Lets say on MySQL database (if it matters).
No, as you could still use D-SQL in your stored procedures... and validating and restricting your input is a good idea in any case.