due discussioni interessanti a riguardo:

http://stackoverflow.com/questions/1...-sql-injection

e

http://stackoverflow.com/questions/8...ection-attacks