Midrange News for the IBM i Community


Posted by: clbirk
how to exchange info without using odbc
has no ratings.
Published: 14 Dec 2013
Revised: 17 Dec 2013 - 1821 days ago
Last viewed on: 11 Dec 2018 (3105 views) 

Using IBM i? Need to create Excel, CSV, HTML, JSON, PDF, SPOOL reports? Learn more about the fastest and least expensive tool for the job: SQL iQuery.

how to exchange info without using odbc Published by: clbirk on 14 Dec 2013 view comments(3)

Return to midrangenews.com home page.
Sort Ascend | Descend

COMMENTS

(Sign in to Post a Comment)
Posted by: Ringer
Premium member *
Comment on: how to exchange info without using odbc
Posted: 4 years 11 months 26 days 3 hours 3 minutes ago
Edited: Tue, 17 Dec, 2013 at 15:16:12 (1821 days ago)

Well, I do like your enthusiasm and attitude. And FYI, you left yourself wide open to SQL injection.

For example if $pdfname contains 1' or 1=1 -- 

which becomes WHERE PDFNAME ='1' or 1=1 -- COMMENTS NOW and returns ALL rows. 

Try db2_prepare, db2_bind_param, and db2_execute instead. 

Chris Ringer

Posted by: clbirk
Premium member *
Comment on: how to exchange info without using odbc
Posted: 4 years 11 months 26 days 31 minutes ago

True, I was showing a simple example and in this case and yes you are 100% correct.

 

Posted by: Ringer
Premium member *
Comment on: how to exchange info without using odbc
Posted: 4 years 11 months 25 days 23 hours 47 minutes ago

No problem. I was just letting the next future reader know. Thanks!