Answer Posted / kerem kusmezer
Sql Injection is one of the input manipulation attacks,
which in case the sql statement is directly buildup from an
string concatanation, in which the user can change through
entry the result sql statement.
For Example:
select top 1 username from users where username
= '&txtusername.Text&'.
If the user enters the text with ' or -- he can add more
command to the outcoming sql statement and change the query
set.
| Is This Answer Correct ? | 2 Yes | 0 No |
Post New Answer View All Answers
How to read data with the sqldatareader ?
Explain the difference between data reader and data set?
What is ole access?
What are the data access namespaces in .NET?
What provider ado.net use by default? Explain the role of data provider in ado.net?
What is difference between ado.net and asp net?
Is datareader faster than datatable?
Which is better ole db or odbc?
What are the rules to implement connection pooling?
What is ole db and odbc?
What are advantages of microsoft-provided data provider classes in ado.net?
What is isolation?
Explain the difference between ado and ado.net?
What is namespace in ado.net?
Describe the command object and its method.