Possible Duplicate:
How prepared statements can protect from SQL injection attacks?
I read that using parameterized queries will guarantee you to be 100% safe from sql injection, but I'm not so sure. If you guys think that it's completely safe, please explain why and vice versa