I view strings as array of bytes, do I need to escape numbers too?
/**
* Login and set cookie etc.
*/
function security_login($email_address, $password, $remember_me) {
$sql = sprintf("SELECT user_id FROM user WHERE email_address = '%s' AND password = MD5('%s');",
mysql_escape_string($email_address),
mysql_escape_string($password));
print_r($this->database->querySingleRow($sql));
}
/**
* Login and set cookie etc.
*/
function security_login($email_address, $password, $remember_me) {
$sql = sprintf("SELECT user_id FROM user WHERE email_address = '%s' AND password = MD5('%s');",
mysql_escape_string($email_address),
mysql_escape_string($password));
print_r($this->database->querySingleRow($sql));
}
PreparedStatement stmt = connection.prepareStatement("select * from table_parts where partNo = ?");
stmt.setString(1, partNo);
stmt.execute();

Comment