SQL quotation marks backslash escape can be bypassed by double-byte injection. Can this problem be avoided by transferring utf-8 first?
SQL quotation marks backslash escape can be bypassed by double-byte injection. Can this problem be avoided by transferring utf-8 first?
the ultimate solution to the java or php, injection problem is to abandon sql splicing and use the parameter placeholder of PrepareStatement
use the parameter binding method of php's PDO to avoid the problem of sql injection