Quote:
Originally Posted by pushipu
Very good post about PDO - 
LSS
This why everyone fail, because he think is 100% secure, there is no such things yet.
|
ofcourse PDO prepared statements are not 100% secure :3
Quote:
|
If ALL your queries are parametrized, you're also protected against 2nd order injection. 1st order injection is forgetting that user data is untrustworthy. 2nd order injection is forgetting that database data is untrustworthy (because it came from the user originally).
|
with basic input/form validation your life will be easier