php 下进行mysql参数化查询

来源:互联网 发布:sql 当前时间减1小时 编辑:程序博客网 时间:2024/05/15 21:06

记录一下,php下的mysql参数化查询

$query = sprintf("SELECT * FROM Users where UserName='%s' and Password='%s'",                   mysql_real_escape_string($Username),                   mysql_real_escape_string($Password));mysql_query($query);或是 $db = new mysqli("localhost", "user", "pass", "database");$stmt = $mysqli -> prepare("SELECT priv FROM testUsers WHERE username=? AND password=?");$stmt -> bind_param("ss", $user, $pass);$stmt -> execute();