05.10.2012 - You should use the setString() method to set the userID . This both ensures that the statement is formatted properly, and prevents SQL injection .