<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>re: String.Format: A Simple Tip</title><link>http://msmvps.com/blogs/manoj/archive/2005/03/15/14551.aspx</link><description>Just came across this post while looking for the &amp;quot;{{&amp;quot; escape format... Thanks! But I couldn't help but see you were using string.Format to construct a SQL statement. :O I have just given a talk with the ASP.NET team about SQL Injection attacks</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator></channel></rss>