Thanks for showing a simple example of this. I haven't got into using parameters yet, which from what I understand is the 'proper' way of handling criteria, especially for preventing SQL injection.
However, I need a string-based solution, as that solution has way too much overhead.
This...