(no title)
ohwp | 11 years ago
For example:
prepare("SELECT name FROM users WHERE country = ? ORDER BY " + unescapedVar, country);
So I wonder, is there any way to force programmers into writing secure queries (by not writing queries)? Is ORM the way to go?
unknown|11 years ago
[deleted]
Eiwatah4|11 years ago