It's 2019 and PHP is *still* teaching people to concatenate SQL and vaguely-sanitized user input instead of using prepared statements. http://php.net/manual/en/mysqli.examples-basic.php … They got rid of the mysql module... only to teach people to use mysqli the same way. This is why SQLi isn't going away.
PHP interpolates variables between "". But even if it didn't, nothing stops you from explicitly concatenating...
-
-
Yeah so it’s interpolated even before the function sees it. If I ever saw like “WHERE username = “ . $username) in a prepared statement ... wait, never mind found examples of GitHub already :)
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.