, , . , - . , , :
, $id = intval($_GET['id']), $id, .
! , , , (, , - ). "".
% _ , , , . , :
$term = $_GET['term'];
$sql = sprintf("SELECT FROM table WHERE column LIKE '%%s%'",
mysql_real_escape_string($term));
, a % $term, , %. %, \% (\ escape- ). str_replace strtr - .