There is an easy way to handle SQL injection in a Hibernate HQL by by statement. Obviously, named parameters do not work.
EDIT:
Feel free to post your solution to this problem. I want to see other people's decisions and teach them.
Thanks for any suggestions and solutions.
java sql-order-by hibernate hql code-injection
michal.kreuzman
source share