How can sanitation that escapes single quotes be defeated by SQL injection in SQL Server? How can sanitation that escapes single quotes be defeated by SQL injection in SQL Server? sql-server sql-server