Beefy Boxes and Bandwidth Generously Provided by pair Networks
good chemistry is complicated,
and a little bit messy -LW

Re^3: Simple question on SQL Injection

by jhourcle (Prior)
on Oct 09, 2007 at 16:56 UTC ( #643745=note: print w/replies, xml ) Need Help??

in reply to Re^2: Simple question on SQL Injection
in thread Simple question on SQL Injection

You can't vary the table name with placeholders, nor field names. They only work with values. However, if you're consistent in your naming, and only use a limited set of characters, you can test to see if input is safe, even if not valid. (for instance, only letters, digits, and underscores)

warn "Invalid value" if ( $input =~ m/\W/ );

note -- '\W' matches any character not matched by '\w', which matches letters, numbers, and underscore. The list of what qualifies as a 'letter' is dependant upon your locale settings. If you wanted only ascii letters, use the following:

warn "Invalid value" if ( $input =~ m/[^a-zA-Z\d_]/ );

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://643745]
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others examining the Monastery: (8)
As of 2019-09-23 09:01 GMT
Find Nodes?
    Voting Booth?
    The room is dark, and your next move is ...

    Results (278 votes). Check out past polls.