in reply to Re^7: DBI do() SQL injectionin thread DBI do() SQL injection
No, please don't. Use quote_identifier for table and column names.