it's kinda both. i saw code that showed how to make a stored procedure. however this sql statement is only going to be used for this particular insert. but the insert has a field where the user can input all different kinds of characters: ',",/, etc. so looking online everyone said the only...