How to understand the principle of PDO from SQL wide byte injection and its correct use
In this issue, the editor will bring you how to understand the PDO principle and correct use of SQL wide bytes. The article is rich in content and analyzes and describes for you from a professional point of view. I hope you can get something after reading this article.
Preface
As the way of parameterized query in database becomes more and more common, the vulnerability of SQL injection is greatly reduced than before, and PDO, as the most typical precompiled query method in php, is used more and more widely.
As we all know, PDO is the best way to prevent SQL injection in php, but it is not a way to eliminate SQL injection. The key depends on how to use it.
Security problems with controllable PDO query statements:
First, create a new library and table locally and write something at will.
Then write a test.php and use PDO to make a simple query: