You should always use bound parameters when possible, and DBI::quote when it isn't.
In reply to Re: Basics: CGI MySQL security by imp in thread Basics: CGI MySQL security by jfrm