in reply to security question, mysql, limit, dbi, and placeholders

I don't have a MySQL database here to try it but perhaps this exerpt from DBI documentation can help:
Data Types for Placeholders The "\%attr" parameter can be used to hint at the data type the placeholder should have. Typically, the driver is only interested in knowing if the placeholder should be bound as a number or a string. $sth->bind_param(1, $value, { TYPE => SQL_INTEGER });
In the error message the number 10 was quoted (like a string), MySQL usually accepts quoted numbers where a number must be, but perhaps not in the LIMIT part of the statement.

(this answer was lead by a suggestion by PodMaster in CB).