Comment on C# Asp.net: Thwart SQL Injection Using Reg Expressions ..parentComments−jasonkester17ySimply amazing that it's 2009 and people are still trying to escape strings by hand. C#, the language for which this piece was written, has had parameterized queries since 2001.
Comments
Simply amazing that it's 2009 and people are still trying to escape strings by hand. C#, the language for which this piece was written, has had parameterized queries since 2001.