Node.js中用escape解决sql注入这时正常情况下能查询到一条数据,如果将param修改成 let param = 'ns"-- ' sql语句就会变成 select * from tb_nature where nature = &2023-02-21JavaScript170