
I have a relative simple question about mysqli_prepare:
When I prepare a statement and then bind parameters to it, does php automatically care for escaping strings etc.?


$stmt = $mysqli->prepare("SELECT FROM table WHERE x=?");
$p = "5'"
# is "5'" converted to 5 like it would when i use intval($p)?


$s = "'xyz' || x LIKE '%'";
# will those "'" be escaped?

thanks for help

PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to