Because you use bind parameters, you're are essentially immune to SQL injection attacks. As for buffer overflow ... I haven't heard of any attacks that work like that, but I'm not a security expert.
Being right, does not endow the right to be rude; politeness costs nothing.
Being unknowing, is not the same as being stupid.
Expressing a contrary opinion, whether to the individual or the group, is more often a sign of deeper thought than of cantankerous belligerence.
Do not mistake your goals as the only goals; your opinion as the only opinion; your confidence as correctness. Saying you know better is not the same as explaining you know better.