my $sth = $dbh->prepare(<param('user'); my $position = $q->param('position'); $sth->execute($user, $position);