From: David Morton Date: 2008-01-02T16:10:11+09:00 Subject: Re: how to pass variable value to a sql query -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Jan 2, 2008, at 1:01 AM, Karthi kn wrote: > Pradeepta Swain wrote: >> Hi, >> How can i pass a variable to a sql query like >> >> rs = dbh.prepare("select *from status_check where id=204") >> rs.execute >> >> Instead of giving the value of id I want to make it dynamic ,where >> I can >> pass the dynamic value of id fetched from database much like in PL/ >> SQL . >> How to do this .Anybody help !! > > rs = dbh.prepare("select *from status_check where id=#{value}") > rs.execute NO! This is a security risk. This opens you up to sql injection attacks. You should always use placeholders so the library can properly escape your input. See my other message for a link on how to use placeholders. David Morton Maia Mailguard http://www.maiamailguard.com mortonda@dgrmm.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (Darwin) iD8DBQFHezjOUy30ODPkzl0RAtFmAJ4qoogCOpMZk+gWRbwGUL08OtTzKwCgiQm6 HWDyvWfx2dhMYYvHKbme4ZA= =2tT+ -----END PGP SIGNATURE-----