How can prepared statements protect from SQL injection attacks? How can prepared statements protect from SQL injection attacks? sql sql