I'm trying to convert my website with PDO so that's it's more secure for sql injections.
I'm having a problem here, for i'm checking if the username isn't already registered:
This is my sql atm:
function isregistered($var,$methode) {
$check1 = mysql_result(mysql_query("SELECT COUNT(gebruikersnaam) FROM leden_temp WHERE ".$methode."='".$var."'"),0);
$check2 = mysql_result(mysql_query("SELECT COUNT(id) FROM leden WHERE ".$methode."='".$var."'"),0);
$check = $check1 + $check2;
if($check == 0) {
return FALSE;
} else {
return TRUE;
}
}
And i'm trying convert it to sql on this way as a pdo statement:
$check1 = $dbh->query("SELECT COUNT(gebruikersnaam) FROM leden_temp WHERE ".$methode."='".$var."'');
But i'm a bit lost on how this actually gonna work with PDO ? Can you guys help me a bit ?