String name = "1' or '1' = '1";
String age = "1' or '1' = '1";
String sql = "select * from user where name = '" + name +"' and age = '"+ age +"'";
最终结果:select * from user where name = '1' or '1' = '1' and age = '1' or '1' = '1'
PreparedStatement:占位符/动态参数化
String sql = "select * from user where name = ? and age = ?";