1

Cannot get the query to run, throwing error on the @searchin variable. Probably very simple but cannot see it.

set @search = "chip";
set @searchin = "CompanyName";

select * from con_search where @searchin like concat ('%',@search,'%')
ndrwnaguib
  • 5,623
  • 3
  • 28
  • 51

1 Answers1

0

This will work, however you should sanatize the data going into it

set @search = 'chip';
set @searchin = 'CompanyName';
set @SQL = CONCAT("SELECT * FROM con_search WHERE `", @searchin, "` LIKE CONCAT('%'", @search, "'%');";
PREPARE stmt1 FROM @SQL;
EXECUTE stmt1; 
Neo
  • 2,305
  • 4
  • 36
  • 70