From: Jon Egil Strand Date: 2006-11-17T03:07:25+09:00 Subject: Re: parse xml file, put results in mysql db > > Pardon me, but your gaping SQL injection hole is showing. > > http://joelonsoftware.com/items/2006/11/01.html > Obviously this is vulnerable for SQL-injections, so I thank you both for completing the picture. What I should have written was: "In my setting, where I massage internally structured and validated data between various formats, I prefer this for readability." The people who could exploit this are the ones who have so much access that they probably could do much worse maladies. Which brings us over to the risk from unfaithful servants. But I didn't write that, and your comments are indeeed correct and appreciated. All the best JE -- Jon Egil Strand Phone: +47 98232340 jes@luretanker.no