Most application developers underestimate the risk of SQL injection attacks against web applications that use Oracle as the back-end database.

This story continues at http://www.databasejournal.com/news/article.php/3306261