Re: design, plpgsql and sql injection in dynamically generated sql - Mailing list pgsql-general

From Pavel Stehule
Subject Re: design, plpgsql and sql injection in dynamically generated sql
Date
Msg-id 162867790908180554v6d291b5dv7f5dc4f995b2cdc6@mail.gmail.com
Whole thread Raw
In response to Re: design, plpgsql and sql injection in dynamically generated sql  (Ivan Sergio Borgonovo <mail@webthatworks.it>)
List pgsql-general
2009/8/18 Ivan Sergio Borgonovo <mail@webthatworks.it>:
> On Tue, 18 Aug 2009 12:38:49 +0200
> Pavel Stehule <pavel.stehule@gmail.com> wrote:
>
>> some unsafe function:
>
> I suspected something similar.
>
> I think many would appreciate if you put these examples here
> http://www.okbob.blogspot.com/2008/06/execute-using-feature-in-postgresql-84.html
> and substitute the int example there with the text one.

actualized
http://okbob.blogspot.com/2008/06/execute-using-feature-in-postgresql-84.html

regards
Pavel

>
> thanks
>
> --
> Ivan Sergio Borgonovo
> http://www.webthatworks.it
>
>

pgsql-general by date:

Previous
From: Sam Mason
Date:
Subject: Re: Best database model for canvassing (and analysing) opinion
Next
From: Adrian Klaver
Date:
Subject: Re: Function Logging