Josh Berkus wrote:
> Could be.  Windows filenames tend to produce false positives, if nothing
> else.  Also, it's possible that the user is using 8.3 as the database,
> but DBI is still bound to an older version of libpq.  Worth checking.

Angel, is that the case here? Are you by any chance using debian or
ubuntu packages?



> 
>> Anyway, in 2.3+ no more escaping is used at all. All insertions are done
>> using parameter binding - that is, except for some numerical type
>> insertions where the values come from a trusted source (internal).
> 
> Glad to hear it.  You're way ahead of the curve.

:-)


-- 
  ________________________________________________________________
  Paul Stevens                                      paul at nfg.nl
  NET FACILITIES GROUP                     GPG/PGP: 1024D/11F8CD31
  The Netherlands________________________________http://www.nfg.nl
_______________________________________________
DBmail mailing list
[email protected]
https://mailman.fastxs.nl/mailman/listinfo/dbmail

Reply via email to