Please please use placeholders in all SQL, everytime, everywhere, always. Imagine what happens when someone submits the value 0'; DROP TABLES; -- as $ref_id. If you use placeholders in your prepared statements, the DBI driver would quoute away some of the danger in this.