Prevent SQL Injections

User picture