首页 > 数据库技术 > 详细

php的mysql_prepare不能使用表明一类级作为参数

时间:2015-03-10 19:28:14      阅读:169      评论:0      收藏:0      [点我收藏+]
No, a parameterised query doesn‘t just drop the parameter values in to the query string, it supplies the RDBMS with the parameterised query and the parameters separately. But such a query can‘t have a table name or field name as a parameter. The only way to do that is to dynamically code the table name into the query string, just as you have already done. If this string is potentially open to attack you should validate it first; such as against a white list list of allowable table

php的mysql_prepare不能使用表明一类级作为参数

原文:http://blog.csdn.net/hellochenlian/article/details/44177929

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!