MySQL : How can mysqli_real_escape_string fail to prevent a SQL injection?

Published --