SQL videos | SQL Programming Part 13 - Dynamic SQL

Posted by Andrew Gould on 10 May 2013

Dynamic SQL allows you to build a complete SQL statement out of individual strings of text and execute it as though it was an SQL statement. It allows you to create immensely flexible queries in which any part of a statement can be parameterised, but it can also leave you vulnerable to the dreaded SQL injection attack! This video teaches you how to build dynamic SQL statements, how to use stored procedures to parameterise the process, and the potential dangers of using dynamic SQL in a live system.

