in reply to Re^3: cleaning up sql from file
in thread cleaning up sql from file

Your approach fails if I you need to insert the following data:

O\'Hara

Your routine will expand that to

O\\'Hara </c>

... which is, again, invalid. SQL injection is hard to prevent if you're interpolating arbitrary data.