Unsanitized external input in SQL query
Overview
Description
Remediation Guidelines
Statement stmt = conn.createStatement(); ResultSet rs = stmt.executeQuery("select name from users where id='" + uri.getQueryParameter("user_id") + "'"));PreparedStatement myStmt = myCon.prepareStatement("select * from students where age > ? and name = ?"); myStmt.setInt(1, uri.getQueryParameter("age")); myStmt.setString(2, uri.getQueryParameter("name"));
References
Configuration
Last updated