Re: Protection from SQL injection

From: Thomas Kellerer <spam_eater(at)gmx(dot)net>
To: pgsql-sql(at)postgresql(dot)org
Subject: Re: Protection from SQL injection
Date: 2008-04-26 21:32:58
Message-ID: fv0727$cge$1@ger.gmane.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-sql

Thomas Mueller wrote on 26.04.2008 18:32:
> Literals can still be used when using query tools, or in applications considered 'safe'.
I fail to see how the backend could distinguish between a query sent by a query
tool and a query sent by an "application".

Thomas

In response to

Responses

Browse pgsql-sql by date

  From Date Subject
Next Message Scott Marlowe 2008-04-27 00:21:48 Re: Protection from SQL injection
Previous Message Jaime Casanova 2008-04-26 21:31:46 Re: Protection from SQL injection