Re: SQL injection, php and queueing multiple statement - Mailing list pgsql-general

From Tom Lane
Subject Re: SQL injection, php and queueing multiple statement
Date
Msg-id 16968.1208018378@sss.pgh.pa.us
Whole thread Raw
In response to Re: SQL injection, php and queueing multiple statement  (Ivan Sergio Borgonovo <mail@webthatworks.it>)
Responses Re: SQL injection, php and queueing multiple statement  (Ivan Sergio Borgonovo <mail@webthatworks.it>)
List pgsql-general
Ivan Sergio Borgonovo <mail@webthatworks.it> writes:
> I may sound naive but having a way to protect the DB from this kind
> of injections looks as a common problem, I'd thought there was
> already a common solution.

Use prepared statements.

            regards, tom lane

pgsql-general by date:

Previous
From: Ray Stell
Date:
Subject: Re: PostgreSQL Processes on a linux box
Next
From: "Dawid Kuroczko"
Date:
Subject: Re: Postgres on shared network drive