以下是否暴露了 Sql Injection 攻击向量?如果确实如此,我该如何预防?
@bookId = '1234;' + 'Drop table Books;'
Select * from Books where bookId = @bookId
它不会像这样执行吗?:
Select * from Books where bookId = 1234; Drop table Books;
以下是否暴露了 Sql Injection 攻击向量?如果确实如此,我该如何预防?
@bookId = '1234;' + 'Drop table Books;'
Select * from Books where bookId = @bookId
它不会像这样执行吗?:
Select * from Books where bookId = 1234; Drop table Books;