Using parameterized queries to avoid SQL injection

Using parameterized queries to avoid SQL injection