You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'on+sel/**/ect+1,2,3,4,5,6,7,8,9,10%' OR LOWER(description) LIKE '%lzd+��ï' at line 1 SQL query : SELECT COUNT(DISTINCT p.productID) FROM SS_products p where categoryID>1 and enabled=1 and ( LOWER(name) LIKE '%lzd+���+5\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\''+and+sleep(3)))+uni/**/on+sel/**/ect+1,2,3,4,5,6,7,8,9,10%' /* OR LOWER(product_code ) LIKE '%lzd+���+5\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\''+and+sleep(3)))+uni/**/on+sel/**/ect+1,2,3,4,5,6,7,8,9,10%' OR LOWER(description) LIKE '%lzd+���+5\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\''+and+sleep(3)))+uni/**/on+sel/**/ect+1,2,3,4,5,6,7,8,9,10%' OR LOWER(brief_description) LIKE '%lzd+���+5\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\''+and+sleep(3)))+uni/**/on+sel/**/ect+1,2,3,4,5,6,7,8,9,10%' */)