Suppose I have a database full of health records and an ASP.NET MVC application. Suppose someone uses the URL / api / medicalRecords? $ Filter = id gt 0 to invoke the Ajax request. It seems to me that it is open for SQL injection - just like 10-15 years ago ...
Does this mean that this is the standard version for SQL injection or is it server dependent (I use IQueryable result and framework 4 entity)?
I know that an authentication mechanism is necessary - but for the sake of this question, suppose the authentication mechanism is not available ...
source share