setting parameters prevent SQL Injection?
Because injection is about WHAT the query is looking for, if you hardcode a version of the query with LIKE and version with CONTAINS nothing bad will happen. You can still use parameters for the arguments.
Обсуждают сегодня