Perhaps usage of Parameters instead of creating the SQL string ... So we dont have to worry about encoding and decoding the values too.
Log in to post a comment.