Reply to Message

Why is it even possible to accidentally execute a string?

It's absurd.

Executing queries inside strings should be explicit - it should be the case that the developer has to purposely tell the system to use the string as a query.

It should not be the case that SQL automatically executes any code it finds in the string.

Frankly, that's really the part that's completely inexcusable.
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox