sqlfiddle
sqlfiddle copied to clipboard
DML filters evasion in MySQL with comments
The filter doesn't catch statements that are followed by a comment: http://sqlfiddle.com/#!2/83fbb/19 By the way while we're at it. How about disabling nonstractional database like myisam and allowing INSERT/UPDATE/DELETE statements? Or allowing to create temporary tables? That's not on the implicit commit list (http://dev.mysql.com/doc/refman/5.6/en/implicit-commit.html).