此代碼是否容易受到SQL注入攻擊?此代碼是否容易受到SQL注入攻擊?
$sql = "SELECT DISTINCT ID, post_title, post_password, comment_ID, comment_post_ID, comment_author, comment_author_email, comment_date_gmt, comment_approved, comment_type, comment_author_url, SUBSTRING(comment_content,1,70) AS com_excerpt FROM $wpdb->comments LEFT OUTER JOIN $wpdb->posts ON ($wpdb->comments.comment_post_ID = $wpdb->posts.ID) WHERE comment_approved = '1' AND comment_type = '' AND post_password = '' ORDER BY comment_date_gmt DESC LIMIT 5";
這是一個wordpress插件。 – Kyoku
假設'$ wpdb'對象與外界不可觸摸(通常是這樣),我會說你對這個特定的查詢很安全 – Phil
這很難閱讀;您是否在查詢中使用來自不受信任來源的數據? –