restrict the scope of variables in a mysql query? with brackets?
- by Haroldo
I can't remember what the method is meant to be for ensuring the scope of a variable in a query is restricted to prevent mysql injection.
where should i put brackets in the following examples?
UPDATE table SET col_1 = '$var', col_2 = '$var2' WHERE col_1 = '$var3'
and
SELECT * FROM table WHERE WHERE col_1 >= '$var1'
(Obviously looking for answers not using PDO!)