Why is it even possible to accidentally execute a string?
It's absurd.
Executing queries inside strings should be explicit - it should be the case that the developer has to purposely tell the system to use the string as a query.
It should not be the case that SQL automatically executes any code it finds in the string.
Frankly, that's really the part that's completely inexcusable.
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



