python format string sql injection