EXEC SQL
语句来执行参数化查询。DATA lv_name TYPE string.
lv_name = 'John';
EXEC SQL.
SELECT * FROM employees WHERE name = :lv_name;
END EXEC.
DATA lv_name TYPE string.
lv_name = 'John';
lv_name = REPLACE( val = lv_name src = '''' with = '' ); " 过滤单引号
DATA: lv_name TYPE string,
lv_salary TYPE p DECIMALS 2.
lv_name = 'John';
lv_salary = 5000.
START TRANSACTION.
EXEC SQL.
UPDATE employees SET salary = :lv_salary WHERE name = :lv_name;
END EXEC.
COMMIT WORK.
限制数据库用户权限:为数据库用户分配最小必需的权限,避免给予过多权限导致恶意用户进行SQL注入攻击。
定期更新数据库系统和应用程序:及时更新数据库系统和应用程序的补丁,以修复已知的安全漏洞,降低遭受SQL注入攻击的风险。