SQL injection

ํด๋ผ์ด์–ธํŠธ์—์„œ ์„œ๋ฒ„์— ๋ฐ์ดํ„ฐ ์ถ”๊ฐ€ํ• ๋•Œ sql๋ฌธ๋ฒ•์„ ๋„ฃ์–ด์„œ ์ž„์˜์ ์œผ๋กœ DB๋ฅผ ์ปจํŠธ๋กค ํ•˜๋Š” ๊ฒฝ์šฐ๋ฅผ ๋งํ•œ๋‹ค.
INSERT INTO User(id, content) VALUES(100,'hi')
๋งŒ์•ฝ์— ํด๋ผ์ด์–ธํŠธ์—์„œ 'hi'๊ฐ€ ์•„๋‹Œ 'DROP ALL TABLES;' ์™€ ๊ฐ™์€ SQL๋ฌธ์„ ๋„ฃ์œผ๋ฉด,
INSERT INTO User(id,content) VALUES(101,'');
DROP ALL TABLES; ๋กœ ์ปดํ“จํ„ฐ๋Š” ์ธ์‹ํ•œ๋‹ค.
ย 
์ด๋ฅผ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๊ธฐ๋ณธ library๋‚˜ framwork๋ฅผ ์ด์šฉํ•˜์—ฌ Character escaping์„ ํ•˜์ž
ย 
ย