Wednesday, 21 August 2013

Prepared like statement

Prepared like statement

We have a statement like
select searchtitle,searchdescription,searchlink from search where
searchtitle like '%$keyword%' or searchdescription like '%$keyword%'"
How can I make it a prepared statement so the user input is properly
sanitized like:
select searchtitle,searchdescription,searchlink from search where
searchtitle like '%?%' or searchdescription like '%?%'"
The above seems to fail, I've even tried '%'+?+'%' AND '%'.?.'%'

No comments:

Post a Comment