Use the quote method of your database handle:
my $escapeId = $dbh->quote( $params{id} )
In reply to Re: Escaping %params by trwww in thread Escaping %params by DaisyLou