首页 > 数据库技术 > 详细

python--防止SQL注入

时间:2019-07-07 00:21:06      阅读:155      评论:0      收藏:0      [点我收藏+]
from pymysql import *


def main():
    # 创建Connextion连接
    conn = connect(host=‘localhost‘, port=3306, user=‘root‘, password=‘‘, database=‘test‘, charset=‘utf8‘)
    # 获取Cursor对象
    cursor = conn.cursor()
    param = "‘ or 1 = 1 or ‘1"
    sql = "select * from users where username = ‘%s‘" % (param,)
    count = cursor.execute(sql)
    print(count)
    # 结果是2 获取到数据库所有记录
    print(cursor.fetchall())
    # ((1, ‘张三‘, ‘男‘, 10), (2, ‘李四‘, ‘男‘, 10))
    count1 = cursor.execute("select * from users where username = %s", param)
    print(count1)
    # 结果是0



if __name__ == ‘__main__‘:
    main()

  

python--防止SQL注入

原文:https://www.cnblogs.com/f-rt/p/11144591.html

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!