jdbc避免SQL注入漏洞的方法:
使用PreparedStatement来避免SQL注入,PreparedStatement继承了Statement接口,履行SQL语句的方法无异,例如:
//预编译SQL语句
PreparedStatement pstmt = conn.prepareStatement ("select * from user where username = ? and password = ?") ;
//为参数下标赋值
pstmt.setString (1,username);
pstmt.setString(2,password);
//履行SQL语句,接受结果
ResultSet resultSet = preparedStatement.executeQuery();
本文来源:https://www.yuntue.com/post/61554.html | 云服务器网,转载请注明出处!