Just going on a hunch, but with the words "unescaped sql string" in your error message, I'm wondering if you are aware of the quoting facilities of DBI?
perldoc DBI should give you more information.
If you're not using DBI for your SQL access yet, you should really look into it.