I am using Yii 1, I want to build the following query:
$a = Model::model()->findAllBySql(
'SELECT * FROM table WHERE name like "%'.$_GET['name'].'%"'
);
To prevent the sql injection I wrote it as follow:
$a = Model::model()->findAllBySql(
'SELECT * FROM table WHERE name like "%:name%"',
array("name"=>$_GET['name'])
);
but it returned no data. Are there any errors in this query ?