Click here to Skip to main content
15,887,746 members
Home / Discussions / Database
   

Database

 
QuestionSql Scripts in C# Pin
da vinci coder19-Nov-05 17:56
da vinci coder19-Nov-05 17:56 
AnswerRe: Sql Scripts in C# Pin
Colin Angus Mackay20-Nov-05 8:13
Colin Angus Mackay20-Nov-05 8:13 
Questionreturning guid from row jsut added Pin
g00fyman19-Nov-05 15:53
g00fyman19-Nov-05 15:53 
QuestionSave difficult ...!!! Pin
mostafa_h19-Nov-05 4:55
mostafa_h19-Nov-05 4:55 
Questiontrying to install SQL SERVER 2000 Pin
microuser_200019-Nov-05 3:51
microuser_200019-Nov-05 3:51 
AnswerRe: trying to install SQL SERVER 2000 Pin
Colin Angus Mackay19-Nov-05 10:08
Colin Angus Mackay19-Nov-05 10:08 
Questionreplace single quotes in SELECT Pin
jszpila18-Nov-05 6:43
jszpila18-Nov-05 6:43 
AnswerRe: replace single quotes in SELECT Pin
Colin Angus Mackay18-Nov-05 13:44
Colin Angus Mackay18-Nov-05 13:44 
jszpila wrote:
I'm querying a table of usernames, some of which have single quotes in them. I'm hesitant to make a stored procedure to perform a search and replace on the entire table, so I was trying to find a way to make the query tolerate the single quote using the REPLACE() method, but I haven't met with any success so far.


I'm not sure I understand the logic of your thinking. How would using REPLACE() tolerate single quotes?

It looks like the code is venturing into a high possibiliy of an Injection Attack. See SQL Injection Attacks and Tips on How to Prevent Them[^]

If you are issuing a SQL Statement from a .NET application like this:
SELECT * FROM MyTable WHERE Name = 'O'Brian'
then you should use a paramter instead
SELECT * FROM MyTable WHERE Name = @Name





My: Blog | Photos

"Man who stand on hill with mouth open will wait long time for roast duck to drop in." -- Confucious


QuestionSQL Reporting Services Error Pin
utsav_verma17-Nov-05 19:07
utsav_verma17-Nov-05 19:07 
QuestionA Transact-SQL Question Pin
Xiaoming Qian16-Nov-05 20:37
Xiaoming Qian16-Nov-05 20:37 
AnswerRe: A Transact-SQL Question Pin
Grav-Vt17-Nov-05 12:56
Grav-Vt17-Nov-05 12:56 
Questionscope identity not a function name Pin
kal2na216-Nov-05 19:37
kal2na216-Nov-05 19:37 
AnswerRe: scope identity not a function name Pin
Grav-Vt17-Nov-05 12:57
Grav-Vt17-Nov-05 12:57 
QuestionCheck for a string of SPACE characters Pin
Chris Meech16-Nov-05 9:06
Chris Meech16-Nov-05 9:06 
QuestionSQL code coverage Pin
Paul Watson16-Nov-05 3:23
sitebuilderPaul Watson16-Nov-05 3:23 
QuestionRe: SQL code coverage Pin
Chris Meech16-Nov-05 9:10
Chris Meech16-Nov-05 9:10 
AnswerRe: SQL code coverage Pin
Paul Watson16-Nov-05 9:22
sitebuilderPaul Watson16-Nov-05 9:22 
QuestionTying a XML playlist to SQL data Pin
normschaef15-Nov-05 11:56
normschaef15-Nov-05 11:56 
Questionschema design question Pin
ppp00115-Nov-05 6:44
ppp00115-Nov-05 6:44 
AnswerRe: schema design question Pin
Daniel Santillanes15-Nov-05 7:00
professionalDaniel Santillanes15-Nov-05 7:00 
GeneralRe: schema design question Pin
toxcct16-Nov-05 5:24
toxcct16-Nov-05 5:24 
QuestionDataSet - Query problem Pin
Timothy_198215-Nov-05 5:47
Timothy_198215-Nov-05 5:47 
AnswerRe: DataSet - Query problem Pin
Daniel Santillanes15-Nov-05 6:49
professionalDaniel Santillanes15-Nov-05 6:49 
GeneralRe: DataSet - Query problem Pin
Timothy_198215-Nov-05 7:36
Timothy_198215-Nov-05 7:36 
GeneralRe: DataSet - Query problem Pin
Daniel Santillanes15-Nov-05 12:18
professionalDaniel Santillanes15-Nov-05 12:18 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.