码迷,mamicode.com
首页 > 数据库 > 详细

php中mysql参数化查询

时间:2016-05-16 17:16:49      阅读:542      评论:0      收藏:0      [点我收藏+]

标签:

$query = sprintf("SELECT * FROM Users where UserName=‘%s‘ and Password=‘%s‘",mysql_real_escape_string($Username),mysql_real_escape_string($Password));  
mysql_query($query);  
或是  
   
$db = new mysqli("localhost", "user", "pass", "database");  
$stmt = $mysqli -> prepare("SELECT priv FROM testUsers WHERE username=? AND password=?");  
$stmt -> bind_param("ss", $user, $pass);  
$stmt -> execute();  

 

php中mysql参数化查询

标签:

原文地址:http://www.cnblogs.com/LoveJulin/p/5498188.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!