Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6845743
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 27, 20262026-05-27T00:32:17+00:00 2026-05-27T00:32:17+00:00

I wrote the following part which is a Java method with two STRING arguments

  • 0

I wrote the following part which is a Java method with two STRING arguments login and pass, representing a user’s login name and password, to check whether the user is found in a database table.

Statement stmt = connection.createStatement();

ResultSet rs = statement.executeQuery ("SELECT * FROM users WHERE username = '" 
        + login + "' AND passwd = '" + pass + "'");

The code when tested worked correctly. I read in a book that there are situations where it could potentially generate an SQL error but it does not mention exactly the circumstances under which the above code could result in an SQL error. Could you please briefly expain me these situations? And also how can I write a version of the code that would prevent the possibilityof such an error occuring?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-27T00:32:18+00:00Added an answer on May 27, 2026 at 12:32 am

    The first problem is that this piece of code is vulenrable to SQL Injection. To avid that you can use Prepared Statements. This might be one potential threat the book might be talking about.

    http://www.unixwiz.net/techtips/sql-injection.html

    example for using prepared statement

    String query = "SELECT * FROM users WHERE username = ? AND passwd = ?";
    
    PreparedStatement ps = connection.prepareStatement(query);
    
    ps.setString(1, login);
    ps.setString(2, passwd);
    
    Resultset rs = rs = ps.executeQuery();
    
    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I wrote following code...but i am getting Error like: Error 1 'LoginDLL.Class1.Login(string, string, string)':
I wrote the following code: import java.lang.*; import DB.*; private Boolean validateInvoice(String i) {
I have mysql table with following fields id (which auto increments) title,name,age,institution,iod the fields
I have the following php function which i wrote a while ago. Now however,
I wrote the following code in order to apply a function for two lists
I'm using the following java code to upload a multi-part image to an ASMX
i wrote following code to create a linkbutton programmatically, but its showing like lable
Wrote the following in PowersHell as a quick iTunes demonstration: $iTunes = New-Object -ComObject
I wrote the following javascript to put in my startup folder to work around
I wrote the following Nant script on my Vista dev machine and was pleased

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.