Are you worried about SQLInjection attacks then you should be. This is a prime real world example.
http://xkcd.com/327/
PingBack from http://www.pythian.com/blogs/637/log-buffer-66-a-carnival-of-the-vanities-for-dbas