$id = q|3';DROP TABLE people;SELECT * FROM people WHERE id = '3|; #### sub SelectProfile { my ( $id, $dbh ) = @_; $id = $dbh->quote( $id ); my $selectquery = "SELECT * FROM people WHERE id = $id"; my $sth= $dbh->prepare($selectquery); $sth->execute(); my $rowdata=$sth->fetchrow_hashref; return $rowdata; }