I have an SQL query of this form
string cmdText = \"Select * from \" + searchTable + \"WHERE \" + searchTable + \"Name =\' \" + searchValue + \"\'\";
There is a blank missing and one too much:
searchTable + "Name =' "
should read
searchTable + " Name ='"
Beside that, use SQL parameters to prevent SQL injection.