鍍金池/ 問答/數(shù)據(jù)庫/ sql注入風險解決

sql注入風險解決

Connection conn = DriverManager.getConnection(DBUrl, DBUser, DBPassword);

String sql = "SELECT * FROM user WHERE username = '" + userName + "'";
Statement stmt1 = conn.createStatement();
ResultSet name = stmt1.executeQuery(sql);

怎樣修改

回答
編輯回答
陪我終

PreparedStatement

2018年7月4日 01:42