i'm looking for confirmation that parameterised statements are not being executed correctly. Current code is as follows:
$ywant = "user supplied integer";
$select = "SELECT a.Authors, a.PublicationYear, a.Title, a.URL, a.ArticleID, f.Format ".
"FROM tbl_ETI_Article a, tbl_ETI_Format f ".
"WHERE a.PublicationYear = '".$ywant."' ".
"AND a.FID = f.FID ".
"ORDER BY a.PublicationYear DESC, a.Title ASC";
$sth = $dbh->prepare( " $select " );
$sth->execute();
i understand that the $ywant variable in the select string should be replaced with a placeholder '?' and then the user supplied data be placed as an argument in the execute statement.
My question is does the above still offer any protection against injection attacks as it is still "being prepared"?