Mat Patnik - 2010-11-07 04:51:57
Is there a difference as far as security between the 2:
$query = sprintf("SELECT * FROM users WHERE user='%s' AND password='%s' LIMIT 1;",
mysql_real_escape_string($user),
mysql_real_escape_string($password));
And
$query = "SELECT *
FROM members
WHERE username = '". mysql_real_escape_string($_SESSION['username']) ."'
AND password = '". mysql_real_escape_string($_SESSION['password']) ."'
LIMIT 1;";