On Mon, Apr 11, 2011 at 10:21 AM, Warren Vail warren@vailtech.net wrote:
Your article seems to suggest that the whole concept of db_placeholders is not valid. How would you do any query where parameters come from a form without this vulnerability?
Please re-read the article and the comment on the article.
Thanks, Greg