Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8927817
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 15, 20262026-06-15T08:17:52+00:00 2026-06-15T08:17:52+00:00

As the title suggests, I would like to know if this code is vulnerable

  • 0

As the title suggests, I would like to know if this code is vulnerable to SQL Injection? And if so, is there a better, more secure, way of achieving the same thing?

def add(table,*args):
    statement="INSERT INTO %s VALUES %s" % (table,args)
    cursor.execute(statement)
  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-15T08:17:53+00:00Added an answer on June 15, 2026 at 8:17 am

    Yes, it is. Use something like this to prevent it:

    cursor.execute("INSERT INTO table VALUES ?", args)
    

    Note that you cannot enter the table in like this. Ideally the table should be hard coded, in no circumstance should it come from a user input of any kind. You can use a string similar to what you did for the table, but you’d better make 100% certain that a user can’t change it somehow… See Can I use parameters for the table name in sqlite3? for more details.

    Essentially, you want to put the parameters in the cursor command, because it will make sure to make the data database safe. With your first command, it would be relatively easy to make a special table or args that put something into your SQL code that wasn’t safe. See the python pages, and the referenced http://xkcd.com/327/ . Specifically, the python pages quote:

    Usually your SQL operations will need to use values from Python
    variables. You shouldn’t assemble your query using Python’s string
    operations because doing so is insecure; it makes your program
    vulnerable to an SQL injection attack (see http://xkcd.com/327/ for
    humorous example of what can go wrong).

    Instead, use the DB-API’s parameter substitution. Put ? as a
    placeholder wherever you want to use a value, and then provide a tuple
    of values as the second argument to the cursor’s execute() method.
    (Other database modules may use a different placeholder, such as %s or
    :1.)

    Basically, someone could set an args that executed another command, something like this:

    args="name; DELETE table"
    

    Using cursor.execute will stuff the value given, so that the argument could be as listed, and when you do a query on it, that is exactly what you will get out. XKCD explains this humorously as well.

    enter image description here

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

As the title suggests, I would like to see if this is something people
This is my code: I would like to have a title in autocomplete, informing
As the title suggests, I would like to know if it is possible to
As the title suggests I would like to convert a long number to the
As the title suggests, I would like to get the last word out of
Like the title suggests I need to do something like so... $i++;//we all know
As the title suggests I would like to be able to use data from
As the title suggests I would like to understand why static classes can have
As what the title suggests, I would like to be able to lock all
I would like to know people's thoughts on the best way to do the

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.