In this sample lets validate a real sql injection - use a popular DB framework - make this VERY lightweight nothing fancy - just needs to highlight calling an execute query without parameterization ...