Does doing prep statement + param binding also take care of the need for escaping spec char in var? Or I still need to use mysqli_real_escape_string for that? Don't shot me please. I haven't touched db since ages lol
This post has been edited by FourZeroFour: Mar 10 2015, 10:38 AM
Quote your damn SQL inputs!, Paging Bobby Tables!
Mar 9 2015, 07:52 PM
Quote
0.0148sec
0.66
6 queries
GZIP Disabled