Your approach fails if I you need to insert the following data:
O\'Hara
Your routine will expand that to
O\\'Hara </c>... which is, again, invalid. SQL injection is hard to prevent if you're interpolating arbitrary data.
In reply to Re^4: cleaning up sql from file
by Corion
in thread cleaning up sql from file
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |