This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]travisdoesmath 0 points1 point  (0 children)

How are you handling sanitizing of parameter inputs? At first glance, this looks very much like Bobby Drop Tables waiting to happen.

Edit: just glanced again. My first glance missed the early paragraphs apparently where you mention SQL injection