static Queries
Parameterized Queries
Stored Procedures
PreviousA3:2021 | Injection | SQL Injection Mitigation | Cycubix DocsNextA3:2021 | SQL Injection Mitigation (2) |
Last updated
Was this helpful?

