传入的参数: name = "zhangsan" pwd = "123 or 1=1"
select * from t_user where name = #{name} and pwd = #{pwd}
mybatis处理之后
select * from t_user where name = 'zhangsan' and pwd= '123 or 1=1'
select * from t_user where name = ${name} and pwd = ${pwd}
mybatis处理之后
select * from t_user where name = zhangsan and pwd= 123 or 1=1
这里如果想把zhangsan带单引号,传入参数name = "'zhangsan'"
select * from t_user where name = 'zhangsan' and pwd = 123 or 1 = 1