Nov 15, 2012 10:39 AM|hans_v|LINK
The correct syntax for an UPDATE statement is
UPDATE [tablename] SET field1 = ...., field2 = .... WHERE....
UPDATE [tablename] SET (field1 = ....., field2 = ....) WHERE....
But I see another security problem. You're concatenating the SQL string with user input, which is not good practice
Read this article: