If Statement Sql Injection