my $name = $cgi->param('name'); my $query = "INSERT ... VALUES($name)"; #### my $name = $cgi->param('name'); my $query = "INSERT ... VALUES(" . dbi->quote($name) . ")";