What is better (more secure) way to handle SQL injections ?
$var = filter_var($_POST['var'], FILTER_SANITIZE_STRING);
or
mysqli_real_escape_string($link, $_POST['var']);
What is better (more secure) way to handle SQL injections ?
$var = filter_var($_POST['var'], FILTER_SANITIZE_STRING);
or
mysqli_real_escape_string($link, $_POST['var']);