Live data from Hacker News

From SQL injection to shell: PostgreSQL edition

pentesterlab.com

1–5 of 5 posts

Re: From SQL injection to shell: PostgreSQL edition

#5
post #4

If I use sql parameters in my queries, am I still vulnerable to SQL injection? What about using a (sane) ORM? Basically, is it only php apps that hand-build queries that are vulnerable to SQL injection?

Any app that hand-builds queries. PHP has nothing to do with this. Just happens to be the vehicle. The problem is simply insecure patterns.