"You must escape all strings, that are not known to be OK - Which method to use is a matter of which DB framework you use: It will provide an escaping function." . . . .