View Single Post
Old Nov 28th, 2007, 4:06 PM   #2
Arevos
Programming Guru
 
Arevos's Avatar
 
Join Date: Aug 2005
Location: England
Posts: 1,499
Rep Power: 5 Arevos is on a distinguished road
Re: Emulating Behaviour Of "mysql_real_escape_string"

You can stop SQL injections by using parameters, e.g:

cursor.execute("SELECT * FROM users WHERE login = '%s' AND passwd = '%s'", (login, passwd))
Arevos is offline   Reply With Quote