Not really. But as long as you use *only* bind variables in JDBC, you should be immune to sql injection.

-Tim

Curley, Thomas wrote:
Hi,

I have an app using MySql and TC4 on linux o JSP app

Does Tomcat have any inbuild features to filter out certain characters like ', ;, etc from request URI's. Would a filters or values impl help with this or is it necessary to parse all input (may affect performance)

any experience

thanks

Thomas



---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Reply via email to