PreparedStatement使ã£ã¦ãã®ã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãèµ·ãããã§ããã©ï¼ã¨ãã話é¡ã徳丸浩ã®æ¥è¨ - Javaã¨MySQLã®çµã¿åããã§Unicodeã®U+00A5ãç¨ããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã®å¯è½æ§ããã åç¾ããã®ã§ãã°ã¬ãã¼ãæãã¦ããã¾ãããMySQL Bugs: #41730: SQL Injection when using U+00A5ã§ãããã¦ããªãããã§è§£æ±ºããããã¨ãæå¾ ãããã¨æãã¾ãã ãã¡ã®ç¤¾å ã§characterEncoding使ã£ã¦ãã¨ããã¯ãªããã大ä¸å¤«ãªã¯ãâ¦ãã¨æã£ã¦ããã®ã§ããããã¯ãã³ã¡ã³ããããã ããã¨ãããcharacter_set_server=cp932ã®è¨å®ããããmysqldã«characterEncodingãªãã§ã¤ãªãã å ´åãã¤ã³ã¸ã§ã¯ã·ã§ã³ãèµ·ããã¾ãããsjisãujisãeucjpmsããã¡ã§ããã¨ããããã§ã
{{#tags}}- {{label}}
{{/tags}}