SQL Injection and mysql_real_escape_string() in PHP | CodeTrail