How to do I sanitize this sql using Zend Framework, so that I can prevent sql injection attack?
"INSERT INTO table(A, B, C)
SELECT MAX(A)+1, '".$params['B']."', '".$params['C']."' FROM table
WHERE B='".$params['B']."' AND C='".$params['C']."'"
$params['B'] and $params['C'] are user inputs.