Prepared like statement
We have a statement like
select searchtitle,searchdescription,searchlink from search where
searchtitle like '%$keyword%' or searchdescription like '%$keyword%'"
How can I make it a prepared statement so the user input is properly
sanitized like:
select searchtitle,searchdescription,searchlink from search where
searchtitle like '%?%' or searchdescription like '%?%'"
The above seems to fail, I've even tried '%'+?+'%' AND '%'.?.'%'
No comments:
Post a Comment