The query string passed to {0} in {1} could contain the following variables {2}. If any of these variables could come from ...

The query string passed to {0} in {1} could contain the following variables {2}. If any of these variables could come from user input, consider using a stored procedure or a parameterized SQL query instead of building the query with string concatenations.