my $name = param('name'); # you may want to prevent search metacharacters: $name =~ s/(\%|_)/\\$1/g; my $sth = $dbh->prepare( "select * from clients where name like ?" ); $sth->execute($name) or die "Whoops!"; while ($sth->fetchrow_hashref) { ... } ####