Re: Need help with quote escaping in exim for postgresql - Mailing list pgsql-general

From Florian Weimer
Subject Re: Need help with quote escaping in exim for postgresql
Date
Msg-id 87y7v23d6m.fsf@mid.deneb.enyo.de
Whole thread Raw
In response to Re: Need help with quote escaping in exim for postgresql  (Martijn van Oosterhout <kleptog@svana.org>)
List pgsql-general
* Martijn van Oosterhout:

>     * If application always sends untrusted strings as out-of-line
> parameters, instead of embedding them into SQL commands, it is not
> vulnerable.

This paragraph should explictly mention PQexecParams (which everybody
should use anyway).

It seems that Exim's architecture prevents the use of PQexecParams,
though.

pgsql-general by date:

Previous
From: Michael Fuhr
Date:
Subject: Re: Procedural language functions across servers
Next
From: Martijn van Oosterhout
Date:
Subject: Re: Need help with quote escaping in exim for postgresql