I know SQL Injection is one... what are the others...
Massage and filter ALL input to your program before processing.
Never process input without filtering and truncating.
-R