I would check first if date_default_timezone_get()
returns a valid value, to avoid a query like: SET time_zone = ""
.
Is this php/mysql expression (which sets the timezone of connection) safe enough?
题
Is this expression is safe or does this approach has vulnerabilities?
$pdo = new PDO('mysql:host=localhost;dbname=test', 'user', 'password');
$pdo->exec('SET time_zone = "' . date_default_timezone_get() . '"');
没有正确的解决方案
其他提示
不隶属于 StackOverflow