Yes, even if you dynamically build your sql statement, you should still use placeholders and bind values.
A functionally equivalent method would be to use DBI::quote, but I prefer to always use placeholders less one forget to quote a field.
In reply to Re: DBI, place holders and CGI forms
by wind
in thread DBI, place holders and CGI forms
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |