防止 JSP SQL Injection (注射)


1
2
3
4
5
String sql = "DELETE FROM table1 WHERE id=? AND pwd=?";
PreparedStatement pstmt = conn.PreparedStatement(sql);
pstmt.setString(1,request.getParameter("id"));
pstmt.setString(2,request.getParameter("pwd"));
pstmt.executeUpdate();