PHP参数化查询见如下示例:$pdo = new PDO("mysql:host=localhost;dbname=database", "dbusername", "dbpassword"); $username = "root";$password = "123456"; $query = "SELECT * FROM users WHERE (name = :username) and (password = :password)";$statement = $pdo->prepare($query, array(PDO::ATTR_CURSOR => PDO::CURSOR_FWDONLY));$statement->bindParam(":username", $username, PDO::PARAM_STR, 10);$statement->bindParam(":password", $password, PDO::PARAM_STR, 12);$statement->execute();