SQLi
SQLi in ORDER BY
SQLi: Active Record — Rails ORM
def index
...
name = params[:name]
@projects = Project.where("name like '" + name + "'");
...
end# Unsafe
st = ActiveRecord::Base.connection.raw_connection.prepare(
"select * from users where email = '#{email}'"
)
results = st.execute
st.close
# Safe
st = ActiveRecord::Base.connection.raw_connection.prepare(
"select * from users where email = ?"
)
results = st.execute(email)
st.closeLast updated