ä»æ¥ã®æ¥è¨ã§ã¯ãOracleã§ã®SQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çã«ã¤ãã¦æ¸ãã¾ãã 以ä¸ã®ãããªã³ã¼ãï¼PHPï¼ãããã¨ãã¾ãã <?php ... $foo_escape = str_replace("'", "''", $foo); $sql = "SELECT * FROM table1 WHERE foo='$foo_escape'"; $stmt = OCIParse($dbh, $sql); ... ã'ããã''ãã«ã¨ã¹ã±ã¼ããã¦SQLæã«åãè¾¼ã¿ãOracleã§å®è¡ï¼Parseï¼ãã¦ãã¾ãã å²ã¨ããããã³ã¼ãããããã¾ããããããã ã¨SQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã«èå¼±ãªå ´åãããã¾ãã ä¸æ£ãªæåå DBãµã¼ãã¨ã®ã³ãã¯ã·ã§ã³ã«EUC-JPï¼JA16EUCTILDEï¼ã使ç¨ãã¦ããã¨ãã¾ãã ããã§ã$fooã«ã[0xA1]' OR 1=1--ãã®ãããªãEUC-JPã¨ãã¦ä¸æ£ãª
{{#tags}}- {{label}}
{{/tags}}