防止sql注入预准备 MysqLi:$qSelect=$DBH-prepare(SELECT*FROMusersWHEREusername=?);$qSelect-bind_param(s,$username);}PDO:$PDO-prepare(SELECT*FROMusersWHEREusername=?SELECT*FROMusersWHEREusername=:username);$pdo-execute([1]);$pdo-execute
防止sql注入预准备
MysqLi:$qSelect = $DBH->prepare("SELECT * FROM users WHERE username = ?"); $qSelect->bind_param("s", $username); }PDO:$PDO->prepare( "SELECT * FROM users WHERE username = ?" "SELECT * FROM users WHERE username = :username" ); $pdo->execute([1]); $pdo->execute([' :username=>1 ']);