|
|||||||||||
|
Re: JDBC PreparedStatements, Java Data Objects/O-R mapping, and SQL Injection
From: Dave Aitel <dave(at)immunitysec.com>
Date: Mon Dec 30 2002 - 18:14:39 EST I dunno about that. Impossible is such a big word, and I've seen SQL Injection successfully done at least few times against a stored procedure. You should put your sample apps on a web site somewhere so people can knock it around a bit.
Dave Aitel
On Mon, 30 Dec 2002 17:32:13 -0500
> The use of prepared statements and stored procedures makes SQL
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:46 EDT |
||||||||||
|
|||||||||||