IMHO, yes. You are always better off with prepared statements.

OWASP agrees. If you look at the recommendation, it says "use
prepared statements" no ifs and/or exceptions.

Honestly, I simply stick with static statements unless there's a real
need for dynamic. The only real need is when you don't know till run
time what file you'll be reading.

"dynamic" WHEREs and ORDER BY can be handled in a static statement.

Charles

On Mon, Aug 1, 2011 at 2:33 PM, Gqcy <gmufasa01@xxxxxxxxx> wrote:
What if I ask the question another way:

are you "always" better off using a prepared statement?

I ask, because even though the programmer carefully created the SQL
via concatenation to protect against injection, the next maintenance
programmer may not.



This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2026 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.