使用字符串连接符将变量和SQL语句拼接起来,不使用bind_param()
示例代码:
// 错误写法
$stmt = $mysqli->prepare("SELECT * FROM `table_name` WHERE MATCH (`column_name`) AGAINST (?)");
$stmt->bind_param("s", $search_term); // 这行代码会出错
// 正确写法
$sql = "SELECT * FROM `table_name` WHERE MATCH (`column_name`) AGAINST ('$search_term')";
$stmt = $mysqli->prepare($sql);
$stmt->execute();