in reply to Escaping characters
In a nutshell, you start with an update statement like
and then execute the statement with a list of scalar values like this:my $sth = $dbh->prepare("update my_table set title=? where key=?");
No quotation marks are needed around the string values being handed to the database, and there is no need to escape things within the scalar values that happen to be quote characters.$sth->execute( $in{title}, $in{key} );
|
|---|