ockehgemã®ããã¯ãã¼ã¯ãè¦ã¦ããã¨ããã6人ã®ã¦ã¼ã¶ã«ç»é²ããã以ä¸ã®è¨äºããã£ãã ãµã¤ãèå¼±æ§ããã§ãã¯ãããï¼--第6åï¼SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã®æ¤æ»æ¹æ³, æ± ç°é
ä¸, ZDNET Japan, 2007å¹´11æ26æ¥ ã¾ãæ± ç°é
ä¸ããé¡è¦ç¥ããªã®ã§ãºããªãããã¨ã«ããã ãã®èå¼±æ§ã®æ¤æ»æ¹æ³ã説æããåã«ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã®ä»çµã¿ã«ã¤ãã¦èª¬æãããã ã¸ãã çµããã®æ¹ãè¦ã¦ã¿ãã¨ã 対ç SQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çã®åºæ¬ã¯XSSã¨åããé©åãªã¨ã¹ã±ã¼ãå¦çãè¡ããã¨ã ãæè¿ãéçºç°å¢ã®å¤ãã¯ãPrepared Statementãããã¯ãã¤ã³ãã¡ã«ããºã ã¨å¼ã°ããä»çµã¿ãå®è£
ããã¦ããã®ã§ãããããç¨ãããã¨ãæãç°¡åãªæ¹æ³ã¨ãããã 対çã«ãæºåãããæã(prepared statement) ã®ãã¨ãæ¸ããã®ã¯ä¸å¿è©ä¾¡ããããããããã¾ãå½¼ã¯andã¨orã®åºå¥
{{#tags}}- {{label}}
{{/tags}}