If someone can provide a link with the use of Parameters instead of concatenation

You didn't mention what server side scripting language, so I'll just provide a reference in case its asp.net that you are working with. Good reference: http://msdn.microsoft.com/en-us/library/ff648339.aspx

