in reply to Simple question on SQL Injection

Use replaceable parameters (avoiding the need for validation and quoting).