how to replace and string in a "SELECT ... IN ()"

Michael Mabin d3vvnull at gmail.com
Fri Sep 26 12:00:59 EDT 2008


So we can drop a table in an in clause?  How is this a use case.  Cartoons
are funny but actual proof that this example using an in-clause provides an
exploit would be more helpful I think.

On Fri, Sep 26, 2008 at 9:50 AM, Benjamin Kaplan
<benjamin.kaplan at case.edu>wrote:

>
>
>  On Fri, Sep 26, 2008 at 10:38 AM, Michael Mabin <d3vvnull at gmail.com>wrote:
>
>>  I laugh in the face of danger.
>>
>> Give me a use case for an exploit.
>>
>
> http://xkcd.com/327/
>
>


-- 
| _ | * | _ |
| _ | _ | * |
| *  | * | * |
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.python.org/pipermail/python-list/attachments/20080926/c21a7bb3/attachment.html>


More information about the Python-list mailing list