in reply to Security with a MEMO field

As mentioned above, use placeholders (or DBI's quote method, although placeholders are preferable) to put it into the database. As you say it's a memo field, it's probably meant to be displayed again. Assuming you are displaying it as part of a web page, you can make it safe to display in a browser with HTML::Entities.