if (defined($query{"component"}) || defined($query{"env"})) { my $dbh = DBI->connect("DBI:mysql:test", "root", "930612", {'RaiseError' => 1}); my $query = "SELECT * FROM or_mod"; if (defined($query{"component"})) { if ($query eq "SELECT * FROM or_mod") { $query = $query . " where upper(component) = upper('" . $query{"component"} . "')"; #I am forced to deal with quotes myself, as I am not binding later } else { $query = $query . " and upper(component) = upper('" . $query{"component"} . "')"; # I know this is not needed here. I did it just in case some day someone reverse the order of codes } } if (defined($query{"env"})) { if ($query eq "SELECT * FROM or_mod") { $query = $query . " where upper(env) = upper('" . $query{"env"} . "')"; } else { $query = $query . " and upper(env) = upper('" . $query{"env"} . "')"; } } $query = $query . " order by env, application, component, mod_date desc"; print $query; my $sth = $dbh->prepare($query); #This prepare is unreal. One is supposed to prepare a statement only once $sth->execute();