DeepFrontend
Learning Paths
Practice
System Design & DS
Design Studio
Data Structures Curriculum
Real-World Case Studies
Careers
Job Board
Resume Builder
Blog
Sign in
Search
⌘K
Go Pro
Loading compiler resources...
Web Security Quiz Practice
Active Recall Drill Session
← Exit Session
Question 1 of 1
medium
Web Security
Why is manually escaping quote characters an unreliable fix for SQL injection compared to parameterized queries?
A
Manual escaping is always faster and equally safe
B
Escaping rules are driver/database-specific and easy to get subtly wrong or incomplete, while parameterization eliminates the class structurally regardless of escaping edge cases
C
Parameterized queries don't actually work with any database
D
There's no real difference between the two approaches
Check Answer