$db = new PDO("mysql:host=localhost;dbname=$dbName", $dbUser, $dbPassword);
# Named parameters
$stmt = $db->prepare("SELECT id, surname, given_name, birthday FROM users WHERE surname=:surname AND given_name=:given_name");
$stmt->execute(array(':surname' => 'Derf', ':given_name' => 'Fred'));
while ($row = $stmt->fetch()) {
....
}
// assumes $_POST has keys 'surname' and 'given_name'
for ($_POST as $key => $val) {
$stmt->bindValue(":$key", $val);
}
$stmt->execute();
while ($row = $stmt->fetch()) {
....
}
# Positional parameters
$stmt = $db->prepare("SELECT id, surname, given_name, birthday FROM users WHERE surname=? AND given_name=?");
$stmt->execute(array('Derf', 'Fred));
while ($row = $stmt->fetch()) {
....
}