We'd have to see the code you're using. It shouldn't matter whether it's on or off assuming you define and use your own variables.
EDIT: That's not to mention the fact that you should never be placing user-supplied data directly into a SQL query anyway...