1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Quick SQL Injection question?

Discussion in 'Microsoft News' started by NewsBot, Apr 11, 2008.

  1. NewsBot

    NewsBot I Got News

    Joined:
    Feb 8, 2006
    Messages:
    1,813
    Operating System:
    Windows Vista Home Premium
    Imusing Sql Server 2005 and C# 1.1. I do realize about SqlCommand andParamters to eliminate Sql Injection but if i were forced to create adynamic query and were unable to use Parameters, to avoid sql injectionis it ONLY necessary to replace all instances of single quote with 2xsingle quotes from incoming user data?

    Thank you




     

Share This Page