python多表查询,防SQL注入

import datetime
now = str(datetime.datetime.now().strftime('%Y-%m-%d')) #今天日期
start_time=now+' 00:00:01'
end_time=now+' 23:23:59'
time=(start_time,end_time)

conn = pymysql.connect(host='', port=4000, user='', passwd='', db='')
cursor = conn.cursor()
sql= '''
select
k.number ,
x.term,
DATE_FORMAT(n.gmt_time,'%%Y-%%m-%%d %%H:%%i:%%s') as CREATE_TIME
from ruck n
left join box x on n.truck_box_id =x.id
left join truck k on n.truck_id =k.id
where (k.number=%s or x.term=%s)
and n.gmt_time BETWEEN %s and %s
order by n.gmt_time desc limit 0,%s
'''
cursor.execute(sql,[number,term,time[0],time[1],int(line)]) # 防SQL注入
result = cursor.fetchall()
print("result------",result)
cursor.close()
conn.close()
原文地址:https://www.cnblogs.com/mys6/p/14710328.html