Preventing SQL Injections with string based queries - C#