Why is it even possible to accidentally execute a string?
It's absurd.
Executing queries inside strings should be explicit - it should be the case that the developer has to purposely tell the system to use the string as a query.
It should not be the case that SQL automatically executes any code it finds in the string.
Frankly, that's really the part that's completely inexcusable.
Discussion on:
Message 7 of 1
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



