From: Florian Gilcher Date: 2008-05-31T07:49:59+09:00 Subject: Re: How do i replace actual value in the query with variable -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On May 30, 2008, at 6:37 PM, Phillip Gawlowski wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Ryan Lewis wrote: > | or even: > | (0..4).each { |q| conn.exec( 'UPDATE SCH_EVENT SET P_ID = 2444334 > where > | RANK = #{q.to_f} AND playlist_id = 432' ) } > > Gotta love an SQL injection waiting to happen.. > Converting to a number type before using the value is injection safe. I wonder how you are going to convince #to_f (or #to_i )to return valid SQL code. But: why don't you just use prepared Statements? Regards, Florian Gilcher -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.8 (Darwin) iEYEARECAAYFAkhAhKIACgkQJA/zY0IIRZaEsQCeLig1V1IQeJVRcvf2A194pCw7 vW4AniG9q9dCLwTxChvfAQm9tooTjpqn =fp2m -----END PGP SIGNATURE-----