KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I have to add a statement to my java program to update a database table: String insert = "INSERT INTO customer(name,address,email) VALUES('" + name + "','" + addre + "','" + email + "');"; I heard that this can be exploited through an SQL injection like: DROP TABLE customer; My program has a Java GUI and all name, address and email values are retrieved from Jtextfields . I want to know how the following code ( DROP TABLE customer; ) could be added to my insert statement by a hacker and how I can prevent this.
Tags (comma-separated)
Save Edits
Cancel