Forum Moderators: open
Dim strName As String = Request.from("name").replace("'","''")
Dim strSQL As String = "SELECT address FROM users WHERE name = '" & strName & "'"
However...
Ad Hoc SQL is nearly always a bad idea. Consider using parameterized SQL or stored procedures instead.
MSDN:How To: Protect From SQL Injection in ASP.NET [msdn2.microsoft.com]
MSDN:How To: Protect From Injection Attacks in ASP.NET [msdn2.microsoft.com]
MSDN:Anti-Cross Site Scripting [msdn2.microsoft.com]