Developer error: The most dangerous programming mistakes
javaworld.com
javaworld.com
There is also an old way which also correctly escapes parameters but is easier to get wrong by forgetting to add it somewhere, which is using your database library's function to escape input before concatenating it into a directly-executed SQL string.
Here are some examples of those methods – in PHP, because it’s the only language I’ve used to build a site without an ORM (which is another option). It’s been a while since I used PHP, but as far as I can tell, with PHP’s built-in library, you would use PDO (PHP Data Objects) for parameter binding. For escaping input for SQL strings, you would use mysql_real_escape_string() (or its relative for your database engine).
To put all together it was really not an article I want to read. Sorry. If you posted the link because you think the content is readable, maybe rework it in an own blog post next time, if the quality of the original is so low. It helps you twice. First readers will appreciate your delivery much more and second, you will get the traffic/fame and not the source page here.
I hope my detailed analysis of why I can't suggest reading this article or giving you the +1 helped.