Can I protect against SQL injection by escaping single-quote and surrounding user input with single-quotes? Can I protect against SQL injection by escaping single-quote and surrounding user input with single-quotes? sql sql