You also want to read about SQL injections :
http://www.nextgenss.com/papers/adva..._injection.pdf
http://www.spidynamics.com/papers/SQ...WhitePaper.pdf

Have fun