ibatis避免sql注入的方法:
使用#写法采取预编译方式,将转义交给数据库,则不会出现注入问题,例如:
//mysql环境
select * from test where school_name like concat('%',${name},'%')
//oracle环境
select * from test where school_name like '%'||${name},'%'
//SQL Server环境
select * from test where school_name like '%'+${name},+'%'
本文来源:https://www.yuntue.com/post/62057.html | 云服务器网,转载请注明出处!

微信扫一扫打赏
支付宝扫一扫打赏