I am building a small web page for our lab's parts inventory. The search code builds its SQL by string concatenation, along the lines of "SELECT * FROM parts WHERE name = '" + userInput + "'", and a colleague said this is open to SQL injection. My plan was to double any single quotes in the input.
Is that enough? How do parameterized queries differ from escaping, and are there places where parameters cannot be used?




