没有问号占位符的预备声明仍然安全吗?
例:
String username = "userename from EditText";
String password = "password from EditText";
PreparedStatement statement = _con.prepareStatement("SELECT * FROM users WHERE username = '"+username+"' AND password = '"+password+"';");
ResultSet rs = statement.executeQuery();
Run Code Online (Sandbox Code Playgroud)