在对上一个问题的评论中,有人说以下 sql 语句打开了我的 sql 注入:
select
ss.*,
se.name as engine,
ss.last_run_at + interval ss.refresh_frequency day as next_run_at,
se.logo_name
from
searches ss join search_engines se on ss.engine_id = se.id
where
ss.user_id='.$user_id.'
group by ss.id
order by ss.project_id, ss.domain, ss.keywords
假设$userid
变量被正确转义,这如何让我变得脆弱,我能做些什么来修复它?