Parameterised query
Also called a prepared statement: the SQL is sent with placeholders and the values separately, so input can never change the query structure.
Learn it hands-on
- SQL Injection Medium
- SQL Injection: Code Review Medium
Also called a prepared statement: the SQL is sent with placeholders and the values separately, so input can never change the query structure.