Queries that have user input should be executed with parametrized queries and should possibly use sp_executesql