emulated prepared statements vs real prepared statements
问题 What's exactly the difference between the two kinds of prepared statements ? I think real prepared statements require server side support wich accepts paramenters after parsing and compiling the schema/template of sql code, and , I suppose ,that's what guarantees us against sql-injection. In the case of emulated prepared statements ,with no server support, what does it guarantee us against it ? 回答1: You are correct, real prepared statements must be supported by the server. A real prepared