$name = "O'Reilly"; $sth = $db->prepare("SELECT * FROM emp WHERE name = '$name'"); $sth->execute(); #### $name = "O'Reilly"; $sth = $db->prepare("SELECT * FROM emp WHERE name = ?"); $sth->execute($name); #### my $field = $old ? "olddata" : "newdata"; $sth = $db->prepare("SELECT * FROM ?"); $sth->execute($field);