1. 程式人生 > >like語句防止SQL註入

like語句防止SQL註入

concat bsp lec test where mysq sql rom school

mysql: select * from test where school_name like concat(‘%‘,${name},‘%‘)

oracle: select * from test where school_name like ‘%‘||${name},‘%‘

SQL Server:select * from test where school_name like ‘%‘+${name},+‘%‘

like語句防止SQL註入