• Indeed.  And please make sure you read and understand about SQL injection before that goes anywhere near a live server.

    John