mysqli 转义字符串函数
mysqli_real_escape_string($db,$string)
mysqli 预编译
拼装SQL语句 把要进行的操作的SQL语句提前写好,把需要改变的元素变成占位符
SELECT * id,username FROM user WHERE user_name = ? AND password = ? //组装mysql语句 ?为占位符
$stmt = mysqli_prepare ($db,$sql); //$db->句柄
mysqli_stmt_bind_param($stmt,'ss',$username,$password);//绑定变量
mysqli_executensil($stmt);//执行语句
mysql_stmt_bind_result($stmt,$id,$username);
mysqli_stmt_fetch($stmt);
echo $id,$username; //把绑定结果的字段输出出来