Cenzic 232 Patent
Paid Advertising
sla.ckers.org is
ha.ckers sla.cking
Sla.ckers.org
How do you completely compromise a machine given a text box or badly validated input box? This is a place to talk about code issues (PHP includes, null byte injection, backticks, pipe, etc...) as well as how to properly construct an SQL injection attack. 
Go to Topic: PreviousNext
Go to: Forum ListMessage ListNew TopicSearchLog In
parameterized query vs preparedstatement..help!
Posted by: huz
Date: April 22, 2012 12:56AM

hello guys, i found that parameterized query and preparedstatement can help in preventing sqlia...but i wonder what is the difference between both of them?? and what about bind variable?? i am quite confuse.....

but correct me if i'm wrong...from what i understand, preparedstatement is a way to do a parameterized query or some sort of parameterized query, and the variable that go to the prepared statement will be bind first... is that right??

thanks..

Options: ReplyQuote


Sorry, only registered users may post in this forum.