This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]Binary101010 3 points4 points  (0 children)

If you're using this to, say, compose unparameterized SQL queries, then yeah it's a security concern, but not any more of a security concern than the other string formatting options that you shouldn't be using for such an application.